1,100 questions with Sysinternals-related tags

Sort by: Updated
3 answers One of the answers was accepted by the question author.

Error in Azure Sysmon Workbook project' operator: Failed to resolve table or column expression named 'process_create_whitelist

Hello everyone. I have been trying to set up a lab on my Azure Sentinel tenant to receive sysmon logs. I have followed some of the tutorials posted using the agents. Everything seem to work fine I am receiving logs from sysmon to azure, but where I…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,854 questions
Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
10,819 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
997 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2022-03-26T01:43:54.167+00:00
Alvarado, Peter 21 Reputation points
commented 2024-04-10T16:36:31.4433333+00:00
Adam Jakubiec 0 Reputation points
5 answers One of the answers was accepted by the question author.

Windows Version

2021 July 09 BGinfo query Product shows Windows 10 Pro ReleaseID shows 2009 but Windows version is now 21H1. Is there a way for BGinfo to show 21H1 ? Settings , About shows Edition Windows 10 Pro Version 21H1

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2021-07-09T17:03:33.477+00:00
T M N Irish 21 Reputation points
commented 2024-04-09T10:16:42.01+00:00
Thomas F 1 Reputation point
4 answers

Procexp152.sys Driver cannot load due to security setting

Can anyone at Sysinternals please help? I am suddenly getting a Program Compatibility Assistant error which states, "A driver cannot load on this device" and points at the ProcExp152.sys driver, saying that a security setting has detected this…

Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,374 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2023-08-16T04:41:11.0766667+00:00
suirauqa 65 Reputation points
commented 2024-04-08T12:01:32.29+00:00
Gilles Jaffier 0 Reputation points
1 answer

On the ARM version of Procmon, can Procmon64a.exe be added to the default exclude filter list?

Please forgive the extremely minor nitpick. On x86 and x64 Procmon filters out its own events by default, but the ARM version doesn't. Can Procmon64a.exe be added to the default exclude filter list in Procmon64a.exe? Thanks for making great software.…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2024-03-08T14:21:58.2233333+00:00
Elizabeth Greene 0 Reputation points Microsoft Employee
answered 2024-04-08T11:08:56.96+00:00
Alex Mihaiuc 176 Reputation points Microsoft Employee
2 answers

How to show the number of TCP connection in columns of Process explorer ?

Hello, I was searching for some process with specific TCP connection open but many has 0. And nothing tell me that before I open the details of the process... Is there a way to see trafic / number of TCP connection in the columns of Process Explorer ?

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2023-06-03T09:22:15.8433333+00:00
Sylv1 5 Reputation points
edited an answer 2024-04-05T20:19:06.0333333+00:00
xMaxrayx 0 Reputation points
1 answer

WHOIS - doesn't work for German DE domains

Would you please consider adding functionality to enable WHOIS queries to German DE domains? The root of the problems seems to be that DENIC (the German domain registry) does not implement ICANN's specifications but requires that WHOIS requests conform…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2021-06-28T19:46:50.507+00:00
Martin Wolter 1 Reputation point
edited an answer 2024-04-03T14:49:17.0166667+00:00
Mian Fahad 5 Reputation points
4 answers

Zoomit: When running the Windows Magnifier, the mouse cursor is lost after exiting LiveZoom

Open Windows Magnifier (no need to use) Enter LiveZoom mode, then exit LiveZoom At this moment, it is observed that the mouse pointer is no longer visible

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2023-11-23T04:12:04.53+00:00
hwf1324 5 Reputation points
edited an answer 2024-04-02T18:09:51.5+00:00
Andreas Sieber 0 Reputation points
2 answers

Process explorer systray / taskbar / tray icons lost on explorer.exe (shell) restart

If you use the process explorer graphs in your systray when explorer restarts all systray icons for process explorer are lost. Has been this way for quite awhile (probably ever? at least years?). It is a bit annoying as you must also kill the old one…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2023-06-22T22:30:51.78+00:00
Mitch C 15 Reputation points
commented 2024-04-02T03:51:51.46+00:00
Snappy05 0 Reputation points
0 answers

Is it possible to restrict colour printing by using a password?

I'm currently looking for a new printer for the office. I was informed that one of the features required is color printing restriction. Basically, I need a printer which can limit the ability of color printing and only people with the designated password…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2024-03-26T01:11:06.7533333+00:00
EIRISHA AINA BINTI ARMAN 0 Reputation points
5 answers One of the answers was accepted by the question author.

