Sysinternals: Process Monitor deep dive (demo) | ProcMon, registry, process, Windows | Microsoft

Поделиться
HTML-код
  • Опубликовано: 6 сен 2024

Комментарии • 8

  • @smithnigelw
    @smithnigelw 9 месяцев назад

    Great! I’ve used ProcMon many times, but learned many new techniques from this video.

  • @PhO3NiX96
    @PhO3NiX96 5 месяцев назад

    I'm struggling to find a way to trace what script/program writes down a specific file under a specific directory at startup, meaning like when I start my PC, the file is already there so I can't trace after using Procmon, which would mean I need to use the boot thing mentioned in the video but for some reason I can't find what program writes down this file.

  • @QQ_Victory
    @QQ_Victory 2 года назад +1

    Great deep dive into ProcMon! Very interesting.

  • @Ciaran401
    @Ciaran401 9 месяцев назад

    A demo of you loading your own symbols would be great

  • @saeed5508
    @saeed5508 Год назад +1

    Where have you got that Isfahani Carpet?

  • @berndeckenfels
    @berndeckenfels Год назад

    22:40 enabling those symbols not only translated the addresses but also showed much more user mode stack frames? Is that local calls in same module or another effect?

  • @Ehren1337
    @Ehren1337 2 года назад +2

    time to move on to windows 11

  • @gin42069
    @gin42069 Год назад

    how to unload procmon can u help me?