Mark Russinovich of SysInternals has made available Tokenmon which is an application that monitors and displays a variety of security-related activity taking place on a system. Tokenmon gets its name from the fact that Windows NT/2000 stores a process' security information, including the user account context in which the process executes, in an object called a token. Tokenmon monitors includes the following:
- User logon/logoff
- Applications enabling or disabling security privileges in their process tokens
- Process startup and exit (token creation/deletion)
- Impersonation