
To do this, open up File Explorer and paste in \\ \tools. If you’d rather not (or can’t) download an EXE, you can also use the Sysinternals Live folder. There is a way around this which will be touched on later in this Guide. Procmon only runs with elevated permissions so you’ll be prompted to accept this if you have UAC enabled when you run it. Now run procmon by invoking the ~\ProcessMonitor\procmon.exe file.


Finding the Process Accessing an IP Address.

Troubleshooting Applications that Require Admin Rights.Changing Procmon’s Altitude (Capturing Lower-Level Events).Setting up Long-Running Procmon Captures.Exporting and Opening Events to/from Log Files.Highlighting Events and Converting to Filters.Importing and Exporting Procmon Configurations.
