Sysinternals Tools Updates

Hmmmm, now it says Windows 10. I don't know why it did not before. However, I am keeping my custom entry because I want it to say which version of W10 I have so I have created a custom entry to correctly report I have "Windows 10 Pro 64-bit".
 
Okay, I am going crazy now because it is back to Windows 8. Not sure what is happening but I think they have some more work to do on this program. I still like it and since it is easy to customize entries I will keep using it.
 
From Update: Sigcheck v2.4, Sysmon v3.2, Process Explorer v16.1, Autoruns v13.51, AccessChk v6.01 - Sysinternals Site Discussion - Site Home - TechNet Blogs:
Sigcheck v2.4
This update to Sigcheck, a powerful command-line utility that reports image file and signing information, as well as information on certificates, now has an option that will report any certificates installed on the system that do not chain to one of the certificates in the Microsoft certificate trust list (CTL). It also adds the ability to take image information captured from Sigcheck on a system disconnected from the Internet and obtain VirusTotal status from one that’s connected.
Sysmon v3.2
This release of Sysmon, a background service that logs security-relevant process and network activity to the Windows event log, now has the option of logging raw disk and volume accesses, operations commonly performed by malicious toolkits to read information by bypassing higher-level security features. Thanks to David Magnotti for the contribution.
Process Explorer v16.1
Process Explorer now includes a column in the handle view that reports the text version of handle access masks, as well as several bug fixes including one that would result in the suspension of .NET threads when viewed via the stack dialog.
Autoruns v13.51
This release of Autoruns, a comprehensive autostart entry manager, fixes a WMI command-line parsing bug, emits a UNICODE BOM in the file generated when saving results to a text file, and adds back the ability to selectively verify the signing status of individual entries.
AccessChk v6.01
This release of AccessChk, a command-line utility that reports effective and actual access for many different object types including files, registry keys, and services, now handles accounts with long names, fixes a bug that prevented reporting of kernel object accesses when run elevated, and fixes the inadvertent creation of a registry key when querying a non-existent key.
 
From Update: Sysmon v4, Procdump v8, Sigcheck v2.51:

Sysmon v4.0
This release of Sysmon, an advanced background monitor that records process-related activity to the event log for use in intrusion detection and forensics, introduces more powerful filtering capabilities, allowing for both include and exclude rules to be specified for specific events types, as well as complex matching on different event fields.

Procdump v8.0
Procdump, a utility for capturing process dump files based on CPU, memory, and other triggers, has improved support for lightweight reflection dumps on Windows 7 and Windows 8, now creates a named event that can be signaled by another process to gracefully terminate it, does more intelligent default path searches for the debugging tools libraries, and makes trigger timing and repeat behaviors consistent across trigger types.

Sigcheck v2.51
This update to Sigcheck, a command-line utility that reports detailed information about images, including their signatures and VirusTotal status, as well as certificate stores, now cleanses newline and other characters from CSV output to prevent line breaks.
 
Sure wish they would update BGInfo. That is one of my favorite Sysinternals programs but it just does not work correctly for folks using multimonitor setups and different backgrounds on each monitor. Oh well. :( Glad to see they are updating others in the collection. That gives me hope BGInfo will eventually be updated too.
 
From Update: Sigcheck v2.4, Sysmon v3.2, Process Explorer v16.1, Autoruns v13.51, AccessChk v6.01:

Sigcheck v2.4
This update to Sigcheck, a powerful command-line utility that reports image file and signing information, as well as information on certificates, now has an option that will report any certificates installed on the system that do not chain to one of the certificates in the Microsoft certificate trust list (CTL). It also adds the ability to take image information captured from Sigcheck on a system disconnected from the Internet and obtain VirusTotal status from one that’s connected.
Sysmon v3.2
This release of Sysmon, a background service that logs security-relevant process and network activity to the Windows event log, now has the option of logging raw disk and volume accesses, operations commonly performed by malicious toolkits to read information by bypassing higher-level security features. Thanks to David Magnotti for the contribution.
Process Explorer v16.1
Process Explorer now includes a column in the handle view that reports the text version of handle access masks, as well as several bug fixes including one that would result in the suspension of .NET threads when viewed via the stack dialog.
Autoruns v13.51
This release of Autoruns, a comprehensive autostart entry manager, fixes a WMI command-line parsing bug, emits a UNICODE BOM in the file generated when saving results to a text file, and adds back the ability to selectively verify the signing status of individual entries.
AccessChk v6.01
This release of AccessChk, a command-line utility that reports effective and actual access for many different object types including files, registry keys, and services, now handles accounts with long names, fixes a bug that prevented reporting of kernel object accesses when run elevated, and fixes the inadvertent creation of a registry key when querying a non-existent key.
 
