{"_id":"@bun-win32/sysmon","_rev":"5-bbfcd71d58172cc6d2db0d81e8a9d5a6","name":"@bun-win32/sysmon","dist-tags":{"latest":"2.0.1"},"versions":{"1.0.0":{"name":"@bun-win32/sysmon","version":"1.0.0","keywords":["bun","cpu","etw","eventlog","ffi","memory","metrics","monitoring","pdh","process","sysmon","systeminformation","windows","wmic"],"author":"Stev Peifer <stev@bell.net>","license":"MIT","_id":"@bun-win32/sysmon@1.0.0","maintainers":[{"name":"obscuritysrl","email":"stev@bell.net"}],"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dist":{"shasum":"b9e64f7e46e981413b99d4006dc77e90804b5cbe","tarball":"https://registry.npmjs.org/@bun-win32/sysmon/-/sysmon-1.0.0.tgz","fileCount":19,"integrity":"sha512-n2DhWtBYW0bJq90weh2BrwcVDridkM7kRAQdE8QNDOlQ0PyRkhPzKfITrnn80nc1XBYRy7Tv4SuZW/VQRFYNcA==","signatures":[{"sig":"MEUCIQDeztwMtc3f+pSMtvF4QBDEgeJe8ggNsUr1tkIspfeKCQIgY58Um+Qzk7gm44hdjjll/iykFtYvOcY3JbULTsBXLsY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":151768},"main":"./index.ts","type":"module","module":"index.ts","shasum":"b9e64f7e46e981413b99d4006dc77e90804b5cbe","engines":{"bun":">=1.1.0"},"exports":{".":"./index.ts"},"private":false,"scripts":{"example:taskman":"bun ./example/taskman.ts","example:selftest":"bun ./example/sysmon.selftest.ts","example:benchmark":"bun ./example/benchmark.ts","example:crosscheck":"bun ./example/crosscheck.ts","example:event-tail":"bun ./example/event-tail.ts","example:etw-firehose":"bun ./example/etw-firehose.ts","example:hello-sysmon":"bun ./example/hello-sysmon.ts","example:sysmon-report":"bun ./example/sysmon-report.ts"},"_npmUser":{"name":"obscuritysrl","email":"stev@bell.net"},"_integrity":"sha512-n2DhWtBYW0bJq90weh2BrwcVDridkM7kRAQdE8QNDOlQ0PyRkhPzKfITrnn80nc1XBYRy7Tv4SuZW/VQRFYNcA==","repository":{"url":"git://github.com/ObscuritySRL/bun-win32.git","type":"git","directory":"packages/sysmon"},"_npmVersion":"10.8.3","description":"Native-speed Windows system metrics, PDH counters, Event Log tail, and a decoded real-time ETW firehose for Bun — CPU/memory/disk/process/socket data via direct FFI, no PowerShell, no wmic, no node-gyp.","directories":{},"sideEffects":false,"_nodeVersion":"24.3.0","dependencies":{"@bun-win32/pdh":"1.0.4","@bun-win32/tdh":"1.0.0","@bun-win32/core":"1.1.3","@bun-win32/ntdll":"1.0.7","@bun-win32/psapi":"2.0.8","@bun-win32/user32":"3.0.21","@bun-win32/wevtapi":"1.0.0","@bun-win32/advapi32":"1.0.12","@bun-win32/iphlpapi":"1.0.4","@bun-win32/kernel32":"1.0.25","@bun-win32/powrprof":"1.0.1","@bun-win32/rstrtmgr":"1.0.0","@bun-win32/wtsapi32":"1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest"},"peerDependencies":{"typescript":"^5"},"_npmOperationalInternal":{"tmp":"tmp/sysmon_1.0.0_1781092669891_0.4225532504505267","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@bun-win32/sysmon","version":"1.0.1","keywords":["bun","cpu","etw","eventlog","ffi","memory","metrics","monitoring","pdh","process","sysmon","systeminformation","windows","wmic"],"author":"Stev Peifer <stev@bell.net>","license":"MIT","_id":"@bun-win32/sysmon@1.0.1","maintainers":[{"name":"obscuritysrl","email":"stev@bell.net"}],"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dist":{"shasum":"c397c872ca2b1978d94abdb21d4f92d38cd98d86","tarball":"https://registry.npmjs.org/@bun-win32/sysmon/-/sysmon-1.0.1.tgz","fileCount":20,"integrity":"sha512-b5facKrFH940LobEsbt/hEN8mS3HmMPCevjpZLWdquEvx8qZ/XXB889ZPdIjuKWbq14GzW/8PDgDf92TBt71RQ==","signatures":[{"sig":"MEUCIBA5Sp0pQkhWjqQT0EKLINsC50zrUInX4Kl3js+JC/r4AiEAhKDDdW+8b6/1hfruH+JzJYgDezXEBMPqmdC0EjbHmwE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":153235},"main":"./index.ts","type":"module","module":"index.ts","shasum":"c397c872ca2b1978d94abdb21d4f92d38cd98d86","engines":{"bun":">=1.1.0"},"exports":{".":"./index.ts"},"private":false,"scripts":{"example:taskman":"bun ./example/taskman.ts","example:selftest":"bun ./example/sysmon.selftest.ts","example:benchmark":"bun ./example/benchmark.ts","example:crosscheck":"bun ./example/crosscheck.ts","example:event-tail":"bun ./example/event-tail.ts","example:etw-firehose":"bun ./example/etw-firehose.ts","example:hello-sysmon":"bun ./example/hello-sysmon.ts","example:sysmon-report":"bun ./example/sysmon-report.ts"},"_npmUser":{"name":"obscuritysrl","email":"stev@bell.net"},"_integrity":"sha512-b5facKrFH940LobEsbt/hEN8mS3HmMPCevjpZLWdquEvx8qZ/XXB889ZPdIjuKWbq14GzW/8PDgDf92TBt71RQ==","repository":{"url":"git://github.com/ObscuritySRL/bun-win32.git","type":"git","directory":"packages/sysmon"},"_npmVersion":"10.8.3","description":"Native-speed Windows system metrics, PDH counters, Event Log tail, and a decoded real-time ETW firehose for Bun — CPU/memory/disk/process/socket data via direct FFI, no PowerShell, no wmic, no node-gyp.","directories":{},"sideEffects":false,"_nodeVersion":"24.3.0","dependencies":{"@bun-win32/pdh":"1.0.4","@bun-win32/tdh":"1.0.0","@bun-win32/core":"1.1.3","@bun-win32/ntdll":"1.0.7","@bun-win32/psapi":"2.0.8","@bun-win32/user32":"3.0.21","@bun-win32/wevtapi":"1.0.0","@bun-win32/advapi32":"1.0.12","@bun-win32/iphlpapi":"1.0.4","@bun-win32/kernel32":"1.0.25","@bun-win32/powrprof":"1.0.1","@bun-win32/rstrtmgr":"1.0.0","@bun-win32/wtsapi32":"1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest"},"peerDependencies":{"typescript":"^5"},"_npmOperationalInternal":{"tmp":"tmp/sysmon_1.0.1_1781092904781_0.11896015353633227","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@bun-win32/sysmon","version":"1.0.2","keywords":["bun","cpu","etw","eventlog","ffi","memory","metrics","monitoring","pdh","process","sysmon","systeminformation","windows","wmic"],"author":"Stev Peifer <stev@bell.net>","license":"MIT","_id":"@bun-win32/sysmon@1.0.2","maintainers":[{"name":"obscuritysrl","email":"stev@bell.net"}],"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dist":{"shasum":"01ef544b188ad55c5e67264798d3b5e00f9b2e44","tarball":"https://registry.npmjs.org/@bun-win32/sysmon/-/sysmon-1.0.2.tgz","fileCount":20,"integrity":"sha512-rCaf6cEI/asVugadbQ1V4mVea33XNdJmYDY+tHYIXwYS7+G6Y0nfar6P+emc5l8PDJq8cSA2hXnlBcPlx0/3tQ==","signatures":[{"sig":"MEUCIQCpXTvrLdau/kBrmegn3G/1sjEDEa3Ek1mAL528hWmGBgIgYldeMAPJPrTZoVbhqJl96GT+3fn5FE/OnHqQFdh4Rso=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":153520},"main":"./index.ts","type":"module","module":"index.ts","shasum":"01ef544b188ad55c5e67264798d3b5e00f9b2e44","engines":{"bun":">=1.1.0"},"exports":{".":"./index.ts"},"private":false,"scripts":{"example:taskman":"bun ./example/taskman.ts","example:selftest":"bun ./example/sysmon.selftest.ts","example:benchmark":"bun ./example/benchmark.ts","example:crosscheck":"bun ./example/crosscheck.ts","example:event-tail":"bun ./example/event-tail.ts","example:etw-firehose":"bun ./example/etw-firehose.ts","example:hello-sysmon":"bun ./example/hello-sysmon.ts","example:sysmon-report":"bun ./example/sysmon-report.ts"},"_npmUser":{"name":"obscuritysrl","email":"stev@bell.net"},"_integrity":"sha512-rCaf6cEI/asVugadbQ1V4mVea33XNdJmYDY+tHYIXwYS7+G6Y0nfar6P+emc5l8PDJq8cSA2hXnlBcPlx0/3tQ==","repository":{"url":"git://github.com/ObscuritySRL/bun-win32.git","type":"git","directory":"packages/sysmon"},"_npmVersion":"10.8.3","description":"Native-speed Windows system metrics, PDH counters, Event Log tail, and a decoded real-time ETW firehose for Bun — CPU/memory/disk/process/socket data via direct FFI, no PowerShell, no wmic, no node-gyp.","directories":{},"sideEffects":false,"_nodeVersion":"24.3.0","dependencies":{"@bun-win32/pdh":"1.0.4","@bun-win32/tdh":"1.0.0","@bun-win32/core":"1.1.3","@bun-win32/ntdll":"1.0.7","@bun-win32/psapi":"2.0.8","@bun-win32/user32":"3.0.21","@bun-win32/wevtapi":"1.0.0","@bun-win32/advapi32":"1.0.12","@bun-win32/iphlpapi":"1.0.4","@bun-win32/kernel32":"1.0.25","@bun-win32/powrprof":"1.0.1","@bun-win32/rstrtmgr":"1.0.0","@bun-win32/wtsapi32":"1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest"},"peerDependencies":{"typescript":"^5"},"_npmOperationalInternal":{"tmp":"tmp/sysmon_1.0.2_1781098641711_0.6618611620904105","host":"s3://npm-registry-packages-npm-production"}},"2.0.0":{"name":"@bun-win32/sysmon","version":"2.0.0","keywords":["bun","cpu","etw","eventlog","ffi","memory","metrics","monitoring","pdh","process","sysmon","systeminformation","windows","wmic"],"author":"Stev Peifer <stev.p@outlook.com>","license":"MIT","_id":"@bun-win32/sysmon@2.0.0","maintainers":[{"name":"obscuritysrl","email":"stev.p@outlook.com"}],"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dist":{"shasum":"f5f9f258c8551eae576752ecd5d30140ab1315c9","tarball":"https://registry.npmjs.org/@bun-win32/sysmon/-/sysmon-2.0.0.tgz","fileCount":20,"integrity":"sha512-3wjJgTn8kQrmo9G0rTi9rFt/RqPFB/NO4UgoFYhnsKWjW1jb3Tu9AVloJFPXpXoqfTRFxq1oZToQRKQSFZZVdg==","signatures":[{"sig":"MEQCIF0EuNl9gLOostHdIfw9ah3UIMfzNew5/SlgwB6oDCSmAiA9Dn5fCD58Nv7i508f3GMvTZH7mRNWroLyhxaDNH12OA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":153522},"main":"./index.ts","type":"module","module":"index.ts","shasum":"f5f9f258c8551eae576752ecd5d30140ab1315c9","engines":{"bun":">=1.1.0"},"exports":{".":"./index.ts"},"private":false,"scripts":{"example:taskman":"bun ./example/taskman.ts","example:selftest":"bun ./example/sysmon.selftest.ts","example:benchmark":"bun ./example/benchmark.ts","example:crosscheck":"bun ./example/crosscheck.ts","example:event-tail":"bun ./example/event-tail.ts","example:etw-firehose":"bun ./example/etw-firehose.ts","example:hello-sysmon":"bun ./example/hello-sysmon.ts","example:sysmon-report":"bun ./example/sysmon-report.ts"},"_npmUser":{"name":"obscuritysrl","email":"stev.p@outlook.com"},"_integrity":"sha512-3wjJgTn8kQrmo9G0rTi9rFt/RqPFB/NO4UgoFYhnsKWjW1jb3Tu9AVloJFPXpXoqfTRFxq1oZToQRKQSFZZVdg==","repository":{"url":"git://github.com/ObscuritySRL/bun-win32.git","type":"git","directory":"packages/sysmon"},"_npmVersion":"10.8.3","description":"Native-speed Windows system metrics, PDH counters, Event Log tail, and a decoded real-time ETW firehose