Boot Logging with Process Monitor

preview_player
Показать описание
Process Monitor is a powerful tool, mostly used for real-time logging of file system, Registry, Process/Thread and network activity.
It can also log Windows boot operations if so configured!
Рекомендации по теме
Комментарии
Автор

Hi Pavel, Good to make people aware of how powerful PM is for troubleshooting. If it does end up being a mini series, an advanced topic might be the altitudes of minifilters and how PM supports the /altitude switch if needed to gain visibility.

ek
Автор

Hi Pavel, I'm following you from Colombia. You have a deep understanding of Windows architecture. I've been reading Windows Internals 7th and taking notes for several months now.

cryptosthefuture
Автор

How process Monitor driver handles transfering such amount of data to user space? Does it have its own thread worker to write data to some shared memory region that being read by ProcMon?

Riketta
Автор

How to crash the Universe 101:
Ask AI or God or [insert random diety here]
What is going on when windows boot up?
... or watch smart people solving it

patrickjankun
welcome to shbcf.ru