Sysinternals Suite

Sysinternals Suite März 2023

Process Explorer v17.03

This update to Process Explorer, an advanced process, DLL, and handle viewing utility, adds improved packaged app support, fixes a dark mode bug, and fixes a security bug.

PsTools v2.5

This update to PsTools, a suite of programs for interacting with local or remote Windows systems, fixes command-line argument processing issues in several tools.

PsExec v2.42

PsExec, a light-weight telnet/ssh alternative for launching processes on Windows, now supports file paths longer than MAX_PATH characters.

PsPing v2.12

PsPing, a tool implementing the standard ping functionality, alongside TCP/UDP latency and bandwidth measurements, receives bugfixes for its benchmarks, and now uses random data for communication buffers.

PsShutdown v2.6

PsShutdown, a command-line utility for managing local or remote shut down, reboot, logoff, or lock for Windows computers, now displays its notification dialog on the target machine, and has a new flag, -x, for turning the monitor off, required to initiate Modern Standby where applicable.

PsFile v1.04, PsGetSid v1.46, PsInfo v1.79, PsKill v1.17, PsList v1.41, PsLogList v2.82, PsPasswd v1.25, PsService v2.26, and PsSuspend v1.08

have been also updated to work with long file paths and command lines.

Sysmon 1.1.1 for Linux

This update to Sysmon for Linux removes support for Ubuntu 18.04, Debian 10 and includes other fixes.

TCPView v4.18

TCPView, a Windows program that shows detailed listings of all TCP and UDP endpoints, receives a fix for a crash that can occur when receiving events in certain cases, and improvements for the dark mode.
Sysmon 1.1 for Linux

This update to Sysmon for Linux, an advanced host monitoring tool, adds support for a wider range of distributions (e.g., RHEL) by leveraging BTF enabled kernels.

Contig v1.83

This release for Contig, a single-file defragmenter, fixes a bug preventing the 64-bit Contig64.exe from working, fixes a path parsing bug, and adds support for ARM64.

ProcDump 1.4.1 for Linux

This update to ProcDump for Linux, a flexible tool for manual and trigger-based process dump generation, adds the capability to generate dumps based on the contents of an exception message.

Process Monitor v3.93

Process Monitor, a utility for observing real-time file system, Registry, and process or thread activity, receives fixes for several user interface and log file bugs.
RDCMan v2.92

This update to RDCMan, a tool for managing and connecting to Remote Desktop sessions, fixes a naming error impeding plugin operation, updates the icon set, and fixes mstscax.dll load on some systems where initialization would previously fail.

Sysmon v14.14

This update to Sysmon, an advanced host monitoring tool, fixes a timeout occurring with FileDelete and FileDeleteDetected events on low-speed media.

ZoomIt v6.12

This update to ZoomIt, a screen magnification and annotation tool, eliminates drawing artifacts occurring when changing magnification, changing pen width, or combining these steps, and improves drawing settings persistence.
Active Directory Explorer v1.52

This update to Active Directory Explorer, an advanced Active Directory viewer and editor, fixes a crash caused by searching for strings in a snapshot longer than object names.

Contig v1.82

This update to Contig, a single-file defragmenter, adds safe DLL loading and support for long command-line arguments.

Sysmon v14.13

This update to Sysmon addresses CVE-2022-41120 by ensuring the archive directory has permissions restricted to the system account.
Process Explorer v17.02

This update to Process Explorer fixes two bugs that can lead to crashes and another that leads to an unexpected dialog in an error case.

Sysmon v14.12

This update to Sysmon fixes a bug related to volumes without file system security.
ProcDump v11.0

This update to ProcDump, a command-line utility for generating memory dumps from running processes, adds ModuleLoad/Unload and Thread Create/Exit triggers, removes Internet Explorer JavaScript support, and improves descriptive text messages.

ProcDump 1.3 for Linux

This update to ProcDump for Linux changes the CLI interface to match ProcDump for Windows, and adds a new process group trigger (-pgid) to allow monitoring all processes running in the same process group.

Process Explorer v17.01

This update to Process Explorer fixes a crash when right-clicking an empty area of the lower pane threads tab and improves menu rendering.
Process Explorer v17.0

This update to Process Explorer, an advanced process, DLL and handle viewing utility, adds dark theme support, multipane view in the main window with a new threads pane, startup performance optimization and more.

Handle v5.0

This update to Handle, a tool that displays information about open handles for any process in the system, adds CSV output with a new -v switch and has an option to print the granted access mask with -g.

Process Monitor v3.92

This update to Process Monitor, a utility for observing in real time file system, Registry, and process or thread activity, adds a command-line option for setting the filter driver’s altitude.

Sysmon v14.11

This update to Sysmon, an advanced host monitoring tool, fixes a bug preventing FileDeleteDetected events reporting and adds support for ARM64.
  • ZoomIt v6.11
    • This update to ZoomIt fixes a crash with right-justified text input and improves multiline text handling.
  • ZoomIt v6.1
    • This update to ZoomIt, a screen magnification and annotation tool, adds right-justified text input, an option to scale the screen recordings resolution, and usability fixes.
Sysmon v14.1

This update to Sysmon, an advanced host monitoring tool, adds a new event type, FileBlockShredding that prevents wiping tools such as Sysinternals SDelete from corrupting and deleting files.

Coreinfo v3.6

This update to Coreinfo, a utility that reports system CPU, memory and cache topology and information, now has an option (-d) for measuring inter-CPU latencies in counter ticks.

AccessEnum v1.35

This update to AccessEnum, a tool that summarizes account permissions on files and folders, fixes a version number mismatch in its version information.

BgInfo v4.32

This update to BgInfo, a tool for displaying system information on screen desktop, correctly reports Windows 11 Insider versions.

NotMyFault v4.21

This update to NotMyFault, a tool used to crash, hang, and cause kernel memory leaks on Windows, now works on ARM64 systems.
Sysmon v14.0

This major update to Sysmon, an advanced host monitoring tool, adds a new event type, FileBlockExecutable that prevents processes from creating executable files in specified locations. It also includes several performance improvements and bug fixes.

AccessEnum v1.34

AccessEnum, a tool for enumerating file system and registry permissions, now supports paths longer than MAX_PATH characters.

Coreinfo v3.53

This update to Coreinfo, a utility that reports system CPU, memory and cache topology and information, now handles NUMA nodes with more than 64 processors.
Oben Unten