for Bun — CPU/memory/disk/process/socket data via direct FFI, no PowerShell, no wmic, no node-gyp.","directories":{},"sideEffects":false,"_nodeVersion":"26.3.0","dependencies":{"@bun-win32/pdh":"2.0.0","@bun-win32/tdh":"2.0.0","@bun-win32/core":"2.0.0","@bun-win32/ntdll":"2.0.0","@bun-win32/psapi":"3.0.0","@bun-win32/user32":"4.0.0","@bun-win32/wevtapi":"2.0.0","@bun-win32/advapi32":"2.0.0","@bun-win32/iphlpapi":"2.0.0","@bun-win32/kernel32":"2.0.0","@bun-win32/powrprof":"2.0.0","@bun-win32/rstrtmgr":"2.0.0","@bun-win32/wtsapi32":"2.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest"},"peerDependencies":{"typescript":"^5"},"_npmOperationalInternal":{"tmp":"tmp/sysmon_2.0.0_1782436017256_0.439641611715452","host":"s3://npm-registry-packages-npm-production"}},"2.0.1":{"author":"Stev Peifer <stev.p@outlook.com>","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dependencies":{"@bun-win32/advapi32":"2.0.1","@bun-win32/core":"2.0.1","@bun-win32/iphlpapi":"2.0.1","@bun-win32/kernel32":"2.0.1","@bun-win32/ntdll":"2.0.1","@bun-win32/pdh":"2.0.1","@bun-win32/powrprof":"2.0.1","@bun-win32/psapi":"3.0.1","@bun-win32/rstrtmgr":"2.0.1","@bun-win32/tdh":"2.0.1","@bun-win32/user32":"4.0.1","@bun-win32/wevtapi":"2.0.1","@bun-win32/wtsapi32":"2.0.1"},"description":"Native-speed Windows system metrics, PDH counters, Event Log tail, and a decoded real-time ETW firehose for Bun — CPU/memory/disk/process/socket data via direct FFI, no PowerShell, no wmic, no node-gyp.","devDependencies":{"@types/bun":"latest"},"exports":{".":"./index.ts"},"license":"MIT","module":"index.ts","name":"@bun-win32/sysmon","peerDependencies":{"typescript":"^5"},"private":false,"publishConfig":{"access":"public"},"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","repository":{"type":"git","url":"git://github.com/ObscuritySRL/bun-win32.git","directory":"packages/sysmon"},"type":"module","version":"2.0.1","main":"./index.ts","keywords":["bun","cpu","etw","eventlog","ffi","memory","metrics","monitoring","pdh","process","sysmon","systeminformation","windows","wmic"],"sideEffects":false,"engines":{"bun":">=1.1.0"},"scripts":{"example:benchmark":"bun ./example/benchmark.ts","example:crosscheck":"bun ./example/crosscheck.ts","example:etw-firehose":"bun ./example/etw-firehose.ts","example:event-tail":"bun ./example/event-tail.ts","example:hello-sysmon":"bun ./example/hello-sysmon.ts","example:selftest":"bun ./example/sysmon.selftest.ts","example:sysmon-report":"bun ./example/sysmon-report.ts","example:taskman":"bun ./example/taskman.ts"},"_id":"@bun-win32/sysmon@2.0.1","_integrity":"sha512-Qnv+yLQYZnkeUiZZcmBgbwKzNKrIKj+p1s1LObA6xroC2ENAQo3uQyKXI/6sOGDURD9wGlcmyQeNnTjRHwEbYA==","_nodeVersion":"26.3.0","_npmVersion":"10.8.3","shasum":"fbb4983648f9cfed91edaeae85bf4a280d9741b8","dist":{"integrity":"sha512-Qnv+yLQYZnkeUiZZcmBgbwKzNKrIKj+p1s1LObA6xroC2ENAQo3uQyKXI/6sOGDURD9wGlcmyQeNnTjRHwEbYA==","shasum":"fbb4983648f9cfed91edaeae85bf4a280d9741b8","tarball":"https://registry.npmjs.org/@bun-win32/sysmon/-/sysmon-2.0.1.tgz","fileCount":20,"unpackedSize":153522,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCYNgewr6cnWnCn24LlR9uW9E6IdYNE11Sm4AVNPyjLiQIhAMoqruxkuKQYnpRWXA/deWv0Z7qELBB0vLe4rkmAfDAN"}]},"_npmUser":{"name":"obscuritysrl","email":"stev.p@outlook.com"},"directories":{},"maintainers":[{"name":"obscuritysrl","email":"stev.p@outlook.