RDCMan 2.8 crashes when using Connect Group
Nice to see RDCMan getting some love again! Unfortunately I run into an unhandled exception when using "Connect group": System.NullReferenceException: De objectverwijzing is niet op een exemplaar van een object ingesteld. bij…
Sysinternals
new PROCEXP causes 'netsh trace' to stop running SystemTrace?
I downloaded your new code (16.42), but found a problem with it. I always use 'netsh trace' for all Web connections. For some reason, whenever I run this new PROCEXP, 'netsh trace' on Win7 will NOT capture the 'system trace' information at the…
Sysinternals
Can the command line version of TCPView (tcpvcon) be updated to output ports ?
As the title says, can the command line version of tcpview be updated to output the local and remote ports?
Sysinternals
Sysinternals VMMAP cannot load some MMP files
Trying to debug a problem on a remote machine, I have saved an mmp file and cannot load it. The file will not even load on the machine that generated it. "The specified file does not have a valid VMMap format" At first I thought it was a…
Sysinternals
Displayed version has not been updated in the latest Sysmon v13.22
Is it only me or the latest released Sysmon binary still displays the old version during installation?
Sysinternals
Unable to login to Windows 10
I have Windows 10 Enterprise which is workgroup machine. I have only one local user account in it. I use this local account to login to the system. I don't use Microsoft Account for login. After few weeks, when i try to login it doesn't accept the…
Windows for business | Windows Client for IT Pros | Networking | Network connectivity and file sharing
Sysinternals
What is the disk space limit for FileDelete event archiving?
While playing around with Sysmon I noticed that one of my deleted files weren't archived due to insufficient disk space on one of my machines. This is a sample FileDelete event (EID 23): File Delete archived: RuleName: FileDelete - Files in…
Sysinternals
Certain rule combinations seems to prevent logging of Sysmon events
I'm trying to verify my Sysmon-configuration with small test cases inspired by Atomic Red Team. When checking my test cases for Mshta (Mitre Att&ck T1218.005) I noticed that certain combinations of rules seems to prevent logging of Sysmon…
Sysinternals
Is it a bug in Autoruns that if file "c:\Program" exists some .lnk paths in Autoruns are shown as broken?
Hi. I've found a possible bug in Autoruns. If there's a file named "Program" in C:\ then all the .lnk autorun entries in StartUp folders that point to %ProgramFiles(x86)% or %ProgramFiles% will show broken paths. Should it be reported…
Sysinternals
bginfo stops showing after refreshing it
Hi We use bginfo on all windows server OS since years. On Windows 2012 (not R2) the refreshing bginfo information with the following command: "C:\Program Files\BgInfo\bginfo.exe" "C:\Program Files\BgInfo\w2012.bgi" /Timer:0…
Sysinternals
du fails with "not a valid application for this OS platform"
the strange thing is, it was working fine a short time ago. Maybe a Win 10 update broke it. https://learn.microsoft.com/en-us/sysinternals/downloads/du .\du.exe Program 'du.exe' failed to run: The specified executable is not a valid…
Sysinternals


Procmon v3.82 does not allow keyboard shortcuts in the dialog boxes
Procmon v3.82 does not allow keyboard shortcuts in the dialog boxes. When in any of the dialog boxes, such as Event Properties, Process Monitor Filter, keyboard shortcuts seem to go to the main window. For example, using Ctrl-C copies text from the…
Sysinternals

Process Explorer shows incorrect Autostart Location
Using Sysinternals Process Explorer (procexp.exe / procexp64.exe) version 16.42, when opening the properties of a service host process (svchost.exe) running a specific service or service host group (in my case, netsvcs), the Autostart Location on the…
Sysinternals
Detecting ScareCrow and the like...
In reading FireEye's recent blog on "Smoking out a DARKSIDE affiliate's supply chain software compromise" I followed the thread to one of the noted frameworks, ScareCrow. See github - optiv/ScareCrow . In reviewing process hollowing and…
Sysinternals
Process Explorer (Filter Processes...)
what exactly does Find --> Filter Processes do? i click on the menu item expecting to see some sort of dialog box where i can include/exclude processes that are displayed. i get nothing happening? anybody have this working? thanks!!
Sysinternals
Procmon v3.82 will not add a filter when using context menu | Include | <any menu item>
Procmon v3.82 will not add a filter when using context menu | Include | <any menu item> Where <any menu item> is any of the available menu options such as Path.
Sysinternals
Autoruns virus total shows MOST microsoft files as NOT SIGNED on BOTH my computers (EXTREMELY desperate for help)
Notice the strange differences in verification? From Microsoft corp To (verified) To Microsoft Windows (verified) And then the files that DO have valid signatures according to virus total all display MICROSOFT CORPORATIONS (verified)…
Sysinternals
Sysmon help: I’m unable to filter on EID 13, data name ‘Details’
Seems I’m able to log ‘Details’ with an exclude nothing/include everything but can’t filter what I log. Keep getting a config update error of: “Element ‘Details’ is unexpected according to content model of parent element ‘RegistryEvent’.” Am I…
Sysinternals
[Small nitpick bug] Dump files for processes that have multiple dots in name have wrong suggested name
The dump files I'm talking about are the ones created by Right Click -> Create Dump. The suggested name for the dump files is usually the prefix + ".dmp", eg: procexp64.dmp But if the program has multiple dots in it's name, for example:…
Sysinternals
Autoruns 13.100 "Publisher" field bugged (resulting in broken MS/Windows filtering)
Most, but not all, entries show up with the publisher as "(Verified) ", i.e. it just says "Verified" and nothing after it, normally it would say something like "(Verified) Microsoft Corporation". Comparing to a saved file…