That reframes the anniversary. The real story is that Windows has had a second, deeper diagnostic layer for three decades, maintained by one of Microsoft's most senior engineers, and most Windows 11 owners never encounter it. For sysadmins and developers, Sysinternals is familiar. For the much larger group of enthusiasts who live in Task Manager and the Startup apps page in Settings, the question is practical: which of these tools are worth installing, what do they show that the built-in tools don't, and where is Microsoft taking them next?
Sysinternals at 30: A 1996 Russinovich Side Project That Microsoft Still Updates Every Few Weeks
Microsoft's official Sysinternals hub on Microsoft Learn describes the origin plainly: the Sysinternals website "was created in 1996 by Mark Russinovich to host his advanced system utilities and technical information." The same page positions the tools for IT professionals and developers who need to "manage, troubleshoot and diagnose your Windows and Linux systems and applications." With that 1996 start date, 2026 is the suite's 30th year. XDA notes that Microsoft acquired the company in 2006, which makes this year the 20th anniversary of Sysinternals becoming a Microsoft property as well.
The name itself can mislead people. XDA's columnist observes that "Sysinternals" sounds like a set of internal tools for Microsoft engineers, and that it is easy to assume the utilities stopped getting attention years ago. Neither is accurate. The tools are public downloads, the product pages carry Russinovich's byline, and the "What's New" feed on Microsoft Learn records a steady flow of releases throughout 2026.
The suite has also grown well beyond Windows. The 2026 release feed includes listent 1.0, a macOS command-line tool for discovering code-signing entitlements in executable binaries, and ZoomIt for Mac, which Microsoft describes as bringing the Windows version's zooming, annotation, screenshot and recording capabilities to macOS. The utilities index also lists jcd, a directory-navigation tool for Linux and macOS. Windows remains the center of the collection. The cross-platform additions show a toolkit that is still expanding in 2026.
The anniversary shares a birth year with another Microsoft power-user project. According to 9to5Windows, PowerToys also turns 30 this year, having first been released for Windows 95 in November 1996 before its modern open-source revival. The two toolkits have ended up in a similar position on Windows 11: both are Microsoft products, both are aimed at people who want more control, and both are opt-in downloads rather than inbox components. WindowsForum's earlier reporting on Windows 11's optional tools described PowerToys and Visual Studio Code as opt-in by design, because they are fast-moving tools aimed at audiences that expect to install their own utilities. XDA has separately pointed out that nothing in Windows setup tells a new user that PowerToys utilities like FancyZones, Command Palette or Keyboard Manager exist. Sysinternals is even further out of view, because PowerToys at least has a consumer-friendly identity. Sysinternals has none.
Six Sysinternals Release Drops Between March and August, Then a September 10 Build
XDA's claim that the Sysinternals hub logged six substantial update drops between March 26 and August 19, 2026 checks out against Microsoft's "What's New" feed. The feed shows dated release batches on March 26, May 7, June 17, July 24, August 12 and August 19. The Sysinternals Suite download page and the utilities index were then updated again on September 10, 2026.
The following table summarizes the 2026 releases recorded on Microsoft's Sysinternals hub.
| Date (2026) | Tool and version | Change Microsoft recorded |
|---|---|---|
| March 26 | DebugView 5.0 | Improved Windows 11 support, a modern UI with a dark theme, and performance optimizations |
| March 26 | Sysmon 15.2 | Better handling of the internal event queue, making the service more resilient to dropped events under high system load |
| March 26 | NotMyFault 4.40 | Added secure kernel and hypervisor crash triggers |
| March 26 | ZoomIt 11.0 | Panorama/scrolling screenshots, text extraction during snip, break timer improvements, and the trimming clip editor for existing.mp4 files |
| March 26 | listent 1.0 (macOS) | New tool for listing code-signing entitlements |
| May 7 | Autoruns 14.2 | Added support for Windows packaged apps |
| May 7 | ProcDump 12.0 | Added process tree support with the -pt switch |
| May 7 | ZoomIt 12.0 | Webcam overlay for video captures and clip appending in the video trim editor |
| June 17 | Autoruns 14.3 | Bug fixes, and the command-line autorunsc brought fully in line with the GUI, including packaged-app support |
| June 17 | ZoomIt 12.1 | Image backgrounds, webcam background blur and microphone noise cancellation |
| July 24 | ZoomIt for Mac 12.21 | macOS release of ZoomIt |
| August 12 | NotMyFault 4.6 | Rewritten in Rust with a modern UI |
| August 12 | RDCMan 3.20 | Azure Virtual Desktop workspace feed and Microsoft Dev Box support |
| August 12 | ZoomIt 12.2 | DemoMirror, for mirroring the screen, a region, or a window onto a second monitor |
| August 19 | Process Monitor 4.1 | New IPC event class for named pipes and mailslots |
| August 19 | ZoomIt 12.3 for macOS | DemoMirror for the Mac version |
The utilities index then records a further set of point releases dated September 10, 2026: Process Explorer 17.14, Process Monitor 4.11, Sysmon 15.22, Sigcheck 2.92, ZoomIt 12.22, PipeList 1.03, and several PsTools components including PsGetSid 1.47, PsInfo 1.8, PsKill 1.18, PsShutdown 2.61 and PsSuspend 1.09. Other versions that appear only in the index include DebugView 5.02 (June 17), ProcDump 12.01 and LiveKd 5.65 (both July 9), Coreinfo 4.02 and PsPing 2.13 (August 12), RDCMan 3.21 (August 19), and SDelete 2.06 (March 5). Read together, the feed records the headline releases, and the index shows the maintenance builds that followed. The version numbers progress consistently: Sysmon 15.2 in March becomes 15.22 by September, and Process Monitor 4.1 in August becomes 4.11 three weeks later.
That rhythm matters for how readers should treat the suite. A Sysinternals download is a snapshot. A copy pulled onto a USB stick in 2024 is missing Autoruns' packaged-app support, DebugView's rebuilt interface and Process Monitor's IPC events. Anyone who keeps a toolkit folder for troubleshooting should refresh it on a regular schedule, or use a distribution route that updates automatically, which the Microsoft Store option provides.
The index also shows that "actively maintained" applies unevenly across the 74 entries in the Suite. The flagship tools get regular attention, and some of them received updates several times this year. Plenty of smaller utilities have not changed in years. Junction 1.07, ListDLLs 3.2, Hex2dec 1.1, NTFSInfo 1.2 and Sync 2.2 all carry July 4, 2016 dates. TCPView 4.19 dates from April 2023, and VMMap 3.4 from October 2023. The BlueScreen screen saver is dated November 1, 2006, and its description still lists Windows NT 4, Windows 2000, Windows XP, Server 2003, and Windows 95 and 98. The dormant tools still work as reference utilities, but "updated regularly" describes the suite's core. It does not describe every file in the download.
Process Explorer 17.14 Shows the Handles and DLLs That Task Manager Leaves Out
Process Explorer is the strongest single argument for installing Sysinternals, and XDA's columnist says it replaced Task Manager on their PC, to the point of mapping a keyboard shortcut to launch it whenever a process ran into trouble. That is a personal workflow judgment, but Microsoft's own description of the tool explains why people make it.
Microsoft's product page opens with the problem Process Explorer was built to solve: "Ever wondered which program has a particular file or directory open? Now you can find out." The tool shows which handles and DLLs each process has opened or loaded. A handle is a process's reference to an operating-system object such as a file, directory or registry key. A DLL is a code library that a process loads to use shared functions. The utilities index adds that Process Explorer can reveal what files, registry keys and "other objects" processes have open, and it "will even show you who owns each process."
The interface follows from that purpose. Process Explorer's window has two panes. The top pane always lists the currently active processes, including the names of the accounts that own them. The bottom pane changes with the mode you pick. In handle mode it lists the handles opened by whichever process is selected in the top pane. In DLL mode it lists the DLLs and memory-mapped files that process has loaded. A search function works in the other direction: give it a handle or DLL name, and it shows which processes have that object open or that library loaded.
Microsoft describes the practical payoff as help with "tracking down DLL-version problems or handle leaks." The file-lock case is the one most Windows users will actually hit. When Windows refuses to delete or rename a file because it is in use, the search function answers the question the error dialog leaves open, which is which process is holding it. The DLL view serves developers and security-minded users trying to understand what code a process has pulled in, including modules from unexpected locations.
One detail in XDA's column needs correcting. XDA writes that the September 10 build "introduced Process Explorer 17.14, which now shows the handles and DLLs each process has open." Process Explorer 17.14 was published on September 10, 2026, but handle and DLL inspection is the tool's defining, long-standing function. It is the capability the product page opens with, not a new feature of this release. Microsoft's Process Explorer page does not list what changed in 17.14. Readers should treat 17.14 as the current maintenance build of a mature tool.
The same product page carries two compatibility details that matter before downloading. Process Explorer 17.14 lists its supported platforms as Windows 11 and higher on the client side, and Windows Server 2019 and higher on the server side. Windows 10 is not in the current supported-client list, so anyone still running Windows 10 is outside Microsoft's stated support for this build. Installation, by contrast, is trivial. Microsoft's instruction is simply to run procexp.exe, and a help file documents operation. The download is 3.5 MB.
Power users who want Process Explorer to resolve function names inside Windows components will run into symbol configuration. Microsoft notes that when you configure the path to DBGHELP.DLL and the symbol path uses a symbol server, the folder containing DBGHELP.DLL must also contain SYMSRV.DLL to support the server paths used. That is a niche setting, but it explains a common confusion when symbol lookups fail even though a symbol server has been specified.
Process Explorer also has command-line siblings for scripted or remote work, which Microsoft cross-references from the same page. Handle is a command-line handle viewer, ListDLLs is a command-line DLL viewer, PsList lists processes locally or remotely, and PsKill terminates local or remote processes. For administrators, those counterparts are often more useful than the GUI, because their output can be captured, logged and compared.
Autoruns 14.3 Exposes the Startup Locations the Settings App Never Lists
If Process Explorer is the deeper Task Manager, Autoruns is the deeper Startup apps page. Microsoft's utilities index describes it as showing what programs are configured to start automatically when the system boots and the user signs in, and adds that Autoruns "also shows you the full list of Registry and file locations where applications can configure auto-start settings."
The key word is full. The Startup apps page in Windows 11 Settings shows a curated set of user-facing startup entries. Software can register itself to run automatically in many more places than that page surfaces. XDA's columnist lists some of the categories Autoruns covers beyond sign-in entries: WMI entries, Winsock providers, boot-execute images and Explorer shell extensions. XDA also writes that Microsoft positions Autoruns as the startup monitor with the widest knowledge of auto-start locations, and that the columnist's own experience agrees. Microsoft's index wording, the "full list" of Registry and file locations, supports the same general claim, though it does not give a count of locations, and neither will this article.
The 2026 updates are the most consequential in years for this tool, because they address how Windows 11 software is increasingly delivered. Autoruns 14.2, released May 7, added support for Windows packaged apps, the app-package format used by Microsoft Store and similar modern app deployments. A startup auditor that can't see packaged apps has a blind spot on a modern Windows 11 PC. Autoruns 14.3, released June 17, added bug fixes and "fully aligns the command-line autorunsc with the GUI capabilities, including packaged apps support."
The command-line alignment is the change IT administrators should note. autorunsc is the scriptable form of Autoruns. Before 14.3, an administrator auditing startup entries through a script could get a different picture than someone clicking through the GUI on the same machine. After 14.3, Microsoft states the two match, including packaged apps. For anyone collecting auto-start inventories across many machines, or comparing a suspect machine's startup entries against a known-good baseline, that parity makes the scripted audit trustworthy.
A word of practical caution belongs here, and it is an inference from how the tool is described rather than a documented Microsoft warning. Autoruns shows the internals of how Windows boots, including entries Windows itself depends on. The fact that an entry appears in the list says nothing about whether it is unwanted. Disabling unfamiliar entries on a working machine can break the software that registered them. Sigcheck, another Suite tool that Microsoft describes as dumping file version information and verifying that images are digitally signed, is the more cautious first step when an unfamiliar executable turns up in a startup location. It was updated to 2.92 on September 10.
Process Monitor 4.1, ProcDump 12.0 and DebugView 5.0 Keep the Deep-Diagnostics Bench Current
Process Explorer and Autoruns are the easiest entry points, but much of Sysinternals' reputation among administrators and developers rests on tools that record behavior over time instead of showing a snapshot.
Process Monitor is the clearest example. Microsoft describes it as a utility for "observing real-time file system, Registry, and process or thread activity," and the index adds DLL activity. Version 4.1, released August 19, adds an IPC event class covering named pipes and mailslots, two Windows inter-process communication mechanisms. Before 4.1, a Process Monitor trace focused on file, registry, process and thread activity. After 4.1, it can also capture those communication events, which is useful when one process's failure depends on another process it talks to. PipeList, which displays the named pipes on a system with the maximum and active instance counts for each, received a September 10 update to 1.03 and complements that new event class.
ProcDump is aimed at problems that are hard to catch live. Microsoft describes it as a command-line utility for capturing process dumps of "otherwise difficult to isolate and reproduce CPU spikes." It also works as a general dump tool and can monitor a process and generate a dump when it has a hung window or an unhandled exception. ProcDump 12.0, released May 7, adds process tree support with the -pt switch. Microsoft's release note says nothing more about it, but the name indicates the switch extends dump capture from a single process to a process and its tree, which matters for applications that spread work across child processes. The current index version is ProcDump 12.01, dated July 9.
DebugView had one of the year's most visible updates. The tool intercepts calls made to DbgPrint by device drivers and to OutputDebugString by Win32 programs, so developers can view and record debug output locally or across the internet without attaching a debugger. DebugView 5.0, released March 26, improved Windows 11 support, moved to a modern interface with a dark theme, and added performance optimizations. The index now lists 5.02, dated June 17.
The same pattern of modernization shows up at the edges of the suite. NotMyFault, which Microsoft describes as a tool that can crash, hang and cause kernel memory leaks on demand, gained secure kernel and hypervisor crash triggers in 4.40 and was rewritten in Rust with a modern UI in 4.6 on August 12. That tool exists for testing crash handling, dump collection and debugging procedures, so it belongs on test systems only. RDCMan, the Remote Desktop connection manager many administrators use daily, added an Azure Virtual Desktop workspace feed and Microsoft Dev Box support in 3.20 on August 12, and reached 3.21 on August 19. LiveKd 5.65, which lets Microsoft kernel debuggers examine a live system, and Coreinfo 4.02, which maps logical processors to physical processors, NUMA nodes and sockets, both received summer updates.
The Suite bundle also includes long-standing administrative staples that did not make headlines this year but explain why sysadmins keep it around. PsExec executes processes on remote systems. AdExplorer is an Active Directory viewer and editor. AccessChk shows effective permissions on files, registry keys, services, processes and kernel objects. TCPView is an active socket viewer. RAMMap analyzes physical memory usage across several tabs and received an update to 1.63 on March 26. VMMap analyzes a process's virtual and physical memory. Disk2vhd converts physical systems into virtual machines. WinObj browses the Object Manager namespace. Taken together, the set covers process, memory, disk, network, identity and security inspection, and Windows 11 has no single inbox equivalent.
Why ZoomIt Made It Into PowerToys and Process Explorer Hasn't
After decades of Microsoft making little effort to promote Sysinternals, XDA argues, the company has started moving pieces of it into PowerToys. The first and so far only full migration is ZoomIt, the screen zoom, annotation and recording tool. According to XDA, PowerToys 0.88 added ZoomIt as a built-in utility, with Russinovich credited for contributing the original code, and PowerToys 0.100 gave it a webcam overlay and clip appending on June 10, 2026.
The Sysinternals release feed sets out the sequence. Standalone ZoomIt 12.0 gained webcam overlay support and clip appending in its trim editor on May 7. The PowerToys release carrying the same capabilities followed on June 10, according to XDA. For this feature, the standalone Sysinternals version led and the PowerToys copy followed about a month later. Standalone ZoomIt kept moving after that: 12.1 in June added image backgrounds, webcam background blur and microphone noise cancellation, and 12.2 in August added DemoMirror. Users who want the newest ZoomIt features first have a reason to prefer the Sysinternals build, while PowerToys users get ZoomIt inside a toolkit they may already run.
The obvious next candidate is Process Explorer, and there is organized demand for it. XDA reports, and the PowerToys GitHub repository shows, a feature request opened on February 26, 2026 asking the PowerToys team to make Process Explorer the next Sysinternals integration after ZoomIt. The request lists capabilities it says go beyond Task Manager, including process trees, DLL and handle searches, per-process resource graphs, VirusTotal integration, TCP connections and security attributes. That is a community request. Microsoft has not committed to it or put it on any announced roadmap.
The technical obstacle has also been stated publicly. The Process Explorer request builds on an older umbrella request to bring Sysinternals tools into PowerToys. According to XDA, Microsoft's Clint Rutkas closed that thread with an invitation for the community to name the tools it wanted next, and explained that because the Sysinternals tools rely on undocumented APIs, they cannot simply be moved into PowerToys the way ZoomIt was. The PowerToys team's own developer documentation for the ZoomIt module shows what the migration involved: moving the code, removing private or undocumented implementation details, validating the result through API scanning, and building a bridge between ZoomIt's registry-based settings and the PowerToys settings system.
That is the core reason Sysinternals remains separate. ZoomIt is a presentation tool, and its work can be expressed through documented Windows interfaces with some effort. Process Explorer's value comes from exposing the handle tables and loaded modules of other processes, the kind of deep introspection the Rutkas comment associates with undocumented APIs. Moving it into PowerToys would mean either reworking that dependency or accepting different rules for one module. The public record does not show which way Microsoft would go. It shows that the ZoomIt path does not transfer cleanly to the tools people most want.
Built-In Sysmon Brings One Sysinternals Tool Inside Windows 11, Disabled by Default
Sysmon is the second route by which Sysinternals functionality is reaching Windows, and it goes further than PowerToys: into Windows itself. XDA reports that Sysmon arrived in Windows 11 Insider builds in February 2026 as an optional feature that ships disabled by default.
Standalone Sysmon, which Microsoft describes as an advanced host security monitoring tool that "monitors and reports key system activity via the Windows event log," continues in parallel. Its 15.2 release in March made the service more resilient to dropped events under high system load, and the index lists 15.22 as of September 10.
Microsoft's documentation for the built-in version draws its boundaries clearly. Built-in Sysmon applies to supported Windows 11 or later systems, requires administrator privileges, and is disabled by default. It cannot coexist with a standalone Sysmon installation, so organizations already running the Sysinternals version must choose one. It records system activity to the Windows Event Log, but it does not analyze those events, generate alerts, block activity or prevent actions. It is a telemetry source, and something else, whether a SIEM, a log pipeline or an analyst, must consume what it produces.
Microsoft documents the enablement sequence in two steps, both run with administrator rights:
- Enable the optional feature with
Enable-WindowsOptionalFeature -Online -FeatureName Sysmonin an elevated PowerShell session. - Install the Sysmon service with
sysmon -i.
Enabling the feature is only the start. Microsoft's guidance is that organizations need to supply and test an XML configuration file that defines what Sysmon records, because an overly broad configuration can generate a high volume of events. For a security team, the configuration determines whether Sysmon is useful at all. For a curious enthusiast, the practical message is that turning on built-in Sysmon without a considered configuration produces log volume, not insight.
The built-in feature changes deployment more than capability. Before it, getting Sysmon onto a Windows 11 fleet meant distributing and installing the Sysinternals binary. With the optional feature, the component is part of Windows and is switched on through standard Windows feature management, subject to the no-coexistence rule. Organizations standardized on the standalone installer have no reason to rush, but new deployments on supported Windows 11 systems now have a native option.
Getting Sysinternals Onto a Windows 11 PC: The Suite, the Microsoft Store or Sysinternals Live
Because Sysinternals doesn't ship with Windows 11, the first decision is how to obtain it, and Microsoft offers several documented routes suited to different jobs.
The Sysinternals Suite download on Microsoft Learn, updated September 10, 2026, bundles the troubleshooting utilities and their help files into one package of 192.2 MB. Microsoft notes the Suite excludes non-troubleshooting tools, and it lists 74 entries from AccessChk to ZoomIt, which is where XDA's "over 70 utilities" figure comes from. Two specialized builds sit alongside it: a Sysinternals Suite for ARM64 at 21.3 MB, relevant to Windows on Arm PCs, and a Sysinternals Suite for Nano Server at 9.8 MB. Tools can also be downloaded individually from their own product pages, as with the 3.5 MB Process Explorer package.
The Microsoft Store option addresses the staleness problem described earlier. Microsoft's utilities index describes it as "Sysinternals Utilities installation and updates via Microsoft Store." Given this year's release pace, that is the lowest-maintenance route for a personal PC, where keeping a manually downloaded folder current tends to get forgotten.
Sysinternals Live is the technician's route. Microsoft describes it as a service that runs Sysinternals tools directly from the web without manually downloading them. The documented paths follow a simple pattern, where <toolname> is the tool's executable name:
- In Windows Explorer, enter
live.sysinternals.com/<toolname>or\\live.sysinternals.com\tools\<toolname>. - In a command prompt, run
\\live.sysinternals.com\tools\<toolname>. - To browse everything available, open the Sysinternals Live directory in a browser or Windows Explorer at the live.sysinternals.com address.
For Process Explorer, whose executable Microsoft names as procexp.exe, the command-prompt form is \\live.sysinternals.com\tools\procexp.exe. The Process Explorer page itself offers a "Run now from Sysinternals Live" link. Live is convenient on a machine you're troubleshooting once and don't want to leave files on. In a managed environment, running executables directly from an internet location should first be checked against organizational policy, application-control rules and network restrictions, which may block it entirely.
Whichever route you use, remember that these tools operate at a low level. Several need administrator rights to see everything, as the built-in Sysmon documentation spells out for that component. Their output is also dense. A Process Monitor trace can record enormous volumes of activity in seconds. Microsoft's own starting point for learning is the official guide it lists on the Sysinternals hub, Troubleshooting with the Windows Sysinternals Tools, alongside Russinovich's "Case of the Unexplained" troubleshooting presentations and the Windows Sysinternals Administrator's Reference by Russinovich and Aaron Margosis.
What this means for you
Your decision depends on how often you troubleshoot Windows beyond what Task Manager and Settings can answer. For most readers, the right move is a small, deliberate install of two or three tools. The full Suite is worth it mainly for people who administer machines or write software.
Home users and enthusiasts on Windows 11 get the most return from Process Explorer and Autoruns. Process Explorer answers the "file in use" question and shows which account owns each process. Autoruns, now at 14.3 with packaged-app support, shows startup entries the Settings page doesn't list. Installing them through the Microsoft Store keeps them current without effort. Treat Autoruns as a way to see startup entries first. Use Sigcheck to verify an unfamiliar executable's signature before disabling anything.
IT administrators should refresh any stored Sysinternals toolkit, because 2026 changed several tools meaningfully. The autorunsc parity in Autoruns 14.3 makes scripted startup audits match the GUI. Process Monitor 4.1's IPC events extend what a trace can capture. RDCMan 3.20 and 3.21 add Azure Virtual Desktop and Microsoft Dev Box support. Security teams evaluating built-in Sysmon should plan the XML configuration before enabling the feature and should not enable it on machines already running standalone Sysmon.
Windows 10 holdouts should check platform support before assuming current builds work. Process Explorer 17.14 lists Windows 11 and higher as its supported client platform. PowerToys users who value ZoomIt can stay put, but the standalone Sysinternals ZoomIt got this year's webcam overlay feature about a month earlier and has continued adding features since.
- Sysinternals turned 30 in 2026 and remains a separate download from Windows 11, available as a 192.2 MB Suite, an ARM64 or Nano Server build, individual tools, a Microsoft Store package, or via Sysinternals Live.
- Microsoft recorded six release batches between March 26 and August 19, 2026, followed by a September 10 build that includes Process Explorer 17.14, Process Monitor 4.11 and Sysmon 15.22, so older downloaded copies are materially out of date.
- Process Explorer's handle and DLL views are its long-standing core feature, and version 17.14 is the current maintenance release supported on Windows 11 and Windows Server 2019 or later.
- Autoruns 14.2 added Windows packaged-app support and 14.3 brought the command-line autorunsc to parity with the GUI, which makes it the right tool for complete startup audits on modern Windows 11 PCs.
- A Process Explorer integration into PowerToys is only a community request from February 2026, and Microsoft has publicly cited the tools' reliance on undocumented APIs as the reason they can't move over the way ZoomIt did.
- Built-in Sysmon on supported Windows 11 systems is disabled by default, requires administrator rights, cannot coexist with standalone Sysmon, and only logs events, so it needs a tested XML configuration and a place to send its data.
Thirty years in, Sysinternals is not being folded into Windows 11 wholesale, and the undocumented-API problem Microsoft has described publicly makes that unlikely for the tools people value most. What the 2026 record shows instead is a two-track strategy. The standalone suite keeps shipping at a pace of roughly one release batch a month, while selected pieces cross into the platform where they can be rebuilt on documented foundations: ZoomIt in PowerToys, and Sysmon as a disabled-by-default Windows 11 feature. For Windows users, the practical consequence is unchanged, and the best diagnostic tools Microsoft makes still have to be installed on purpose. Whether Process Explorer becomes the next tool to cross over will be settled in the PowerToys repository, where that request is still open.