![]() |
User Session |
Post Reply
|
| Author | |
jcferret
Newbie
Joined: 30 October 2006 Location: United States Online Status: Offline Posts: 4 |
Post Options
Quote Reply
Topic: User SessionPosted: 30 November 2006 at 10:14am |
|
Good tip... Thanks :)
|
|
![]() |
|
namrehto
Senior Member
Joined: 23 June 2005 Location: Scotland Online Status: Offline Posts: 3861 |
Post Options
Quote Reply
Posted: 30 November 2006 at 10:07am |
|
If you make a capture with ProcMon instead, then you can subsequently play with filters non-destructively and try to drill down to the events you're looking for.
|
|
|
Gil
|
|
![]() |
|
jcferret
Newbie
Joined: 30 October 2006 Location: United States Online Status: Offline Posts: 4 |
Post Options
Quote Reply
Posted: 30 November 2006 at 9:56am |
|
Aw nuts.... would come in handy on countless occasions...
|
|
![]() |
|
EP_X0FF
Senior Member
Joined: 08 March 2006 Location: Russian Federation Online Status: Offline Posts: 4753 |
Post Options
Quote Reply
Posted: 30 November 2006 at 5:58am |
I do not think so. You need some specialized software. |
|
|
Ring0 - the source of inspiration
|
|
![]() |
|
jcferret
Newbie
Joined: 30 October 2006 Location: United States Online Status: Offline Posts: 4 |
Post Options
Quote Reply
Posted: 30 October 2006 at 10:49am |
|
Is there a way to set Regmon to only capture the keys accessed by the user that is running it, instead of all keys accessed on the server? (Under terminal services or Citrix) I'm trying to trace some Internet Explorer activity (Group Policy crap), which means there are tons of reg keys accessed already... without having to sort through 30+ users worth of keys instead of just the 1 user I mean to monitor |
|
![]() |
|
Post Reply
|
| Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |