Hacker News new | past | comments | ask | show | jobs | submit login

I think you’re mistaken. ProcMon doesn’t use ETW on Windows and I don’t believe it ever did?



Sorry about that; I guess I misremembered?

This file says it does, though only for network events: https://documentation.help/Process-Monitor/documentation.pdf


Indeed I don't think so. ProcMon uses a kernel driver for the event tracing.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: