If I create a file stream, Process Monitor intercepts it with IRP_MJ_CREATE
how to monitor the creation of a named file stream
feizzer
120
Reputation points
https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
How do I get notified when a named file stream is created. I want to do this in Kernel.