Process Monitor is an advanced monitoring tool for Windows that shows real-time file system, Registry, and process/thread activity. It combines the features of two legacy Sysinternals utilities, Filemon and Regmon, and adds an extensive list of enhancements including rich and non-destructive filtering, comprehensive event properties such session IDs and user names, reliable process information, full thread stacks with integrated symbol support for each operation, simultaneous logging to a file, and much more. This tool can be used when standard troubleshooting has yielded no results and more advanced tools are needed.
As ProcMon is an advanced tool, high systems knowledge and familiarity with your environment are needed to take action based on the results of it. It is recommended that you consult with your qualified IT professional when running and reviewing a ProcMon log.