Update: Sysmon v6, Autoruns v13.7, AccessChk v6.1, Process Monitor v3.32, Process Explorer v16.2, LiveKd v5.61, and BgInfo v4.21:

Sysmon v6
This release of Sysmon, a background monitor that records activity to the event log for use in security incident detection and forensics, introduces an option that displays event schema, adds an event for Sysmon configuration changes, interprets and displays registry paths in their common format, and adds named pipe create and connection events (thanks to Giulia Biagini for the contribution). Check out the related presentation from Mark’s RSA Conference, “How to Go From Responding to Hunting with Sysinternals Sysmon.”
Autoruns v13.7
Autoruns, an autostart entry point management utility, now reports print providers, registrations in the WMI\Default namespace, fixes a KnownDLLs enumeration bug, and has improved toolbar usability on high-DPI displays.
AccessChk v6.1
This update to AccessChk, a command-line utility that shows effective and actual permissions for file, registry, service, process object manager, and event logs, now reports Windows 10 process trust access control entries and token security attributes.
Process Monitor v3.32
This update of Process Monitor, a file system registry, process and network real-time monitor, adds an option to display process and thread IDs in hexadecimal format, and includes improved toolbar usability on high-DPI displays. It also includes drivers signed to be compatible with the driver signing policy in recent releases of Windows 10.
Process Explorer v16.2
The latest release of Process Explorer, a powerful process management and diagnostic utility, fixes a bug listing Wow64 thread stacks, and includes improved toolbar usability on high-DPI displays. It also includes drivers signed to be compatible with the driver signing policy in recent releases of Windows 10.
LiveKd v5.61
This release of LiveKd, a live-system kernel debugger and dump generator, includes drivers signed to be compatible with the driver signing policy in recent releases of Windows 10.
BgInfo v4.21
This update to BgInfo, a utility that adds system information to the desktop background, fixes a bug that prevented the standalone 64-bit version from working.
 
Thanks for this Corrine. I am a bit surprised to see BgInfo on that list. It was reported in the past it would not be updated "for Windows 10".

I used it for years and it worked great - until Windows 10 came around. Text would became overlapped and unreadable. And if, like me, you used multiple monitors with one extended background image across all monitors, And you BgInfo on a secondary monitor, it would take the portion of the background from the primary monitor and use that on the secondary monitors too. So you would, for example, see two left sides of the background image. :(

Hmmm, something is not right. v4.21 is the same version from 2 years ago and when you download the zip file and look at the dates, the timestamps are still 10/28/2015. :(
 
I commented on the technet update page. It is currently awaiting moderation. So wait and see.
 
May 16: Sysinternals Update: ProcDump v9, Autoruns v13.71, BgInfo v4.22, LiveKd v5.62, Process Monitor v3.33, Process Explorer v16.21:
ProcDump v9
This major update to ProcDump, a utility that enables process dump capture based on a variety of triggers, introduces the ability to take capture multiple dumps sizes. This is particularly useful when capturing crash dumps of applications susceptible to termination due to unresponsiveness (e.g. IIS Ping killing w3wp.exe). This release also adds support for an associated Kernel Dump of the process that includes the kernel stacks of the process.
Autoruns v13.71
This update to Autoruns, a comprehensive autostart execution point manager, adds Microsoft HTML Application Host (mshta.exe) as hosting image so it displays the hosted image details, and now doesn’t apply filters to hosting images.
BgInfo v4.22
This release of Bginfo honors Device Guard policy for VB scripts specified as the source of field data.
LiveKd v5.62
This update to Livekd is signed with a certificate installed in the Win7 RTM trusted roots store.
Process Monitor v3.33
Procmon v3.33 includes bug fixes for destructive event filtering and is signed with certificate installed in the Win7 trusted roots store.
Process Explorer v16.21
This Process Explorer release includes a fix for an intermittent bug in the Virus Total scanning logic, and is signed with Win7 RTM-compatible certificate.



May 22: Sysinternals Update: Sysmon v6.02, Sigcheck v2.55:
Sysmon v6.02
This release of Sysmon, an advanced background monitor that records process-related activity to the event log for use in intrusion detection and forensics, fixes a bug in the named pipe monitoring logic that could cause a bluescreen crash.

Sigcheck v2.55
This update to Sigcheck, a command-line utility that reports detailed information about images, includes a fix for a bug that caused the display of publisher names with commas to be truncated at the first comma.
 
I sure hope they really did do something to BGInfo. Last time they said they updated it, they really didn't. It was the same v4.21, same timestamp and same file size as previously posted. This time, I see it is 4.22, the executable has a new 4/16/2017 time stamp, and the file size has grown a bit. So when I get a chance, I'll try it again and see if they did anything about W10 support (which it lacked :() and proper dual monitor support.
 
Sysinternals Update: Sysmon v6.1, Process Monitor v3.4, Autoruns v13.8, AccessChk v6.11:
Sysmon v6.1
This update to Sysmon, a background monitor that records activity to the event log for use in security incident detection and forensics, adds monitoring of WMI filters and consumers, an autostart mechanism commonly used by malware, and fixes a bug in image load filtering.

