How to analyze Windows minifilter performance impact

A question was brought to me, of how can one analyze minifilter driver impact on Windows clients? For the answer, I went back to my roots. Because, with agents from security and management tools enterprises use, like AV, SCCM, Tanium, BigFix, etc, generally you don’t know what its doing at a specific time, and then… Continue reading How to analyze Windows minifilter performance impact

How to collect a boot trace on Windows 10 with Windows Performance Recorder from the Microsoft ADK

The Dude

For: Windows 10 (any x64 build) Requirements: Windows Performance Toolkit from the Microsoft ADK   Launch WPRUI as administrator (aka Windows Performance Recorder) by clicking Start and searching for WPRUI. Right-click/click run as administrator Check boxes that are important in your scenario. My recommendation is check First Level Triage Expand Resource Analysis check CPU check… Continue reading How to collect a boot trace on Windows 10 with Windows Performance Recorder from the Microsoft ADK

Windows 10 20H2 boot trace – dropped events

TLDR: At time of writing, Windows 10 20H2 has a bug where the default buffer allocations in boot tracing are inadequate to capture the data of a boot trace. The fix is pretty simple, use good old xbootmgr instead. This is a binary from the older ADK and gets installed when you install the current… Continue reading Windows 10 20H2 boot trace – dropped events

Exit mobile version