viewer9 documentation

Procmon Bug: QueryStreamInformationFile Alternate Data Stream

Procmon does not show the final Alternate Data Stream in some cases for the QueryStreamInformationFile event. This is not a bug in the PML data, only in the way Procmon displays it. viewer9 is able to display the complete data.

For example, Procmon exhibits this problem on a capture of a dir /r command in the Windows console on files with multiple data streams.

Example

In this case involving MsMpEng.exe, Procmon 3.89 shows just the "::$DATA" stream:

viewer9 shows both the "::$DATA" stream and the missing ":Zone.Identifier:$DATA" stream:

See also

Posted 4 Jul 2022 last updated 22 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.