Process Monitor v3.4
Process Monitor, a file system registry, process and network real-time monitor, now includes a /runtime switch for terminating monitoring after a specified amount of time, when in hexadecimal mode shows process tree process IDs in hexadecimal, and fixes a bug in automated boot log conversion.

Autoruns v13.8
This release of Autoruns, a utility for viewing and managing autostart execution points (ASEPs), adds additional autostart entry points, has asynchronous file saving, fixes a bug parsing 32-bit paths on 64-bit Windows, shows the display name for drivers and services, and fixes a bug in offline Virus Total scanning.

AccessChk v6.11
This update to AccessChk, a command-line utility that reports effective access and can dump access control lists, adds a cache to improve queries that enumerate multiple objects, and has the -s switch start container enumeration at the specified container when -d is specified.
 
From Sysmon v6.2, AccessChk 6.20, Sigcheck v2.60, Whois v1.20 – Sysinternals Site Discussion:

Sysmon v6.20
This Sysmon release adds the ability to change the Sysmon service and driver names to foil malware that use them to detect its presence.

AccessChk v6.20
This update to AccessChk, a command-line utility that reports effective access and can dump access control lists, fixes a bug in that could cause it to crash when looking up account effective access checks.

Sigcheck v2.60
This release fixes catalog signing and timestamp reporting bugs, and no longer truncates publisher names that include commas.

Whois v1.20
Whois, a command-line utility that reports domain registration information for the specified domain, works with new whois registry server redirects.
 
From Autoruns v13.81, Bginfo v4.23, Handle v4.11 – Sysinternals Site Discussion:

Autoruns v13.81
This update to Autoruns fixes a Wow64 bug in Autorunsc that could cause 32-bit paths to result in 'file not found' errors, and expands the set of images not considered part of Windows for the Windows filter in order to reveal malicious files masquerading as Windows images.


Bginfo v4.23
This update to Bginfo fixes bugs that caused incorrect scaling on Windows 10 multimonitor systems.


Handle v4.11
When run on 64-bit systems, Handle now extracts the 64-bit version to the %TEMP% directory rather than the local directory.
 
I am very disappointed to report that Bginfo still does not work properly on multi-monitor Windows 10 systems. I just don't understand why they cannot fix this. It used to work great with Windows 7. If you have a large image set to span across all your monitors, you cannot get Bginfo to appear only on the secondary monitor (in my case, my right monitor). The only options are the Primary or All monitors.

Also, contrary to settings instructions (regardless which you select) BGinfo alters the background. In my case, it takes the right half of my image and displays it on both monitors. Why?

But also (at least in preview mode - I backed out and did not accept the changes) it wipes out any shortcut icons you have displayed on the monitor, regardless where they are located - that is, even if not under the Bginfo displayed data.

This is too bad because to me, this was a great little program.
 
Last edited:
Apologies, obviously, I've missed a few updates. Following are the most recent:

February 19, 2019, from Sysmon v9.0, Autoruns v13.94

Sysmon v9.0 introduces rule groups that enable the specification of AND or OR matching logic across a set of rules. It also fixes a memory leak in signature verification.

Autoruns 13.94
This Autoruns update fixes a bug that prevented the correct display of the target of image hosts such as svchost.exe, rundll32.exe, and cmd.exe.




December 9, 2018, from Autoruns v13.93, Handle v4.21, Process Explorer v16.22, SDelete v2.02, Sigcheck v2.71, Sysmon v8.02 and VMMap v3.25:
Handle 4.21
This Handle release fixes a race condition that could cause a bluescreen.

ProcessExplorer 16.22
This Process Explorer release fixes a race condition that could cause a bluescreen.

Sdelete 2.02
SDelete now includes a progress filter that reports progress for the disk cleaning phase that purges MFT resident files.

Sigcheck 2.71
This release fixes a crash when attempting to scan small files (< 512 bytes) and resolves issue with incorrect timestamp being reported.

VMMap 3.25
This VMMap update fixes a bug that prevented profiling a 32-bit application on a 64-bit OS.
 
Updates released today:

  • Sysmon v10.0
    This release of Sysmon adds DNS query logging, reports OriginalFileName in process create and load image events, adds ImageName to named pipe events, logs pico process creates and terminates, and fixes several bugs.
  • Autoruns v13.95
    This Autoruns updates adds support for redirected user Shell folders.
 
From Windows Sysinternals

What's New (June 20, 2019)
What's New (September 05, 2019)
  • Sysmon v10.4
    This major update to Sysmon, a security event monitoring service, adds nested rule support to rule groups and “contains any” and “contains all” rule conditions for more flexible filtering, as well as several bug fixes.
  • Process Explorer v16.30 This update to Process Explorer adds a Shared Commit column to the process view, fixes a bug that caused it to terminate when it is configured to run at logon and the system went to battery, and fixes bugs that prevented the system CPU graph from correctly showing multiple sockets.
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top