Jump to content

RegMon: Difference between revisions

From Wikipedia, the free encyclopedia
Content deleted Content added
Oorang (talk | contribs)
No edit summary
Oorang (talk | contribs)
No edit summary
Line 1: Line 1:
{{Notability|date=June 2007}}
{{Notability|date=June 2007}}


'''RegMon''' is a tool used in [[system administration]], [[computer forensics]], and application debugging. RegMon was primarily created by [[Mark Russinovic]]<ref>http://blogs.technet.com/markrussinovich/about.aspx</ref> and [[Bryce Cogswell]], employed by [[SysInternals]] prior SysInternals being bought out by [[Microsoft]] in 2006.
'''RegMon''' is a tool used in [[system administration]], [[computer forensics]], and application debugging. RegMon was primarily created by [[Mark Russinovich]]<ref>http://blogs.technet.com/markrussinovich/about.aspx</ref> and [[Bryce Cogswell]], employed by [[SysInternals]] prior SysInternals being bought out by [[Microsoft]] in 2006.


RegMon monitors and records all actions attempted against the [[Microsoft Windows]] [[Windows Registry|Registry]]. RegMon can be used to detect failed attempts to read and write registry keys. It also allows for filtering on specific keys, processes, process IDs, and values.
RegMon monitors and records all actions attempted against the [[Microsoft Windows]] [[Windows Registry|Registry]]. RegMon can be used to detect failed attempts to read and write registry keys. It also allows for filtering on specific keys, processes, process IDs, and values.

Revision as of 21:26, 11 February 2008

RegMon is a tool used in system administration, computer forensics, and application debugging. RegMon was primarily created by Mark Russinovich[1] and Bryce Cogswell, employed by SysInternals prior SysInternals being bought out by Microsoft in 2006.

RegMon monitors and records all actions attempted against the Microsoft Windows Registry. RegMon can be used to detect failed attempts to read and write registry keys. It also allows for filtering on specific keys, processes, process IDs, and values.

RegMon and it's Sister Application FileMon have been replaced in Windows Vista by Process Monitor[2][3].