Procmon visilibily into Kernel activities

mrboyd 6 Reputation points
2021-04-15T16:07:16.907+00:00

Hi Guys,
Today I had a developer tell me that Procmon could not 'see' actions that occur in kernel mode because they don't cross the system call boundery between user mode and kernel mode, and the filter driver can only see those transactions and not the ones before it. Is this accurate? If it is, is there a way (other than windbg) to catch transaction that happen in Kernel mode?

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
842 questions
No comments
{count} votes