If this works remotely as well as the Windows version, I'm stoked. Polling for information (like with lsof) really rubs me the wrong way.
replies(2):
For your stated issue, see lsfd
https://learn.microsoft.com/en-us/windows-hardware/drivers/d...
procmon is cool, but i have found it limited when the program isnt doing anything 'obvious', and also that i have to download it and run it from the web is a problem when debugging on client systems.