viewer9 documentation


Device and PostOp are 32-bit integers. These fields are not displayed in Procmon.

Example from 64-bit PML

Hover over field values like Time, ResultCode, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

IRP_MJ_CLOSE opcode=3,22

ev=34556 advop=IRP_MJ_CLOSE

Time:2022-05-17 16:06:22.4529749

evdata[0-105] file offset 20022949

000 01 00 00 17 00 c7 77 .......w
804 04 00 00 01 00 00 00 ........
1600 00 00 00 00 00 00 00 ........
omit 4 rows of zeros
5600 00 00 00 00 00 00 00 ........
6424 80 d0 02 43 3a 5c 50 $...C:\P
7272 6f 67 72 61 6d 44 61 rogramDa
8074 61 5c 4d 69 63 72 6f ta\Micro
8873 6f 66 74 5c 53 65 61 soft\Sea
9672 63 68 5c 44 61 74 61 rch\Data
10400 00 ..

Call Stack stacksize=16

0xfffff880011730f7194fltmgr.sys + 0x20f7C:\Windows\system32\drivers\fltmgr.sys
0xfffff88001173fc7194fltmgr.sys + 0x2fc7C:\Windows\system32\drivers\fltmgr.sys
0xfffff880011726c7194fltmgr.sys + 0x16c7C:\Windows\system32\drivers\fltmgr.sys
0xfffff80002b4b19e161ntoskrnl.exe + 0x2fd19eC:\Windows\system32\ntoskrnl.exe
0xfffff800028823d4161ntoskrnl.exe + 0x343d4C:\Windows\system32\ntoskrnl.exe
0xfffff80002c7a860161ntoskrnl.exe + 0x42c860C:\Windows\system32\ntoskrnl.exe
0xfffff80002b466d4161ntoskrnl.exe + 0x2f86d4C:\Windows\system32\ntoskrnl.exe
0xfffff800028eff53161ntoskrnl.exe + 0xa1f53C:\Windows\system32\ntoskrnl.exe
0x77c8989a2ntdll.dll + 0x6989aC:\Windows\SYSTEM32\ntdll.dll
0x7fefd7f680c43KERNELBASE.dll + 0x2680cC:\Windows\system32\KERNELBASE.dll
0x7fef467c4f5525MSSRCH.DLL + 0x4c4f5C:\Windows\system32\MSSRCH.DLL
0x7fef467c3ac525MSSRCH.DLL + 0x4c3acC:\Windows\system32\MSSRCH.DLL
0x7fef4632039525MSSRCH.DLL + 0x2039C:\Windows\system32\MSSRCH.DLL
0x7fef4631821525MSSRCH.DLL + 0x1821C:\Windows\system32\MSSRCH.DLL
0x77a1556d0kernel32.dll + 0x1556dC:\Windows\system32\kernel32.dll
0x77c7372d2ntdll.dll + 0x5372dC:\Windows\SYSTEM32\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.