Looking for RoboCopy GUI and RichCopy

I was troubleshooting somebody else's computer and needed to back up their files while excluding some stuff. Microsoft used to put out a free utility called RoboCopy GUI that helped setting up the parameters for robocopy and made it easier to copy/paste…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2022-12-17T08:06:22.71+00:00
Slick RCBD 46 Reputation points
answered 2024-03-23T18:26:28.3966667+00:00
Cinchoo 0 Reputation points
0 answers

Connect to Azure AD joined client with RDCMan

I love Remote Desktop Connection Manager (RDCMan) and I use it every day. However, I can't get it to connect to an Azure joined Win10/11 device (using mstsc.exe works). Is there a way to make it work on RDCman or is anyone updating RDCMan with this…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2023-10-10T09:27:10.7166667+00:00
Per-Torben Sørensen 25 Reputation points
commented 2024-03-22T05:51:30.4366667+00:00
Brian 0 Reputation points
0 answers

Powershell Script as a scheduled task errors when I try to connect to Excel worksheet to add data.

My PowerShell script runs fine when I execute it manually. But when I run it from the task scheduler either manually or triggered it errors. $excel = New-Object -ComObject excel.application $workbook = $excel.Workbooks.Add() Errors start here: All three…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2024-03-20T20:49:38.69+00:00
Mike McMillan 0 Reputation points
commented 2024-03-21T14:58:41.4733333+00:00
Mike McMillan 0 Reputation points
1 answer

Procmon Boot-Logging and Network traffic

I have a freshly loaded and patch win11 22H2 device. I can use procmon to capture and see network summary and traffic all day long. if I setup boot-logging and reboot the device and force network traffic once the device is backup up and then go…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2023-06-19T21:59:27.6766667+00:00
k3llyd 15 Reputation points
answered 2024-03-20T05:33:27.46+00:00
Navanath Yenpure 155 Reputation points
1 answer

Unable to stop or uninstall Sysmon 15.0

Since the new Sysmon version 15.0 we have been unable to stop the service or uninstall the application. As you can see the service is unable to be stopped even when trying to uninstall it. We've tried this as administrator, System and through an SCCM…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2023-08-18T06:49:58.4233333+00:00
Persson, Daniel 25 Reputation points
answered 2024-03-20T05:27:45.18+00:00
Navanath Yenpure 155 Reputation points
3 answers

Print Monitors gone after changing them in Autorun

Hi, Mocking around (uncheck to disable) with printer monitors in Autorun64 (14.0.9.0). Got an errors "Failed to disable" from Autorun and when I was finished HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Monitors was empty.…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2022-08-05T05:21:37.627+00:00
micce 16 Reputation points
edited a comment 2024-03-18T18:15:12.7+00:00
Piotr Janik 0 Reputation points
0 answers

procdump: bug when using perf.counter as perf.threshold for when a process has been running at Y% usage for X amount of time

I'm trying to use ProcDump to create a memdump when my process has been using basically 100% of a single core for over an hour. Here's the problem though; when using the parameter -p "\Process(processname)\% Processor Time" value (Performance…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2024-03-15T13:36:39.0766667+00:00
Patrik Mattsson 0 Reputation points
edited the question 2024-03-15T13:57:59.5533333+00:00
Patrik Mattsson 0 Reputation points
4 answers

[Sysmon 15.12] Server crashes from time to time with Sysmon v15.12

We had a crash after 20 minutes of the installation of Sysmon 15.12. In the system event log we've found this message: The computer has rebooted from a bugcheck.  The bugcheck was: 0x00000139 (0x0000000000000003, 0xffff928901305000, 0xffff928901304f58,…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2024-02-05T16:34:48.0566667+00:00
Joe Doe 156 Reputation points
commented 2024-03-12T08:41:38.2866667+00:00
Alex Mihaiuc 176 Reputation points Microsoft Employee
0 answers

My processexplorer icon is set as a cpu monitor, but sometimes my laptop freezes for long periods, and all I see are a couple of red dots at the bottom of the icon, can I put it into a different mode that will show me some sort of indication?

I have Process Explorer running with the status bar icon. It's set as a cpu monitor. I've been using PE for a long time. I've set it up on this new laptop, but for some reason the PE icon is only showing anything happening in about the last pixel row of…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2024-03-11T23:56:39.5933333+00:00
KARR, DAVID 6 Reputation points
0 answers

Sysmon DNS Query Logs - QueryResults Field

How do I display type: 1 for Type A DNS logs in the QueryResults field of Sysmon Event ID 22 DNS Query logs? I tried generating the logs using the below XML format: <Sysmon schemaversion="4.90">  <EventFiltering>  <DnsQuery…

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
10,771 questions
Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,828 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,779 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,374 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2024-03-11T04:05:38.8966667+00:00
1357A 0 Reputation points
1 answer

How can I make Cacheset appear on the taskbar when it's running?

When I'm running Cacheset 1.2.0.1 on windows 11 home 22H2 it doesn't show up on the taskbar. How can I make it show up?

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,100 questions
asked 2024-03-07T12:50:06.1866667+00:00
K Damstra 0 Reputation points
answered 2024-03-09T12:56:48.8233333+00:00
RLWA32 40,941 Reputation points