Process Monitor X (ProcMonX)

Discussion in 'other software & services' started by WildByDesign, Jan 16, 2018.

  1. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    Process Monitor X (ProcMonX)
    By Pavel Yosifovich

    Extended Process Monitor-like tool based on Event Tracing for Windows

    Link: https://github.com/zodiacon/ProcMonX
    First Testing Preview Build: https://github.com/zodiacon/ProcMonX/releases/tag/0.1-preview1



    Something to keep an eye on. This does not utilize a kernel-mode driver as most others do since this utilizes Event Tracing instead which has been around for quite some time but has been more popular among defenders in recent times. Tons of potential in Event Tracing.

    Anyway, this is just a first working prototype for initial testing. So far it's working relatively well here. But something to keep an eye on going forward though.

    This is one of the main authors for Windows Internals books and has a whole pile of nice free / open source apps on his Github (including GFlagsX).
     
  2. NormanF

    NormanF Registered Member

    Joined:
    Feb 20, 2009
    Posts:
    2,870
    I'm sticking with Process Hacker. Its a good replacement for the Windows Task Manager.
     
  3. guest

    guest Guest

    Soon there will be a blog post about it (and a screenshot of this tool can be seen in the following tweet)
     
  4. guest

    guest Guest

    Pavel's Blog
    ProcMon vs. ProcMonX
    January 17, 2018
     
  5. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,788
    Location:
    .
  6. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    This is getting quite powerful. Very nice. Also, we need to understand that we cannot compare this to Process Hacker or Process Explorer since it is quite different. This is more for monitoring/logging very much the same as Process Monitor (ProcMon) but done in a different method as the blog explains. Great for gathering information on malware and such.

    I have been compiling the binary myself with each and every commit that Pavel makes because it keeps getting better.
     
  7. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,788
    Location:
    .
    :thumb: thanks
     
  8. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    You're welcome. :)
     
  9. guest

    guest Guest

  10. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    @mood Thank you. My RSS feeds for Github accounts seem to be delayed by hours in the past few weeks for some reason.
     
  11. ArchiveX

    ArchiveX Registered Member

    Joined:
    Apr 7, 2014
    Posts:
    1,500
    Location:
    .
    Process Monitor X (ProcMonX)

    Nice GUI. :thumb:
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.