Recent Posts
- The biggest software delusions of the last decade
Thu, 22 Sep 2011
- Software Theft FAIL
Tue, 07 Dec 2010
- A malware with my name
Thu, 09 Sep 2010
- CFF Explorer 7.9 & Secunia
Fri, 13 Aug 2010
- IDAQ: The result of 7 months at Hex-Rays
Mon, 02 Aug 2010
 
Recent Comments
- Comment on The biggest software delusions of the last decade by Roberto
Wed, 18 Jan 2012
- Comment on The biggest software delusions of the last decade by Daniel Pistelli
Mon, 09 Jan 2012
- Comment on The biggest software delusions of the last decade by Assetto
Thu, 05 Jan 2012
- Comment on The biggest software delusions of the last decade by Daniel Pistelli
Sat, 31 Dec 2011
- Comment on The biggest software delusions of the last decade by rizzo
Thu, 15 Dec 2011
 
Filter Monitor
Current Version: 1.1.0

Download Filter Monitor


This utility can list kernel mode filters and also unregister them. Monitored filters are, for instance, registry filters, create process and thread notifications. FilterMon comes both for x64 and x86 and it should work on all Windows systems from Vista RTM to Windows 7 RTM. I can't guarantee that it will work on future versions of Windows as it relies heavily on system internals.


As you probably all know the Service Descriptor Table has been a playground on x86 for all sorts of things: rootkits, anti-viruses, system monitors etc. On x64 modifying the Service Descriptor Table is no longer possible, at least not without subverting the Patch Guard technology.

Thus, programs have now to rely on the filtering/notification technologies provided by Microsoft. And that's why I wrote this little utility which monitors some key filters.

Since I haven't signed the driver of my utility, you have to press F8 at boot time and then select the "Disable Driver Signature Enforcement" option. If you have a multiple boot screen like myself, then you can take your time. Otherwise you have to press F8 frenetically to not miss right moment.


Download Filter Monitor