{"repo":"progmboy/openprocmon","free":true,"listed":false,"github":"https://github.com/progmboy/openprocmon","clone":"git clone https://github.com/progmboy/openprocmon.git","description":"open source process monitor","language":"Rust","stars":329,"topics":["driver","procmon","windows","sdk"],"license":"MIT","category":"api-integrations-sdks","readme_excerpt":"OpenProcMon English · 中文 An open-source Process Monitor implementation for Windows: a kernel miniFilter driver captures process, file, registry and network activity in real time, a Rust SDK talks to the driver and parses the event stream, and a Rust/GPUI desktop GUI presents it. This is a ground-up Rust rewrite of the SDK and GUI. The kernel driver is unchanged, and the original C++ implementation is kept under cpp-backup/ for reference. The Rust SDK is wire-compatible with the original Process Monitor driver and can read/write Procmon .PML logs. An AI agent can drive capture and analysis through an MCP server or a skill — see MCP / Skill. The desktop GUI is powered by [GPUI] and [GPUI-Component]. Contents - Architecture - Repository layout - Features - Screenshots - Build - Run - SDK example - PML logs - MCP / Skill - Kernel driver - Known issues - Status & roadmap - License - Acknowledgements Architecture The driver and the SDK communicate over a Filter Manager communication port; the kernel/user-mode contract lives in kernel/logsdk.h , which the Rust SDK mirrors with #[repr(C, packed)] structures. Repository layout Features - Real-time monitoring of process, file system, registry, and network activity. - Live filtering and highlighting by process name, PID, operation, path, result, or category. - Process tree , and activity summaries for processes, files, registry, network, and cross-references. - Call stack view with per-frame module resolution. - Full .PML interoperabili","default_branch":null,"files":null,"tree":[],"storefront":"/r/progmboy","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/progmboy/openprocmon/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}