Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC InfoSec Handlers Diary Blog


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Filemon and Regmon are dead, long life to Procmon!

Published: 2009-07-27
Last Updated: 2009-07-27 18:32:41 UTC
by Raul Siles (Version: 5)
1 comment(s)

Frequent reader and contributor, Roseman, called our attention about a new update to the Sysinternals tools announced right before the weekend. The most significant piece of information is that End of Life for Filemon and Regmon is September 1, 2009. Yes, in about one month, two of the most widely used tools for Windows malware analysis and system inspection will say goodbye. The good news is that Procmon (v2.5 at this point) is the natural replacement:

Process Monitor is the replacement for Filemon and Regmon and is much more advanced and scalable than its predecessors. We only aim to make Sysinternals tools work on Windows XP and higher,  we’ve decided that it’s time to retire these venerable utilities that were born in the early days of Sysinternals (then NTinternals) back in 1996. So that you have a chance to say goodbye, we’re announcing now that they will be removed from the site on September 1.

Time to update your tool analysis arsenal! Besides that, it is a good time to check Mark's recent "Pushing the Limits of Windows" series of blog posts, exploring the boundaries of fundamental resources in Windows.

--
Raul Siles
www.raulsiles.com

Keywords: sysinternals
1 comment(s)
Diary Archives