Chapter 21. Understanding system behavior
Unlike those in the last several chapters, the cases in this chapter aren’t about troubleshooting failures, but about explaining normal (or at least harmless) observed behavior. Two of the cases demonstrate using Microsoft Windows PowerShell to analyze and extract data from Procmon traces saved as XML.
In “The Case of the Q: Drive,” three lesser-known tools—DiskExt, WinObj, and SigCheck—are brought to bear to explain a mysterious drive letter.
“The Case of the Unexplained Network Connections” is explained ...
Get Troubleshooting with the Windows Sysinternals Tools now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.