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sysmon_2.0.1_1782438242428_0.10224946947516078"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-10T11:57:49.704Z","modified":"2026-06-26T01:44:02.720Z","1.0.0":"2026-06-10T11:57:50.041Z","1.0.1":"2026-06-10T12:01:44.897Z","1.0.2":"2026-06-10T13:37:21.873Z","2.0.0":"2026-06-26T01:06:57.412Z","2.0.1":"2026-06-26T01:44:02.605Z"},"bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"author":"Stev Peifer <stev.p@outlook.com>","license":"MIT","homepage":"https://github.com/ObscuritySRL/bun-win32#readme","keywords":["bun","cpu","etw","eventlog","ffi","memory","metrics","monitoring","pdh","process","sysmon","systeminformation","windows","wmic"],"repository":{"type":"git","url":"git://github.com/ObscuritySRL/bun-win32.git","directory":"packages/sysmon"},"description":"Native-speed Windows system metrics, PDH counters, Event Log tail, and a decoded real-time ETW firehose for Bun — CPU/memory/disk/process/socket data via direct FFI, no PowerShell, no wmic, no node-gyp.","maintainers":[{"name":"obscuritysrl","email":"stev.p@outlook.com"}],"readme":"# @bun-win32/sysmon\n\nNative-speed Windows system monitoring for [Bun](https://bun.sh) — CPU, memory, disk, process, socket, GPU-per-process metrics, native perfmon counters, a typed Event Log tail, and a decoded real-time ETW firehose. Direct FFI into DLLs already in System32: **no PowerShell, no wmic, no WMI, no node-gyp, no vendored .exe**.\n\n```ts\nimport { memory, osInfo, processes, tcpSockets } from '@bun-win32/sysmon';\n\nconst os = osInfo();\nconst ram = memory();\nconst top = processes()\n  .sort((a, b) => Number(b.kernelTime + b.userTime - a.kernelTime - a.userTime))\n  .slice(0, 5);\nconsole.log(`Windows ${os.major}.${os.minor}.${os.build} · ${ram.memoryLoadPercent}% RAM used · ${tcpSockets().length} TCP sockets`);\nconsole.log(`Top processes by CPU time: ${top.map((p) => p.name).join(', ')}`);\n```\n\n```\nWindows 10.0.26200 · 55% RAM used · 219 TCP sockets\nTop processes by CPU time: Idle, opera.exe, opera.exe, System, WaveLink.exe\n```\n\n`bun add @bun-win32/sysmon` is the entire install story (the unscoped [`bun-sysmon`](https://www.npmjs.com/package/bun-sysmon) is the same package) — kilobytes of TypeScript over DLLs every Windows installation already has.\n\n![taskman](https://raw.githubusercontent.com/ObscuritySRL/bun-win32/main/packages/all/screenshots/taskman.png)\n\n*`example/taskman.ts` — per-core bars + ranked process table, sampling at ~680 Hz with 0.1% own CPU.*\n\n## Why this exists\n\nMicrosoft removed `wmic` from Windows 11 24H2/25H2 and Server 2025, hard-breaking the ~20M-download/week monitoring cluster whose universal \"fix\" was spawning `powershell.exe` per sample — 100 ms-class latency, AV-scanned, blocked by enterprise script policy, and the architecture behind a serial command-injection CVE history.