3 ms·
Original ProcMon used ETW, Event Tracing for Windows; the analogous technology (although very different in style) on Linux is eBPF so that’s what this tool uses
by bboreham 5y ago
Original ProcMon used ETW, Event Tracing for Windows; the analogous technology (although very different in style) on Linux is eBPF so that’s what this tool uses.
- altano 5y agoI think you’re mistaken. ProcMon doesn’t use ETW on Windows and I don’t believe it ever did?
- ale42 5y agoIndeed I don't think so. ProcMon uses a kernel driver for the event tracing.
- bboreham 5y agoSorry about that; I guess I misremembered? This file says it does, though only for network events: https://documentation.help/Process-Monitor/documentation.pdf https://documentation.help/Process-Monitor/documentation.pdf