Sysinternals Tools Updates

From ZoomIt v5.0, RDCMan v2.90, Autoruns, ProcMon, TCPView, VMMap, Sysmon and WinObj

ZoomIt v5.0
ZoomIt, a screen zoom and annotation tool, now supports Windows 11 and antialiased line drawing. Note that under Windows 11 and Windows Server 2022 some UI elements might not react to mouse clicks when zoomed. The temporary workaround until a future Windows update is to store the ZoomIt executable under the Windows or the Program Files directories.

RDCMan v2.90
RDCMan, a tool for managing and connecting to Remote Desktop sessions, receives support for Restricted Admin (/restrictedAdmin from mstsc) and Remote Credential Guard (/remoteGuard from mstsc) and bug fixes.

Autoruns v14.08
This Autoruns update fixes a series of application crashes, now correctly parses paths with spaces passed as command line arguments and improves .arn import functionality.

Process Monitor v3.88
This Process Monitor update mitigates a rare program crash condition.

TCPView v4.17
This TCPView update fixes a crash related to filtering by TCP version.

VMMap v3.32
VMMap, a tool that reports the virtual memory layout of a process, now supports Windows 11.

Sysmon v13.32
This Sysmon update fixes a conflict with FileDelete and FileDeleteDetected events in the same config.

WinObj v3.14
This WinObj update makes the behavior of the object tree control more consistent with Windows when handling right clicks.
 
From Autoruns v14.09, ProcMon v3.89, Sysmon v13.33 and ZoomIt v5.10

Autoruns v14.09
This Autoruns update fixes a bug preventing the enabling/disabling of startup folder items.

Process Monitor v3.89
This Process Monitor update fixes a crash related to context menus.

Sysmon v13.33
This Sysmon update fixes a crash occurring on Windows Server 2012 and improves memory handling for the service.

ZoomIt v5.10
This update to ZoomIt, a screen magnification and annotation tool, now supports pen and touch drawing.
 
I've got to check out ZoomIt as an assistive technology for those with low vision. The fact that it's almost entirely controllable via the keyboard is a huge plus!
 
From AccessChk v6.15, RAMMap v1.61 and Sysmon v13.34

AccessChk v6.15

This update for AccessChk, a tool that shows what kind of accesses specific users or groups have to resources including files, directories, Registry keys, global objects and Windows services, fixes a crash with passing long strings on the command line. Parameters previously limited to MAX_PATH characters have no length restrictions now.

RAMMAp v1.61

This update for RAMMap, a utility that analyzes and displays physical memory usage, fixes problems with the processes tab under Windows 11 and improves the UI on scaled displays.

Sysmon v13.34

This Sysmon update improves performance for UDP network event tracing (the NetworkConnect global option), solves a rare system hang (blue screen) when monitoring ProcessCreate events and a memory/handle leak on ImageLoad events with several exclude clauses.
 
From ZoomIt v6.0, BgInfo v4.30, PsExec v2.40, ProcMon v3.90 and Sigcheck v2.90

ZoomIt v6.0
This major update to ZoomIt, a screen magnification and annotation tool, adds built-in screen recording for easy demo recordings, and now supports Unicode typing input.

BgInfo v4.30
This update to BgInfo, a tool for writing various system information to the desktop wallpaper, now correctly reports Windows 11 and Windows Server 2022 versions.

PsExec v2.40
This update to PsExec, a command line utility for remotely launching processes on Windows computers, adds a new option, -g, for selecting the processor group.

ProcMon v3.90
This Process Monitor update improves event list filtering performance.

Sigcheck v2.90
Sigcheck, a command-line utility that shows file version, timestamp and signatures, now supports custom code integrity policy file checks.
 
From Sysmon v14.0, AccessEnum v1.34, and Coreinfo v3.53

Sysmon v14.0
This major update to Sysmon, an advanced host monitoring tool, adds a new event type, FileBlockExecutable that prevents processes from creating executable files in specified locations. It also includes several performance improvements and bug fixes.

AccessEnum v1.34
AccessEnum, a tool for enumerating file system and registry permissions, now supports paths longer than MAX_PATH characters.

Coreinfo v3.53
This update to Coreinfo, a utility that reports system CPU, memory and cache topology and information, now handles NUMA nodes with more than 64 processors.
 
From Sysmon v14.1, Coreinfo v3.6, AccessEnum v1.35, BgInfo 4.32, and NotMyFault 4.21

Sysmon v14.1
This update to Sysmon, an advanced host monitoring tool, adds a new event type, FileBlockShredding that prevents wiping tools such as Sysinternals SDelete from corrupting and deleting files.

Coreinfo v3.6
This update to Coreinfo, a utility that reports system CPU, memory and cache topology and information, now has an option (-d) for measuring inter-CPU latencies in counter ticks.

AccessEnum v1.35
This update to AccessEnum, a tool that summarizes account permissions on files and folders, fixes a version number mismatch in its version information.

BgInfo v4.32
This update to BgInfo, a tool for displaying system information on screen desktop, correctly reports Windows 11 Insider versions.

NotMyFault v4.21
This update to NotMyFault, a tool used to crash, hang, and cause kernel memory leaks on Windows, now works on ARM64 systems.
 
From ZoomIt v6.1

ZoomIt

This update to ZoomIt, a screen magnification and annotation tool, adds right-justified text input, an option to scale the screen recordings resolution, and usability fixes.
 
From Process Explorer v17.0, Handle v5.0, Process Monitor v3.92, and Sysmon v14.11

Process Explorer
This update to Process Explorer, an advanced process, DLL and handle viewing utility, adds dark theme support, multipane view in the main window with a new threads pane, startup performance optimization and more.

Handle
This update to Handle, a tool that displays information about open handles for any process in the system, adds CSV output with a new -v switch and has an option to print the granted access mask with -g.

Process Monitor
This update to Process Monitor, a utility for observing in real time file system, Registry, and process or thread activity, adds a command-line option for setting the filter driver’s altitude.

Sysmon
This update to Sysmon, an advanced host monitoring tool, fixes a bug preventing FileDeleteDetected events reporting and adds support for ARM64.
 
From Active Directory Explorer v1.52, Contig v1.82, and Sysmon v14.13

Active Directory Explorer v1.52
This update to Active Directory Explorer, an advanced Active Directory viewer and editor, fixes a crash caused by searching for strings in a snapshot longer than object names.

Contig v1.82
This update to Contig, a single-file defragmenter, adds safe DLL loading and support for long command-line arguments.

Sysmon v14.13
This update to Sysmon addresses CVE-2022-41120 by ensuring the archive directory has permissions restricted to the system account.
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top