\n\n| package | dl/week | install model | the catch |\n| --- | ---: | --- | --- |\n| systeminformation | 7.0M | spawns PowerShell per call | 16 injection advisories (incl. CISA-KEV [CVE-2021-21315](https://github.com/advisories/GHSA-2m39-62fm-q8r3), [CVE-2024-56334](https://github.com/advisories/GHSA-cww6-9c9c-r4mq), [CVE-2025-68154](https://github.com/advisories/GHSA-wphj-fx3q-84ch), three more in 2026); `disksIO()`/`fsStats()` return null on Windows; cached/standby memory hard-zeroed; a 1 Hz poll pegs a core ([#626](https://github.com/sebhildebrandt/systeminformation/issues/626)) |\n| pidusage | 4.5M | spawns wmic → gwmi | the fallback is broken by construction (its own TODO admits it; [#190](https://github.com/soyuka/pidusage/issues/190)/[#191](https://github.com/soyuka/pidusage/issues/191) open, no response); Windows CPU% documented \"Not Accurate\" |\n| ps-tree | 3.3M | spawns wmic | abandoned 2018; hard-broken on Server 2025 ([#69](https://github.com/indexzero/ps-tree/issues/69) closed \"not planned\") |\n| check-disk-space | 3.4M | spawns PowerShell per check | stale 3 years; rejects UNC paths by design |\n| ps-list | 1.6M | vendored fastlist.exe | AV-flagged ([#42](https://github.com/sindresorhus/ps-list/issues/42)); dies under single-file bundling; pid/ppid/name only; no ARM64 |\n| pidtree | 19.6M | spawns wmic → powershell.exe | per-sample spawn either way |\n| @vscode/windows-process-tree | 68k | `node-gyp rebuild` on every install | toolchain required; minimal fields; no Bun |\n\nbun-sysmon is the same data in microseconds, typed end to end, with zero spawn surface — the injection CVE class is structurally impossible.\n\n## Benchmarks (measured, reproduce with `bun run example/benchmark.ts`)\n\nIntel i9-12900KS (24 logical cores) · Windows 11 build 26200 · Bun 1.4.0:\n\n| call | median latency |\n|------|---------------:|\n| `memory()` | 0.8 µs |\n| `cpuTimes()` | 9.7 µs |\n| `tcpSockets()` | 108.1 µs |\n| `processes()` — the ENTIRE process list, full rows | 3.90 ms |\n| `pidStats(pid)` | 3.80 ms |\n| sustained `CpuSampler` rate | 690 Hz @ 0.8% own CPU |\n| **one** `powershell Get-CimInstance Win32_Process` spawn | **346 ms** |\n\n`processes()` is **89× faster** than the single spawn the wmic-era cluster pays *per sample* — and it returns ppid, threads, handles, working set, private bytes, IO counters, and create time for every process, from one syscall.\n\n## What you can do\n\nThe whole process list in one syscall — what pidusage spawns a process per pid to approximate:\n\n```ts\nimport { pidStats, processTree, processes } from '@bun-win32/sysmon';\nconst rows = processes(); // 400+ full rows in ~4 ms\nconst stats = pidStats(process.pid); // the pidusage shape: {cpu, memory, ppid, pid, ctime, elapsed, timestamp}\nconst tree = processTree(); // ps-tree on wmic-less Windows\nconsole.log(rows.length, stats.memory, tree.children.length);\n```\n\nPer-core CPU% the way Task Manager computes it, at kilohertz-class rates:\n\n```ts\nimport { CpuSampler, createTicker } from '@bun-win32/sysmon';\nconst sampler = new CpuSampler();\nconst ticker = createTicker(1); // ~700 Hz real, near-zero CPU (Bun.sleep quantizes to 15.6 ms — this doesn't)\nfor (let i = 0; i < 1_000; i += 1) {\n  ticker.wait();\n  void sampler.sample().perCore;\n}\nticker.dispose();\n```\n\nSocket→PID without netstat, drives with UNC + quota-aware free space, per-interface counters:\n\n```ts\nimport { diskSpace, drives, interfaceCounters, tcpSockets } from '@bun-win32/sysmon';\nconsole.log(tcpSockets({ resolveProcessNames: true }).filter((s) => s.state === 2).length, 'listeners');\nconsole.log(drives().map((d) => `${d.path} ${d.filesystem}`).join(' '), diskSpace('C:').availableBytes);\nconsole.log(interfaceCounters().filter((i) => i.operStatus === 1).map((i) => i.alias).join(', '));\n```\n\nAnd the capabilities **no npm package offers**:\n\n- **Real-time decoded ETW** — `new EtwSession().run(onEvent, { durationMs })` streams decoded kernel events (Procmon-lite; elevated). The no-admin census: `etwProviders()` (1100+ providers) + `etwProviderSchema(guid)` (full event templates).