viewer9 documentation | Index Home |
Procmon Bug: QueryStreamInformationFile Alternate Data Stream
Procmon does not show the final Alternate Data Stream in some cases for the QueryStreamInformationFile event. This is not a bug in the PML data, only in the way Procmon displays it. viewer9 is able to display the complete data.
For example, Procmon exhibits this problem on a capture of a dir /r command in the Windows console on files with multiple data streams.
Example
In this case involving MsMpEng.exe, Procmon 3.89 shows just the "::$DATA" stream:
viewer9 shows both the "::$DATA" stream and the missing ":Zone.Identifier:$DATA" stream:
See also
- QueryInformationFile PML Operations
- Procmon Bug: CreateFileMapping PageProtection
- Procmon Bug: Garbage after \Device\HarddiskVolume path
- Procmon Bug: Garbage in Registry Data
- Procmon Bug: QueryDirectory Missing Filename
- Procmon Bug: RegQueryKey QueryKeyType Name
- Procmon Bug: RegRestoreKey/RegSaveKey Path and HivePath
Posted 4 Jul 2022 last updated 22 Nov 2022 As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.
Copyright 2022, bryantlite, Inc.