Jump to content

SysInternals Tools Updated


Corrine

Recommended Posts

I always keep Process Explorer handy on a USB stick. Never know when you might need it!
just the other day it came in handy in defeating a fake antiviurs2011 that none of the malware or antivirii would help with - including those online.
Link to comment
Share on other sites

  • 11 years later...

From Process Explorer v17.0, Handle v5.0, Process Monitor v3.92, and Sysmon v14.11

 

Process Explorer
This update to Process Explorer, an advanced process, DLL and handle viewing utility, adds dark theme support, multipane view in the main window with a new threads pane, startup performance optimization and more.
 
Handle
This update to Handle, a tool that displays information about open handles for any process in the system, adds CSV output with a new -v switch and has an option to print the granted access mask with -g.
 
Process Monitor
This update to Process Monitor, a utility for observing in real time file system, Registry, and process or thread activity, adds a command-line option for setting the filter driver’s altitude.
 
Sysmon
This update to Sysmon, an advanced host monitoring tool, fixes a bug preventing FileDeleteDetected events reporting and adds support for ARM64.

  • Like 1
Link to comment
Share on other sites

From ProcDump v11.0, ProcDump 1.3 for Linux, and Process Explorer v17.01

 

ProcDump v11.0
This update to ProcDump, a command-line utility for generating memory dumps from running processes, adds ModuleLoad/Unload and Thread Create/Exit triggers, removes Internet Explorer JavaScript support, and improves descriptive text messages.

 

ProcDump 1.3 for Linux
This update to ProcDump for Linux changes the CLI interface to match ProcDump for Windows, and adds a new process group trigger (-pgid) to allow monitoring all processes running in the same process group.

 

Process Explorer v17.01
This update to Process Explorer fixes a crash when right-clicking an empty area of the lower pane threads tab and improves menu rendering.

  • Like 1
Link to comment
Share on other sites

  • 1 month later...
  • 1 month later...

RDCMan v2.92, Sysmon v14.14, and ZoomIt v6.12

 

RDCMan v2.92

This update to RDCMan, a tool for managing and connecting to Remote Desktop sessions, fixes a naming error impeding plugin operation, updates the icon set, and fixes mstscax.dll load on some systems where initialization would previously fail.
 
Sysmon v14.14

This update to Sysmon, an advanced host monitoring tool, fixes a timeout occurring with FileDelete and FileDeleteDetected events on low-speed media.
 
ZoomIt v6.12

This update to ZoomIt, a screen magnification and annotation tool, eliminates drawing artifacts occurring when changing magnification, changing pen width, or combining these steps, and improves drawing settings persistence.

Link to comment
Share on other sites

  • 1 month later...

Sysmon 1.1 for Linux, Contig v1.83, ProcDump 1.4.1 for Linux, and Process Monitor v3.93

 

Sysmon 1.1 for Linux
This update to Sysmon for Linux, an advanced host monitoring tool, adds support for a wider range of distributions (e.g., RHEL) by leveraging BTF enabled kernels.
 
Contig v1.83
This release for Contig, a single-file defragmenter, fixes a bug preventing the 64-bit Contig64.exe from working, fixes a path parsing bug, and adds support for ARM64.
 
ProcDump 1.4.1 for Linux
This update to ProcDump for Linux, a flexible tool for manual and trigger-based process dump generation, adds the capability to generate dumps based on the contents of an exception message.
 
Process Monitor v3.93
Process Monitor, a utility for observing real-time file system, Registry, and process or thread activity, receives fixes for several user interface and log file bugs.

  • Like 1
Link to comment
Share on other sites

  • 3 weeks later...

Process Explorer v17.03, PsTools v2.5, Sysmon 1.1.1 for Linux, and TCPView v4.18

 

Process Explorer v17.03
This update to Process Explorer, an advanced process, DLL, and handle viewing utility, adds improved packaged app support, fixes a dark mode bug, and fixes a security bug.
 
PsTools v2.5
This update to PsTools, a suite of programs for interacting with local or remote Windows systems, fixes command-line argument processing issues in several tools.
 
PsExec v2.41
PsExec, a light-weight telnet/ssh alternative for launching processes on Windows, now supports file paths longer than MAX_PATH characters.
 
PsPing v2.12
PsPing, a tool implementing the standard ping functionality, alongside TCP/UDP latency and bandwidth measurements, receives bugfixes for its benchmarks, and now uses random data for communication buffers.

 

PsShutdown v2.6
PsShutdown, a command-line utility for managing local or remote shut down, reboot, logoff, or lock for Windows computers, now displays its notification dialog on the target machine, and has a new flag, -x, for turning the monitor off, required to initiate Modern Standby where applicable.

