Tracing which process that has opened a particular file

后端 未结 4 582
忘了有多久
忘了有多久 2020-12-17 06:36

From kernel mode in Windows I\'m able to intercept and monitor virtually all actions performed on a particular disk. When a file is opened for any purpose I get an event.

4条回答
  •  我在风中等你
    2020-12-17 06:56

    Sysinternals did a so good job at doing it and explaining it, that some source code of old version are still available here for instance, and the code is well documented (imho). It could be a good start as well.

提交回复
热议问题