Process Monitor is an advanced Windows monitoring tool that provides real-time visibility into file system, Registry, and process/thread activity. It merges the capabilities of the older Filemon and Regmon utilities while adding powerful enhancements like non-destructive filtering and detailed event properties. Users can capture comprehensive data including session IDs, user names, thread stacks, and process details such as image paths and command lines. The tool supports highly configurable views with movable columns and filters applicable to any event field without losing captured data. It can log tens of millions of events with an architecture that scales to gigabytes of log data, enabling in-depth system troubleshooting and malware hunting. Additional features include a process tree viewer to understand process relationships, boot-time logging, and tooltips for quick access to detailed information. Process Monitor runs on Windows 10 and newer client versions.
Features
- Real-time monitoring of file system, Registry, and process/thread activities
- Combines and enhances legacy tools Filemon and Regmon
- Non-destructive and highly flexible filtering system without data loss
- Captures detailed event properties including thread stacks and session/user IDs
- Scalable logging architecture capable of handling tens of millions of events and large log files
- Process tree view to display relationships between processes
- Boot-time logging of all system operations
- Detailed tooltips and cancellable search for efficient data analysis
Categories
SystemFollow Process Monitor
User Reviews
-
Essential tool