Process Monitor v3.50 Process Monitor now includes a /runtime switch to control headless capture duration, correctly shows picoprocesses, displays details for file system APIs introduced in Windows 10, and includes numerous minor improvements and bug fixes. Autoruns v13.82 This Autoruns release shows Onenote addins and fixes several bugs. Du v1.61 This update to Disk Usage…


Bginfo v4.25 This release fixes a bug introduced in v4.20 that caused Bginfo to read ASCII text files incorrectly.

Sysmon v7.01 This release fixes a bug in v7.01 that could cause the sysmon config change event to be corrupt, as well as one that prevented registry keys from being reported with abbreviated root key names (e.g. HKLM).

Sysmon v7.0 Sysmon now logs file version information, and the option to dump the configuration schema adds the ability to dump an older schema or dump all historical schemas.

Bginfo v4.24 This update to Bginfo fixes reported regressions in v4.23 and is compatible with all .bgi files except those created by v4.23.


Autoruns v13.81 This update to Autoruns fixes a Wow64 bug in Autorunsc that could cause 32-bit paths to result in ‘file not found’ errors, and expands the set of images not considered part of Windows for the Windows filter in order to reveal malicious files masquerading as Windows images. Bginfo v4.23 This update to Bginfo…


Sysmon v6.20 This Sysmon release adds the ability to change the Sysmon service and driver names to foil malware that use them to detect its presence. AccessChk v6.20 This update to AccessChk, a command-line utility that reports effective access and can dump access control lists, fixes a bug in that could cause it to crash…


Sysmon v6.10 This update to Sysmon, a background monitor that records activity to the event log for use in security incident detection and forensics, adds monitoring of WMI filters and consumers, an autostart mechanism commonly used by malware, and fixes a bug in image load filtering. Process Monitor v3.40 Process Monitor, a file system registry,…


Sysmon v6.02 This release of Sysmon, an advanced background monitor that records process-related activity to the event log for use in intrusion detection and forensics, fixes a bug in the named pipe monitoring logic that could cause a bluescreen crash. Sigcheck v2.55 This update to Sigcheck, a command-line utility that reports detailed information about images,…