
This update to Process Monitor, a utility that logs process file, network and registry activity, adds support for multiple filter item selection, as well as decoding for new file system control operations and error status codes. In addition to several bug fixes, this major update to Sysmon adds support for capturing clipboard operations to help incident responders retrieve attacker RDP file and command drops, including originating remote machine IP addresses.

This Process Explorer release includes a fix for an intermittent bug in the Virus Total scanning logic, and is signed with Win7 RTM-compatible certificate. Procmon v3.33 includes bug fixes for destructive event filtering and is signed with certificate installed in the Win7 trusted roots store. This update to Livekd is signed with a certificate installed in the Win7 RTM trusted roots store. This release of Bginfo honors applocker policy for VB scripts specified as the source of field data. This update to Autoruns, a comprehensive autostart execution point manager, adds Microsoft HTML Application Host (mshta.exe) as hosting image so it displays the hosted image details, and now doesn’t apply filters to hosting images.

This release also adds support for an associated Kernel Dump of the process that includes the kernel stacks of the process. This is particularly useful when capturing crash dumps of applications susceptible to termination due to unresponsiveness (e.g. This major update to ProcDump, a utility that enables process dump capture based on a variety of triggers, introduces the ability to take capture multiple dumps sizes.

Sysinternals has been updated as follows:
