filespy
Where:
Note
The monitor may not truly detach from the device when it receives the /d command because a filter driver can only detach from a device when it can guarantee that it is on the top of the I/O stack. This will only going to occur when the filter driver receives the detach command from the I/O Manager. When the user application tells the kernel driver to detach from a device, the kernel monitor stops logging the data for that device. Also note that shutting down the user application does not cause the kernel monitor to detach from all the drives. The kernel driver will stop logging the I/O operations that it is seeing, but if the user restarts the user application, the kernel monitor will continue logging to the devices that it was attached to when the user application last stopped. The kernel driver will only reset these attachments to system devices when the system is restarted.