Chapter 21. Understanding system behavior

Unlike those in the last several chapters, the cases in this chapter aren’t about troubleshooting failures, but about explaining normal (or at least harmless) observed behavior. Two of the cases demonstrate using Microsoft Windows PowerShell to analyze and extract data from Procmon traces saved as XML.

Image In The Case of the Q: Drive,” three lesser-known tools—DiskExt, WinObj, and SigCheck—are brought to bear to explain a mysterious drive letter.

Image The Case of the Unexplained Network Connections is explained ...

Get Troubleshooting with the Windows Sysinternals Tools now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.