Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Monitoring IO like Sysinternals' ProcMon

How does the Process Monitor from Sysinternals monitor file IO activity like it does? If you enable the advanced information, you can see that calls that were previously shown as CreateFile are now shown as IRP_MJ_CREATE which suggests that it hooks some rather low level stuff. Does anyone know exactly what it hooks/how it works?

like image 653
John Zane Avatar asked Dec 06 '25 19:12

John Zane


1 Answers

Perhaps your answer is with this SO post

like image 136
Hannes de Jager Avatar answered Dec 08 '25 23:12

Hannes de Jager



Donate For Us

If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!