Content
A diversified value of a known host's error appears first in relation to sleep mode
In the event of engaging once the sleep mode after a long habitual absence, system fails consecutively to reach log-in screen and a reset is deemed inevitable to boot fresh; on performing afterwards AdvancedBoot (to fix mbr) it's too late to snipscreen…


Is BGInfo compatible for both ARM64 and X64 platforms?
Hi, I am trying to leverage on BGInfo to set the desktop dynamically. Just want to check whether it is compatible for both ARM64 and X64 platforms as there seems no remarks indicating this. Thanks.


ZoomIT Live zoom Missing Cursor after Windows 11 upgrade
Hi, I've never had any problem with ZoomIT before, but after Windows 11 upgrade the cursor is missing in Live Zoom mode which makes it very hard to navigate.. Anyone else have the same issue? Im running lates official build of Windows 11…


Translation of the Process Monitor software interface
I want to translate the interface of the Process Monitor software I just need help knowing how to translate Thank you
RDCMan Initialization error with incompatible mstscax.dll
We encountered Initialization error prompt with incompatible version of mstscax.dll, when we trying to start RDCman.exe (version 2.90) Have anybody manage to resolve the version incompatibility issue?


Process Explorer - ProcExp152.sys Driver Flagged As Vulnerable
Hello- We are leveraging a new security solution in our environment that adds protection to our endpoints. The XDR solution has a rule that is detecting the driver ProcExp152.sys as being "vulnerable". I have asked our security vendor to…


Sysinternals: Autoruns missing entries?
I've encountered two apps that start with Windows even though they have no entries present/enabled in Autoruns: Foxit PDF Reader has a behavior where it will open on startup on the last PDF document you were looking at; this behavior cannot be disabled…


what is the alternative tool for PsExec
What is the impact for Application repackaging process without "PsExec.exe" tool. What is the alternative tool for PsExec.exe tool?


ZoomIt: how to get from Live Zoom Mode to drawing and back to Live Zoom seamlessly (plus: without losing mouse cursor)?
Maybe I am doing something wrong, but it seems as if it is not possible to get to drawing mode from Live View mode, stop drawing mode nad get back to Live View Mode directly. After the drawing I have to Zoom out and zoom into Live View Mode again,…


In Process explorer the virus total links do not line up properly with the apps.
when clicking on the virus total column, it takes you to virus totals site, but the app show does not match the app in process explorer... tried pausing and restarting virus total, but does not solve this issue.


ADExplorer crashes on Security Compare option
I'm using ADExplorer64 v 1.52. The option to compare snapshots works great but using the Compare Snapshot Security causes the program to crash. Anyone else see this?


Does VMMap support showing memory usage from a dump file
I have a full process memory dump file and I want to show memory usage information by VMMap. I know VMMap can show memory usage information very well of a live process. and I hope it can show this awesome information from a dump file too.
Backup Process Explorer Column Sets
I know Process Explorer uses registry instead of files like a good portable app would and that the registry is at "HKEY_CURRENT_USER\Software\Sysinternals\Process Explorer". I'm sick of setting up Columns sets for the billionth time so I'd…


[Bug report] proc list scroll suddenly freezes when scrolling by mouse wheel
When I try to scroll the process list with a mouse wheel, the scroll stops / sticks / freezes at the end of a single wheel move. Look at the screenshot: a hint on yellow background pops up under cursor (cursor is not visible on screenshot,…
How to fix autoruns entry yellow highlighted?
Hello, I have windows 10 22h2 with autoruns. I also have the app downloaded from Microsoft Store Called Fluent Search. When i am running autoruns i found an entry on logon category highlighted yellow related with Fluent Search. I am…


RDCMan: Not Using RemoteFX Codec
Does RDCMan support the RemoteFX (RFX) codec for RDP? When I connect to an Ubuntu server running xrdp, the latency between the time the mouse moves and the time the display updates is quite long. Other people report that the RemoteFX codec helps…


Autoruns Command Line Tool - issue with output [-o] switch when querying all profiles
When using autorunsc.exe or autorunsc64.exe on systems with multiple profiles, when retrieving the data for all users I have found that the placement of the -o switch affects the output. If you run : autorunsc64.exe -accepteula -nobanner -a *…
ZoomIt: Consistent modifier keys: Use SHIFT for rectangle
ZoomIt allow for drawing rectangles and lines. In Windows Explorer, the key to "create" a rectangle is the SHIFT key. In ZoomIt, SHIFT is used for the straight line, whereas CTRL is used for the rectangle. This is a bit counter-intuitive to…


Sysmon created remote thread to LSASS Process
I have researched some ways to detect LSASS Credential Dumping in my infrastructure. I found that Sysmon often create remote thread (EventCode=8) to lsass.exe that looks very suspicious. Does it legit? Or some malware already injected to my Sysmon…


Sysmon installation problem - virtual win11 arm
Hi, i am using sysmon couple of years so far, always works perfect. Right now, i am trying on macos UTM virtualization and installed fresh windows 11 arm64 version. I am trying to install sysmon, but there is error for which i cannot find…