You can use ProcMon and add a filter with "Path"
(with contains or is if you know the complete path)
For example, to test, I added Path contains "tata" and it has been logged when I created a file "E:\Temp\tata.txt" with Notepad)
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I'm new to SysInternals and I have a text file being created and I'm not sure which .exe or .dll is creating the .txt file.
I'm not good at filtering Procmon. If I can research this while it's not actively writing the file, I would need to be able to filter for a time range as it happens overnight.
Thanks for your help!
You can use ProcMon and add a filter with "Path"
(with contains or is if you know the complete path)
For example, to test, I added Path contains "tata" and it has been logged when I created a file "E:\Temp\tata.txt" with Notepad)