

instance of __InstanceCreationEvent
{
TargetInstance =
instance of Win32_Process
{
Caption = "c**ent.exe";
CommandLine = "c**ent.exe 980 288 00000187DDA61E20";
CreationClassName = "Win32_Process";
CreationDate = "20171203165847.357821+480";
CSCreationClassName = "Win32_ComputerSystem";
CSName = "SC-201707131612";
Description = "c**ent.exe";
ExecutablePath = "C:\\windows\\system32\\c**ent.exe";
Handle = "4904";
HandleCount = 270;
KernelModeTime = "1406250";
MaximumWorkingSetSize = 1380;
MinimumWorkingSetSize = 200;
Name = "c**ent.exe";
OSCreationClassName = "Win32_OperatingSystem";
OSName = "Microsoft Windows 10 企业版|C:\\windows|\\Device\\Harddisk0\\Partition1";
OtherOperationCount = "654";
OtherTransferCount = "9720";
PageFaults = 7592;
PageFileUsage = 2788;
ParentProcessId = 980;
PeakPageFileUsage = 2788;
PeakVirtualSize = "2199130230784";
PeakWorkingSetSize = 20992;
Priority = 8;
PrivatePageCount = "2854912";
ProcessId = 4904;
QuotaNonPagedPoolUsage = 12;
QuotaPagedPoolUsage = 211;
QuotaPeakNonPagedPoolUsage = 12;
QuotaPeakPagedPoolUsage = 211;
ReadOperationCount = "11";
ReadTransferCount = "5767168";
SessionId = 1;
ThreadCount = 7;
UserModeTime = "7500000";
VirtualSize = "2199130230784";
WindowsVersion = "10.0.14393";
WorkingSetSize = "21135360";
WriteOperationCount = "0";
WriteTransferCount = "0";
};
TIME_CREATED = "131567651291545573";
};


NT_进程监控_开始监控
NT_进程监控_停止监控
NT_指针到文本
| 欢迎光临 TC官方合作论坛 (http://bbs.52tc.co/) | Powered by Discuz! X3.1 |