FileMon/RegMon Now Integrated into Process Monitor
Our old friends FileMon and RegMon have now been integrated into a tool called Process Monitor. This new tool integrates the functionality of file access capturing from FileMon with the registry access capturing of RegMon into a single interface.
Process Monitor now includes some much needed feature enhancements from the original individual tools. The neatest of these is...
...the ability to now gather a summary report from the capture that shows -- for processes, files, and registry calls -- the name of the process or registry location, the first and last event on that item, and how many times that items was read from, written to, or accessed in any way.
Also, the filtering functions are no longer destructive. This means that you can move from filter to filter without losing data.
The combination of these two feature sets takes a lot of the tedious and manual work out of using the tools -- which often led to administrators not using them.
You can download Process Monitor from Microsoft's web site at: http://www.microsoft.com/technet/sysinternals/processesandthreads/processmonitor.mspx