Windows Logs
Last updated
Last updated
If you have a CSV log file produced by procmon (and optionally a pcap file) you can visualize processes behaviors with . (password: procdot)
Make sure that you have the required dependencies for procDOT and make sure to provide their path when you start procDOT.:
windump (Windows)
tcpdump (Linux)
Graphviz
Install procDOT
Note: Avoid installing on Kali
Select a CSV file for ProcDOT, then under Render Configuration (top right of the window) select a Launcher (process) then click Refresh to visualize the process behavior.
You can enable frame-mode to see its behavior step-by-step by clicking on the film icon (bottom left of the window).
For more details on how to use procDOT, check out these on their official website.