A windows system tool, development in rust. A replacement of procmon, more events and useful filter. Typically can check handle leak for a long time(i.e. a week). because can remove the closed handle.
- more events
- public and unpublished. refer to
monitor events
- public and unpublished. refer to
- more useful filter
- filter one event with some filter condition
- filter two events by match some condition. i.e. handle create and close
- find for events
- easy query language
- mark result of query at scroll bar of TableView
- call stack view
- record original module and monitor change
- convert the virtual address to the offset of module
- translate a module offset to the code location
- easy of use
- syntax highlight for filter expression
- tips
- windows11 x64
- windows10 x64
- windows10 x32