ProcMonXv2 icon indicating copy to clipboard operation
ProcMonXv2 copied to clipboard

About the methods of process monitoring

Open hardtolose opened this issue 2 years ago • 1 comments

I am making a lightweight windows process monitoring demo, which can sense the start and end of the process in real time, I do not want to use NT kernel-mode driver. nor ETW or WMI, they will have a certain delay, poor effect for instantaneous processes.

Is there any other way to solve this problem?

hardtolose avatar Nov 01 '23 02:11 hardtolose

You can always enumerate processes every interval (1 sec, 500 msec, whatever), and compare with the previous list for changes. This is how Task Manager and Process Explorer work.

zodiacon avatar Nov 01 '23 12:11 zodiacon