Until now, anyone wanting to know exactly which processes Windows loads at start-up had to use the external tool Sysmon.
Microsoft has released Sysmon 15, converting it into a protected process and adding the new ‘FileExecutableDetected’ option to log when executable files are created. For those not familiar with Sysmon ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results