Looking for RoboCopy GUI and RichCopy
I was troubleshooting somebody else's computer and needed to back up their files while excluding some stuff. Microsoft used to put out a free utility called RoboCopy GUI that helped setting up the parameters for robocopy and made it easier to copy/paste…
Connect to Azure AD joined client with RDCMan
I love Remote Desktop Connection Manager (RDCMan) and I use it every day. However, I can't get it to connect to an Azure joined Win10/11 device (using mstsc.exe works). Is there a way to make it work on RDCman or is anyone updating RDCMan with this…
Powershell Script as a scheduled task errors when I try to connect to Excel worksheet to add data.
My PowerShell script runs fine when I execute it manually. But when I run it from the task scheduler either manually or triggered it errors. $excel = New-Object -ComObject excel.application $workbook = $excel.Workbooks.Add() Errors start here: All three…
Procmon Boot-Logging and Network traffic
I have a freshly loaded and patch win11 22H2 device. I can use procmon to capture and see network summary and traffic all day long. if I setup boot-logging and reboot the device and force network traffic once the device is backup up and then go…
Unable to stop or uninstall Sysmon 15.0
Since the new Sysmon version 15.0 we have been unable to stop the service or uninstall the application. As you can see the service is unable to be stopped even when trying to uninstall it. We've tried this as administrator, System and through an SCCM…
Print Monitors gone after changing them in Autorun
Hi, Mocking around (uncheck to disable) with printer monitors in Autorun64 (14.0.9.0). Got an errors "Failed to disable" from Autorun and when I was finished HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Monitors was empty.…
procdump: bug when using perf.counter as perf.threshold for when a process has been running at Y% usage for X amount of time
I'm trying to use ProcDump to create a memdump when my process has been using basically 100% of a single core for over an hour. Here's the problem though; when using the parameter -p "\Process(processname)\% Processor Time" value (Performance…
[Sysmon 15.12] Server crashes from time to time with Sysmon v15.12
We had a crash after 20 minutes of the installation of Sysmon 15.12. In the system event log we've found this message: The computer has rebooted from a bugcheck. The bugcheck was: 0x00000139 (0x0000000000000003, 0xffff928901305000, 0xffff928901304f58,…
My processexplorer icon is set as a cpu monitor, but sometimes my laptop freezes for long periods, and all I see are a couple of red dots at the bottom of the icon, can I put it into a different mode that will show me some sort of indication?
I have Process Explorer running with the status bar icon. It's set as a cpu monitor. I've been using PE for a long time. I've set it up on this new laptop, but for some reason the PE icon is only showing anything happening in about the last pixel row of…
Sysmon DNS Query Logs - QueryResults Field
How do I display type: 1 for Type A DNS logs in the QueryResults field of Sysmon Event ID 22 DNS Query logs? I tried generating the logs using the below XML format: <Sysmon schemaversion="4.90"> <EventFiltering> <DnsQuery…
How can I make Cacheset appear on the taskbar when it's running?
When I'm running Cacheset 1.2.0.1 on windows 11 home 22H2 it doesn't show up on the taskbar. How can I make it show up?
Procmon scan smb request
Hello, I have an issue on a fileshare server, users are complaining about latency, especially when transferring files to the fileshare server,opening files, or modifying files. I want to launch a procmon on the user workstation to see what what…
when running using procmon /terminate log is corrupted
Hello Guys, I'm configuring procmon to run as a scheduled task and then also using another schedule task to terminate it. Both tasks are configured to run with System. Start task has the following arguments: /AcceptEula /LoadConfig…
Bug in BGInfo - Wrong background with correct text or wrong text on correct background
We have BGInfo being run for all users logging on to our RDS environment using a company background generating some custom info. All servers are virtual. RDS servers use FSLogix. It works most of the time BUT some times BGInfo will: not load the…
Sysmon archive folder too big
Hi all. I'm using sysmon with a lot of rules and I'm having a problem, which has been previously exposed here: The archive folder is getting way too big and I can't find any relevant information on how we should clean this folder. Keeping in mind…
Stable Sysmon 15.x version.
We deployed sysmon v15.12 and ran into an issue with random crash with windows servers. Can you recommend a stable version of sysmon which has a fix to CVE-2023-29343 & CVE-2022-41120. TIA
BSOD DRIVER_OVERRAN_STACK_BUFFER when attaching to w3wp.exe process with VS2019
Recently (as of 2 days ago), every time I try to attach to the IIS process w3wp.exe with Visual Studio 2019 (running on Windows 10), I get the blue screen of death with the DRIVER_OVERRAN_STACK_BUFFER error. Several other people at my organization have…
New startup registry key in Windows 10/11, NOT captured within autoruns
Hi All, While researching the startup behavior of Windows Container (Windows Metro) Apps , like the ones installed through Microsoft Store or native to System (xbox/phone, etc), I came across a new registry key location (different from the known…
400% difference in CPU usage between "Task Manager" and "Sysinternal's Process Explorer"
On one specific server I have 400% difference in CPU usage between "Task Manager" and "Sysinternal's Process Explorer" (both picture taken on the same screenshot, so at the exact same time). What can be the cause of this…