ProcMonXv2
ProcMonXv2 copied to clipboard
can etw file event support correlating filepath?
can ProcMonXv2 support correlating filepath for etw fileio event, especially for filerenam event?
Yes, it's possible, by correlating the file unique key... but it requires work, which I didn't get around to yet :) But I'm happy to receive PRs...
thanks for reply, but when will this feature be added, do you have a plan?
No specific plan, as I am currently juggling several projects. I'll see if I can plan for this in the near future.