Skip to content

Instantly share code, notes, and snippets.

@darbym
Created May 11, 2018 15:52
Show Gist options
  • Save darbym/c6a71073d71732e889cd3e0826f95401 to your computer and use it in GitHub Desktop.
Save darbym/c6a71073d71732e889cd3e0826f95401 to your computer and use it in GitHub Desktop.
# Source: https://twitter.com/subTee/status/972367673186074624
1. Get ProcMon # https://docs.microsoft.com/en-us/sysinternals/downloads/procmon
2. Set Filter For Path Contains "NAME NOT FOUND"
3. Set Filter For Path Contains "TreatAs" [Optional]
4. Set Filter For Username contains SYSTEM 😀
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment