A Linux Version of the Procmon Sysinternals Tool
Posted4 months agoActive4 months ago
github.comTechstory
calmmixed
Debate
40/100
LinuxSysinternalsProcmonSystem Monitoring
Key topics
Linux
Sysinternals
Procmon
System Monitoring
Microsoft has released a Linux version of the Procmon Sysinternals tool, sparking discussion about its features, compatibility, and potential use cases, as well as some concerns about its limitations and build requirements.
Snapshot generated from the HN discussion
Discussion Activity
Active discussionFirst comment
2h
Peak period
13
14-16h
Avg / period
5.2
Comment distribution47 data points
Loading chart...
Based on 47 loaded comments
Key moments
- 01Story posted
Aug 31, 2025 at 6:43 PM EDT
4 months ago
Step 01 - 02First comment
Aug 31, 2025 at 8:56 PM EDT
2h after posting
Step 02 - 03Peak activity
13 comments in 14-16h
Hottest window of the conversation
Step 03 - 04Latest activity
Sep 1, 2025 at 2:26 PM EDT
4 months ago
Step 04
Generating AI Summary...
Analyzing up to 500 comments to identify key contributors and discussion patterns
ID: 45087748Type: storyLast synced: 11/20/2025, 3:44:06 PM
Want the full context?
Jump to the original sources
Read the primary article or dive into the live Hacker News thread when you're ready.
procmon is cool, but i have found it limited when the program isnt doing anything 'obvious', and also that i have to download it and run it from the web is a problem when debugging on client systems.
https://learn.microsoft.com/en-us/windows-hardware/drivers/d...
For your stated issue, see lsfd
https://www.man7.org/linux/man-pages/man1/lsfd.1.html
And is the output csv/logfile compatible with the windows equivalent? If so, that'd be amazing! tools like procdot can analyze/visualize the data:
https://procdot.com/
If you can't beat'em join'em!
http://mslinux.org/
(All: feel free to downvote my neckbeard comment because I'm obviously in the wrong here)
[1] https://github.com/microsoft/ProcMon-for-Linux/blob/main/LIC...
I was a windows user till XP came out and I've missed sysinternals tools. I'm going to enjoy this on my newer kernel machines. Seems to require some pretty cutting edge features.
Darn I'm getting old.
https://www.linkedin.com/posts/markrussinovich_i-had-the-thr...
Now, is it great for Linux? Absolutely not. These tools existed to vaguely resemble the capabilities we have had on *nix for decades and I'm not sure what kind of value could they bring back to Linux... like, really, what? A different, Microsoft-style optics to look at processes?
I mean it.
If it's a collection, I can see the individual pieces needing various compilers.
It's quite limited for an auditing tool...