Brian Baskin
Brian Baskin
Over a bottle of vodka, I finally realized what I was playing at. "[CreateFolder] Explorer.exe:199 > C:\malware" "[CreateFolder] Explorer.exe:199 > C:\malware" "[CreateFolder] Explorer.exe:199 > C:\malware" "[CreateFolder] Explorer.exe:199 > C:\malware" So...
I've kept the ProcmonConfiguration.PMC name because that's what SysInternals has always referred to it as. I don't want people to think that this is using an entirely new file format...
Does the PML file actually exist? This comes up only if Procmon ran and terminated without creating the output file. If this happens you could try running Procmon manually in...
Thank you! The CSV change was a bug in a recent update. The update had meant to only change the csv reading method for the event file, but not for...
Please reopen if there is more to add. Thanks!
To add a data point here, I had the same issues as the originator. Though it told me I needed to install 4.8.0, which I did, then continued to do...