0

I observe sometimes a difference between Process Monitor and Network Monitor. Process Monitor does not show some UDP / TCP network events.

Here is an example:

net use * \\test12345.domain.local\test

shows in Netmon as:

Enter image description here

shows in Process Monitor:

Enter image description here

Why is the NetBIOS nameservice (:137) communication is missing in Process Monitor?

(I've tested it on several virtual and physical Windows PCs, like Windows Server 2008 R2, Windows 7, and Windows Server 2008.)

Peter Mortensen
  • 12,090
  • 23
  • 70
  • 90
marsh-wiggle
  • 2,914
  • 6
  • 28
  • 42
  • I would ask on the sysinternals forum and for more clues, there is a fork of Wireshark that associates packets with process, if netmon doesn't. It might be that the 137 network traffic happens at the kernel level from a Localsystem level access. – Justin Dearing Dec 23 '14 at 22:46

2 Answers2

2

System is deactivated by the default filter (exclude system events). Delete the filter and these events will show up.

Justin Dearing
  • 2,984
  • 6
  • 40
  • 55
1

Shot in the dark: Use psexec to run Process Monitor as localsystem.

Peter Mortensen
  • 12,090
  • 23
  • 70
  • 90
Justin Dearing
  • 2,984
  • 6
  • 40
  • 55