Carbon Black App ControlCarbon Black App Control (formerly Cb Protection)Carbon Black Cloud Audit and RemediationCarbon Black Cloud Audit and Remediation (formerly Cb Live Ops)Carbon Black Cloud ContainerCarbon Black Cloud Endpoint StandardCarbon Black Cloud Endpoint Standard (formerly Cb Defense)Carbon Black Cloud Enterprise EDRCarbon Black Cloud Enterprise EDR (formerly Cb Threathunter)Carbon Black Cloud Managed Detection (formerly Cb Threatsight)Carbon Black Cloud Managed Detection and ResponseCarbon Black Cloud Managed Threat HuntingCarbon Black Cloud PreventionCarbon Black Cloud WorkloadCarbon Black EDRCarbon Black EDR (formerly Cb Response)Carbon Black Hosted EDR (formerly Cb Response Cloud)VMware Carbon Black
Launch Procmon and configure the capture as follows:
Press CTRL+E to stop the current capture.
Press CTRL+X to clear the current results.
Filter > Filter > Click Reset and uncheck Process Name > is System > OK
Options > Profiling Events > Generate thread profiling events > Every 100 milliseconds > OK
Options > Enable Boot Logging
Click OK and reboot the endpoint.
After the reboot, open Process Monitor once more.
When prompted, click Yes to save the boot-time activity as a PML (Ex: Laptop1-bootlog.pml)
Close Process Monitor, and open the PML created to verify it loads without errors.
Compress the PML and upload to Support.
Configure Procmon for Low Altitude:
A preconfigured Low Altitude Procmon (Version 23) is attached to the article. This version can be used to prevent having to reboot. To use the latest version of Procmon, follow these steps: