Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security, Veeam & DevOps

  • Home
  • About
  • Advertise With US
  • Reviews
  • Tech News
  • Contact
  • Toggle search form

Detect registry keys using Process Monitor using Sysinternals Tools

Posted on 07/03/202017/08/2026 IT Expert By IT Expert No Comments on Detect registry keys using Process Monitor using Sysinternals Tools
  1. Home
  2. Windows Server
  3. Detect registry keys using Process Monitor using Sysinternals Tools
Process Monitor

Process Monitor is an advanced monitoring tool for Windows that shows real-time file system, Registry, and process/thread activity. For a tour of Sysinternals tools, please see this link. Kindly refer to these related guides: How to download and use Windows SysInternals tools locally, how to Install Sysinternals from the Microsoft Store, What is System Monitor and how to install and use it, and how to enable Automatic Logon on Windows 10.

It combines the features of two legacy Sysinternals utilities, Filemon and Regmon, and adds an extensive list of enhancements including rich and non-destructive filtering, comprehensive event properties such as session IDs and user names, reliable process information, full thread stacks with integrated symbol support for each operation, simultaneous logging to a file, and much more.

Its unique and powerful features makes Process Monitor a core utility in your system troubleshooting and malware hunting toolkit. This tool can be downloaded from here the folloing link.

Download Sysinternals Tools

Extract the downloaded tool and run the Procmon64.exe as shown below.

Windows registry

Next, after running the executable, agree to the Process Monitor License Agreement.

Registry keys

This will launch the Process Monitor SysInternal Tool as shown below.

System monitoring
Note: This tool is memory intensive

Below are some possibilities that are available with this tool. Here you can choose to include or exclude the program, highlight etc.

Process Monitor

Also, with the “Jump to Object (contl+J)”, you can jump directly to the registry keys associated as shown below

Windows registry

This tool is capable or has the following features

  • Capturing (Screenshots)
  • Auto scrolling
  • Filter
  • Highlight
  •  Show Process tree
  • Include Process from Windows
  • Find
  • Jump to Object
  • Show Registry Activity
  • Show File System Activity
  • Show Network Activity
  • Show Process and Trend Activity
  • Show profiling event.

Emphasizing on the show registry activities, we will have to click on a process name and select it.

Lastly, when you click on the Show Process and Trend Activity, this will apply an even filter as shown below and give the desired output on the Process Monitor window.

Screenshot of Process Monitor from Sysinternals showing current processes and a progress bar for applying an event filter.

Find: With the find function, you can easily find the process (events) in the process monitor.

Screenshot of the Process Monitor application from Sysinternals, displaying a search dialog box with options to find processes by name, including checkboxes for matching whole words and case sensitivity.

Without this, having to search in the numerous process will be cumbersome as you can see below.

Process Monitor window displaying a search operation in progress with a progress bar showing 0% completion and estimated time remaining.

Filter: With filter, you can also perform filter in order to include on your desired process on the Process Monitor UI.

Screenshot of the Process Monitor application from Sysinternals, highlighting the 'Filter' menu with various filtering options available.

Click on the filter, and enter your desired parameters. Next, click on Add, select the program to include, and click on Ok.

Screenshot of the Process Monitor filter menu displaying options to filter entries by architecture in Sysinternals.

Since our filter included just one process, other processes were excluded as shown below.

Text displaying a message about a current filter excluding 790,474 events, with a note indicating it is backed by virtual memory.

Note: When this filter is set, you will have to manually reset it before you can perform other activities correctly again.

Process Monitor Filter window showing options to filter entries by architecture, with a highlighted 'Reset' button.

I hope you found this blog post helpful. If you have any questions, please let me know in the comment session.

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Server Tags:Registry Keys, RegistryEditor, SysInternal, Windows 10, Windows 11, windows sysinternals tools

Post navigation

Previous Post: How to configure the FrontFace Lockdown Tool
Next Post: How to use the Process Explorer from SysInternals Tools

Related Posts

  • shrink and create partition
    How to shrink and create new partition on Windows Server Windows Server
  • screenshot 2020 03 13 at 20.24.17
    How to install Cygwin packages from the command line Windows Server
  • How to Manage Azure Virtual Machines with Windows Admin Center and Serial Console​
    Manage Azure Virtual Machine with Windows Admin Center and Serial Console AWS/Azure/OpenShift
  • Hyper V Virtual Switch
    How to Create Hyper-V Virtual Switch Network | Monitoring
  • images
    How to fix you are not allowed to view this folder on SSRS: MBAM reports cannot be accessed because it could not load folder contents Windows Server
  • Expired Evaluation Configuration Manager to Full Version
    Upgrade Expired Evaluation Configuration Manager to Full Version Windows Server

More Related Articles

shrink and create partition How to shrink and create new partition on Windows Server Windows Server
screenshot 2020 03 13 at 20.24.17 How to install Cygwin packages from the command line Windows Server
How to Manage Azure Virtual Machines with Windows Admin Center and Serial Console​ Manage Azure Virtual Machine with Windows Admin Center and Serial Console AWS/Azure/OpenShift
Hyper V Virtual Switch How to Create Hyper-V Virtual Switch Network | Monitoring
images How to fix you are not allowed to view this folder on SSRS: MBAM reports cannot be accessed because it could not load folder contents Windows Server
Expired Evaluation Configuration Manager to Full Version Upgrade Expired Evaluation Configuration Manager to Full Version Windows Server

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • screenshot 2020 03 20 at 00.44.47
    How to check if homebrew is installed on macOS Mac
  • Storage Explorer
    How to Install Azure Storage Explorer on Windows AWS/Azure/OpenShift
  • Windows Admin Center Apply Update
    How to Apply and Enable Automatic Windows Admin Center Update Windows
  • Virtual Desktop
    Add and Remove Multiple Virtual Desktops in Windows Windows
  • maxresdefault 12
    How to check Windows activation status and change your product key Windows
  • Azure CI CD Pipeline
    CI/CD Pipeline: Your First in Azure DevOps with ASP.Net Core AWS/Azure/OpenShift
  • dfggg 1
    Configuring SimpleSAMLPHP Windows Server
  • maxresdefault 2 1
    How to disconnect a Remote Desktop User Windows Server

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,765 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2026 TechDirectArchive

Loading Comments...

You must be logged in to post a comment.