 

PsFile v1.04, PsGetSid v1.46, PsInfo v1.79, PsKill v1.17, PsList v1.41, PsLogList v2.82, PsPasswd v1.25, PsService v2.26, and PsSuspend v1.08 have been also updated to work with long file paths and command lines.
 
Sysmon 1.1.1 for Linux
This update to Sysmon for Linux removes support for Ubuntu 18.04, Debian 10 and includes other fixes.
 
TCPView v4.18
TCPView, a Windows program that shows detailed listings of all TCP and UDP endpoints, receives a fix for a crash that can occur when receiving events in certain cases, and improvements for the dark mode.

  • Like 1
  • +1 1
Link to comment
Share on other sites

  • 2 weeks later...
  • 1 month later...

From ZoomIt v7.0

 

ZoomIt v7.0

 

This update to ZoomIt, a screen magnification and annotation tool, adds the ability to screen record cropped regions or a specific window, and lets you snip regions of the screen or zoomed views to the clipboard or to a file in a single gesture.

Link to comment
Share on other sites

  • 3 weeks later...

From Process Monitor v3.94

 

Process Monitor v3.94

 

This update to Process Monitor, a utility for observing real-time file system, Registry, and process or thread activity, improves handling of incomplete Procmon Log files (.pml), and restores "Copy All" functionality in the Event Properties window.

  • Like 1
Link to comment
Share on other sites

  • 3 weeks later...

Sysmon v15.0, Autoruns v14.1, and Process Monitor v3.95

 

Sysmon v15.0
This update to Sysmon, an advanced host security monitoring tool, sets the service to run as a protected process, hardening it against tampering, adds a new event, FileExecutableDetected, for when new executable images are saved to files, and fixes a system hang occurring in certain situations due to an interaction between network and file system events.
 
Autoruns v14.1
This update to Autoruns, a utility for monitoring startup items, fixes a bug with detecting non-shortcut files in startup folders, fixes a bug with handling non-UNC, non-absolute paths, and improves theming support.
 
Process Monitor v3.95
This update to Process Monitor fixes a crash on loading certain PML files and improves boot logging.

  • Like 1
Link to comment
Share on other sites

  • 4 weeks later...

ZoomIt v7.1, ProcDump 2.0 for Linux, Process Explorer v17.05, RDCMan v2.93 and VMMap v3.33

 

ZoomIt v7.1
This update to ZoomIt adds audio capture to screen recording.

 

ProcDump 2.0 for Linux
ProcDump for Linux, a flexible tool for manual and trigger-based process dump generation, receives two new .NET GC triggers (-gcm and -gcgen) and updates the existing memory trigger to allow for multiple thresholds.

 

Process Explorer v17.05
This update to Process Explorer, an advanced process, DLL, and handle viewing utility, fixes a crash generated by the process list, fixes a bug with thread affinity decoding on systems with multiple processor groups (more than 64 processors / cores), and makes Escape key handling more consistent.

 

RDCMan v2.93
This update to RDCMan, a tool for managing and connecting to Remote Desktop sessions, re-enables the option to scale thumbnails under the display settings.

 

VMMap v3.33
This update to VMMap, a tool that reports the virtual memory layout of a process, removes automatic loading of dbghelp.dll under "C:\Debuggers".

  • Like 2
  • Thanks 1
Link to comment
Share on other sites

  • 2 months later...

ProcDump 2.2 for Linux, Sysmon 1.3 for Linux, Process Monitor v3.96, and SDelete v2.05

 

ProcDump 2.2 for Linux
This update to ProcDump for Linux adds support for Azure Linux and fixes a couple of memory leaks.
 
Sysmon 1.3 for Linux
This update to Sysmon for Linux adds support for file hashes and fixes a bug with rule case matching.
 
Process Monitor v3.96
This update to Process Monitor speeds up the clear events operation, adds a security fix, and several bug fixes.
 
SDelete v2.05
This update to SDelete, a command line utility for secure file deletion, fixes console output and improves command line parameter parsing.

  • Like 2
Link to comment
Share on other sites

  • 2 weeks later...
  • 3 weeks later...

Sysmon v15.1 and ZoomIt v7.2

 

Sysmon v15.1
This update to Sysmon improves file hash and delete performance, adds a summary message on events dropped due to high system load, fixes a crash during uninstall, and fixes a system hang.

 

ZoomIt v7.2
This update to ZoomIt adds translucent highlighter and blur to draw mode, microphone selection for recording, and copies the recorded file to the clipboard.

Link to comment
Share on other sites

  • 2 months later...
  • 4 weeks later...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...