Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 01-09-2023, 17:46
Eugen Eugen is offline
Friend
 
Join Date: Aug 2002
Posts: 17
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 6
Thanks Rcvd at 1 Time in 1 Post
Eugen Reputation: 0
What tool for Monitoring Application

Hello,
Please indicate a tool that can monitor an application at installation or when running, respectively, what files or registers access and/or create.
Thanks,
Reply With Quote
  #2  
Old 01-09-2023, 19:39
DARKER DARKER is offline
VIP
 
Join Date: Jul 2004
Location: Côte d'Ivoire
Posts: 402
Rept. Given: 14
Rept. Rcvd 111 Times in 46 Posts
Thanks Given: 10
Thanks Rcvd at 550 Times in 152 Posts
DARKER Reputation: 100-199 DARKER Reputation: 100-199
Process Monitor is an advanced monitoring tool for Windows that shows real-time file system, Registry and process/thread activity. It combines the features of two legacy Sysinternals utilities, Filemon and Regmon, and adds an extensive list of enhancements including rich and non-destructive filtering, comprehensive event properties such as session IDs and user names, reliable process information, full thread stacks with integrated symbol support for each operation, simultaneous logging to a file, and much more. Its uniquely powerful features will make Process Monitor a core utility in your system troubleshooting and malware hunting toolkit.

Home/Download:
Code:
https://learn.microsoft.com/en-us/sysinternals/downloads/procmon
Reply With Quote
The Following User Says Thank You to DARKER For This Useful Post:
niculaita (01-10-2023)
  #3  
Old 01-10-2023, 02:33
Zeokat Zeokat is online now
Friend
 
Join Date: Dec 2017
Posts: 65
Rept. Given: 0
Rept. Rcvd 9 Times in 6 Posts
Thanks Given: 283
Thanks Rcvd at 166 Times in 43 Posts
Zeokat Reputation: 9
Maybe PRIMO (Program Installation Monitor) can help (i never tested it):

Code:
https://members.tripod.com/randy_hall/download.htm
Reply With Quote
The Following User Says Thank You to Zeokat For This Useful Post:
niculaita (01-10-2023)
  #4  
Old 01-10-2023, 03:10
Eugen Eugen is offline
Friend
 
Join Date: Aug 2002
Posts: 17
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 6
Thanks Rcvd at 1 Time in 1 Post
Eugen Reputation: 0
Thanks for the suggestions, I will try both.
Reply With Quote
  #5  
Old 01-10-2023, 05:15
uranus64 uranus64 is offline
VIP
 
Join Date: Mar 2011
Location: EE
Posts: 308
Rept. Given: 589
Rept. Rcvd 462 Times in 140 Posts
Thanks Given: 403
Thanks Rcvd at 225 Times in 75 Posts
uranus64 Reputation: 400-499 uranus64 Reputation: 400-499 uranus64 Reputation: 400-499 uranus64 Reputation: 400-499 uranus64 Reputation: 400-499
Try also SysTracer.

Info here:
Quote:
https://www.blueproject.ro/systracer
Download here:
Quote:
http://www.blueproject.ro/systracer/download
Reply With Quote
The Following 2 Users Say Thank You to uranus64 For This Useful Post:
alekine322 (01-13-2023), niculaita (01-10-2023)
  #6  
Old 01-11-2023, 00:20
bolo2002 bolo2002 is offline
VIP
 
Join Date: Apr 2002
Posts: 567
Rept. Given: 107
Rept. Rcvd 14 Times in 13 Posts
Thanks Given: 185
Thanks Rcvd at 222 Times in 143 Posts
bolo2002 Reputation: 14
Quote:
Originally Posted by uranus64 View Post
Try also SysTracer.

Info here:


Download here:
Oh it's still alive since time?i remember of this,it were a good one.
__________________
I like this forum!
Reply With Quote
The Following User Says Thank You to bolo2002 For This Useful Post:
uranus64 (01-11-2023)
  #7  
Old 01-11-2023, 02:47
Artic Artic is offline
Friend
 
Join Date: Jul 2014
Location: target folder
Posts: 106
Rept. Given: 53
Rept. Rcvd 15 Times in 9 Posts
Thanks Given: 157
Thanks Rcvd at 42 Times in 24 Posts
Artic Reputation: 15
DiskPulse might also be an option for monitoring any files written to disk.

the free version is more than enough!

Code:
https://www.diskpulse.com/downloads.html
Reply With Quote
The Following 2 Users Say Thank You to Artic For This Useful Post:
alekine322 (01-13-2023), niculaita (01-11-2023)
  #8  
Old 01-11-2023, 03:48
niculaita's Avatar
niculaita niculaita is offline
Family
 
Join Date: Jun 2011
Location: here
Posts: 1,317
Rept. Given: 941
Rept. Rcvd 87 Times in 59 Posts
Thanks Given: 3,969
Thanks Rcvd at 477 Times in 336 Posts
niculaita Reputation: 87
What about an app that catch insections made by a loader or a dll into an other exe ?
__________________
Decode and Conquer
Reply With Quote
  #9  
Old 01-11-2023, 07:47
TQN TQN is offline
VIP
 
Join Date: Apr 2003
Location: Vietnam
Posts: 320
Rept. Given: 135
Rept. Rcvd 11 Times in 9 Posts
Thanks Given: 122
Thanks Rcvd at 78 Times in 33 Posts
TQN Reputation: 12
Hi niculaita
You can use hollow_hunter or pe-sieve of hasherezade
https://github.com/hasherezade/hollows_hunter
Reply With Quote
The Following 3 Users Say Thank You to TQN For This Useful Post:
alekine322 (01-13-2023), MarcElBichon (01-11-2023), niculaita (01-11-2023)
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 03:32.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2022 )