Procmon scan smb request
Hello, I have an issue on a fileshare server, users are complaining about latency, especially when transferring files to the fileshare server,opening files, or modifying files. I want to launch a procmon on the user workstation to see what what…
when running using procmon /terminate log is corrupted
Hello Guys, I'm configuring procmon to run as a scheduled task and then also using another schedule task to terminate it. Both tasks are configured to run with System. Start task has the following arguments: /AcceptEula /LoadConfig…
Bug in BGInfo - Wrong background with correct text or wrong text on correct background
We have BGInfo being run for all users logging on to our RDS environment using a company background generating some custom info. All servers are virtual. RDS servers use FSLogix. It works most of the time BUT some times BGInfo will: not load the…
Sysmon archive folder too big
Hi all. I'm using sysmon with a lot of rules and I'm having a problem, which has been previously exposed here: The archive folder is getting way too big and I can't find any relevant information on how we should clean this folder. Keeping in mind…
Stable Sysmon 15.x version.
We deployed sysmon v15.12 and ran into an issue with random crash with windows servers. Can you recommend a stable version of sysmon which has a fix to CVE-2023-29343 & CVE-2022-41120. TIA
BSOD DRIVER_OVERRAN_STACK_BUFFER when attaching to w3wp.exe process with VS2019
Recently (as of 2 days ago), every time I try to attach to the IIS process w3wp.exe with Visual Studio 2019 (running on Windows 10), I get the blue screen of death with the DRIVER_OVERRAN_STACK_BUFFER error. Several other people at my organization have…
New startup registry key in Windows 10/11, NOT captured within autoruns
Hi All, While researching the startup behavior of Windows Container (Windows Metro) Apps , like the ones installed through Microsoft Store or native to System (xbox/phone, etc), I came across a new registry key location (different from the known…
400% difference in CPU usage between "Task Manager" and "Sysinternal's Process Explorer"
On one specific server I have 400% difference in CPU usage between "Task Manager" and "Sysinternal's Process Explorer" (both picture taken on the same screenshot, so at the exact same time). What can be the cause of this…
What to do If window Dosn't Open In window 11
Help With Window 11 Is There anybody to Fix Problem
Can someone help me fix this BGInfo error?
Hello, I'm having a problem. I'm the IT specialist of a company. Then a host turns on a computer it gets an error message "Cannot find the configuration file 'C:\BGInfo\bginfo2.bgi/SILENT.bgi' do you want to create a new file". And when I press…
Process Explorer v17.05 Issue: TCP/IP Properties Tab Blank
Trying to troubleshoot a few issues, however unable to view information in Process Explorer v17.05 When I right click to view properties of a process, parent or child I run into this Issue: TCP/IP Properties Tab Blank TCP View shows limited data as well,…
Bug Report: tcpview bad IPv6 name resolution
TCPView v4.19 on Windows 11 With "Resolve names" OFF, tcpview displays the local and remote IPv6 addresses. With "Resolve names" ON, it produces spurious "names" that look like IPv4 addresses, and then attempts to resolve…
Sysmon DNS Query Support
I have been trying to generate Sysmon Event ID 22 DNS Query logs using the below xml format <Sysmon schemaversion="4.90"> <EventFiltering> <DnsQuery onmatch="exclude" /> </EventFiltering>…
Fvevol.sys blue screen + Critical_process_died blue screen error
Hey there, I went to turn on my computer today (It is a lenovo legion that has been working since christmas windows 11), and within seconds of logging in I got a Fvevol.sys blue screen error. After restarting I got a blue screen immediately after boot…
psshutdown to remote hibernate pc getting Couldn't access PCXX normal shutdown works fine
So I'm trying to remotely hibernate a PC on my home network. Topline: normal remote shutdown using shutdown.exe works fine but doesn't support remote hibernation, only shutting down or resetting and psshutdown attempts to connect to the remote pc but…
Sysmon DNS Query Support
I have been trying to generate Sysmon Event ID 22 DNS Query logs using the below xml format <Sysmon schemaversion="4.90"> <EventFiltering> <DnsQuery onmatch="exclude" /> </EventFiltering>…
Sysinternals Procmon Unable to Sort Columns
Can you sort columns in Procmon? Have tried logging in as user and Admin same result Clicked on header column and nothing Moved col to far left and no response.
Disk2VHD via CMD no VSS option
When using Disk2VHD from the command line, it seems there is a bug that we have to provide a parameter, while there is no parameter to use vss for the image. Based on the help and documentation it seems when using no parameter it uses VSS, even the…
Sysinternals RDCMan Experience options not working
Hello Experience options not working on added servers on last version of rdcman and windows 10 20H2