Process Monitor is a new enhanced freeware, real-time file system, Registry and process/thread activity software built from scratch by the erstwhile Sysinternals team in Microsoft.

Enhancements over the previous standalone versions of Regmon and Filemon include:

? Monitoring of process and thread startup and exit, including exit status codes
? Monitoring of image (DLL and kernel-mode device driver) loads
? More data captured for operation input and output parameters
? Non-destructive filters allow you to set filters without losing data
? Capture of thread stacks for each operation make it possible in many cases to identify the root cause of an operation
? Reliable capture of process details, including image path, command line, user and session ID
? Filters can be set for any data field, including fields not configured as columns
? Process tree tool shows relationship of all processes referenced in a trace
? Process tooltip for easy viewing of process image information