\n- **Live Event Log tail with publisher message formatting** — `for await (const e of tailEvents({ channel: 'System' }))`. The one native rival (nwinread) returns raw XML only, x64-only prebuilds, and its repo is gone.\n- **Native PDH perfmon counters** — `CounterSet`, locale-proof English paths, wildcard expansion; the only direct PDH binding on npm.\n- **Per-process GPU%** — `gpuUsageByProcess()`, Task Manager's GPU column ([pidusage#131](https://github.com/soyuka/pidusage/issues/131) has asked since 2021).\n- **SMBIOS without WMI** — `smbios()`: BIOS/board/CPU/per-slot RAM straight from the firmware table.\n- **File-lock forensics** — `whoLocks(paths)`: which processes hold a file open (Restart Manager).\n- **Disk I/O counters** — `diskIoCounters()` + `processIoCounters(pid)` (systeminformation returns null on Windows, [#274](https://github.com/sebhildebrandt/systeminformation/issues/274)).\n- Plus `cpuFrequency()` (live, not the base clock), `sessions()` (real RDP/console attribution), `powerStatus()`/`batteryState()`/`powerScheme()`, handle/GDI/USER object counts, and a high-res `watch()` that samples at ~700 Hz for the CPU cost systeminformation's `observe()` spends on 1 Hz.\n\n![sysmon-report](https://raw.githubusercontent.com/ObscuritySRL/bun-win32/main/packages/all/screenshots/sysmon-report.png)\n\n*`example/sysmon-report.ts` — the full census on one page: SMBIOS identity, memory + commit, top processes, drives, socket owners, sessions — zero spawns.*\n\n## Honest scoping\n\n- **Windows 10/11 + Server, Bun ≥ 1.1, x64.** Not a cross-platform library — that's systeminformation's value, not this package's. Windows-native depth is the thesis.\n- **Node core already covers the trivial cases** — `os.freemem()`, `process.cpuUsage()`, `fs.statfs` (single-path free space). sysmon's value is everything core can't reach: other-process metrics, per-core load, socket→PID, counters, ETW, the Event Log, SMBIOS, GPU%.\n- **Real-time ETW needs an elevated process and blocks the JS thread while pumping** (`durationMs` is the contract). Everything else — including the provider census and the Event Log tail — is no-admin.\n- **EvtSubscribe push and a worker-owned ETW AsyncIterable are deliberately out of v1** (foreign-thread callbacks are a crash class under FFI). The tail is pull+poll; the firehose is blocking/foreground.\n- **No CPU temperature / S.M.A.R.T. / fan speeds** — there is no universal Windows path (vendor IOCTLs; the packages that claim it usually return null). A deliberate non-goal, not an omission.\n\n## Note to AI agents\n\nRead [`AI.md`](https://github.com/ObscuritySRL/bun-win32/blob/main/packages/sysmon/AI.md) — it is the complete surface contract: every export with its signature, a capability→API table, copy-paste recipes, and the gotchas ledger. You should not need to read source.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}