Security Basics mailing list archives

Re: How to find a process


From: "Michael Painter" <tvhawaii () shaka com>
Date: Thu, 14 Jun 2007 09:38:51 -1000


----- Original Message ----- From: "Ansgar -59cobalt- Wiechers" <bugtraq () planetcobalt net>
To: <security-basics () securityfocus com>
Sent: Thursday, June 14, 2007 8:30 AM
Subject: Re: How to find a process


On 2007-06-14 Dan Denton wrote:
My apologies to the list. That's Process Explorer, not Process Monitor.

Process Monitor is a successor to Process Explorer. See
http://www.microsoft.com/technet/sysinternals/ProcessesAndThreads/processmonitor.mspx

Umm, I'd say it's more of a successor to Filemon and Regmon.
On my box (I'm using Winpatrol and ZoneAlarm), when I open Process Monitor, I get 10,494 out of 20, 384 events recorded in about two seconds and I don't see an easy way to correlate to a port if that's required. Process Explorer has that neat 'TCP/IP' tab.

--Michael

Current thread: