CMTrace Open

Adam Gell · AdamGell.CMTraceOpen

An open-source log viewer inspired by Microsoft's CMTrace.exe.

winget install --id AdamGell.CMTraceOpen --exact --source winget

Latest 1.1.0

Release Notes

What's New in v1.1.0 New Workspaces

  • Event Log Viewer — Parse .evtx files or query live Windows Event Log channels. "This Computer" auto-loads Application, System, Security, and Setup in parallel. Event Viewer-style nested tree sidebar, severity badges, channel grouping, and resizable detail pane.
  • Sysmon Dashboard — Full Sysmon analysis workspace: open .evtx files or query the live Sysmon event log. Dashboard with metric cards, event type chart, timeline histogram, security alerts, and top process/network/DNS/registry lists. Events table with virtual scrolling and severity filtering. Classifies 23 Sysmon event types with structured field extraction. Intune Enhancements
  • Microsoft Graph API integration (Windows, opt-in) — Resolve app GUIDs to display names via Graph API. Authenticates silently using WAM with the device's existing Entra ID session — no app registration required. Pre-populate cache fetches apps, remediation scripts, platform scripts, and shell scripts. Gated behind Settings > Graph API toggle.
  • AppWorkload enrichment — Parse "Get policies" JSON payloads to build GUID-to-app-name mappings. InfoPane shows resolved app names, structured policy metadata cards, and decoded base64 PowerShell detection scripts.
  • Activity view — Groups timeline events by app into collapsible cards with worst status, event count, duration, and parsed structured fields (intent, detection, applicability, reboot, enforcement).
  • GUID Registry dialog — Searchable table of all GUID-to-app-name mappings with source confidence ranking and tabbed view (All/Apps/Scripts/Remediations).
  • SideCarScriptDetectionManager events — PowerShell script detection lifecycle events in the Intune timeline. Log Viewer Features
  • Settings dialog — Full settings UI replacing the Accessibility dialog: Appearance, Columns, Behavior, Updates, File Associations tabs. Ctrl+, to open.
  • Context menu — Right-click any log row for Copy, Jump to Line, Quick Filter, Reveal in File Manager, and Error Lookup via native OS menu.
  • Multi-file unified timeline — Merge entries from multiple open log files into a single time-sorted view with color-coded source borders and cross-file timestamp correlation.
  • Session save/restore — Save workspace state to .cmtrace JSON files (Ctrl+Shift+S). Files integrity-checked with SHA-256 hashes on restore.
  • Log diff — Compare two open log files side-by-side or inline. Fuzzy matching normalizes GUIDs and timestamps for smarter diffing.
  • Resizable InfoPane, Jump to Line, Reveal in File Manager, Quick Filter Bug Fixes
  • Rotated AppWorkload files now correctly parse as LogicalRecord framing
  • GUID extraction prefers "for app " patterns over generic first-GUID matching
  • Session save no longer silently fails when no tabs are open
  • Session restore no longer bails entirely when saved files are missing
  • Tab close properly clears log content, filters, and UI state Downloads ───────────────────────────────┬──────────────────────────────────── File │Description ───────────────────────────────┼──────────────────────────────────── CMTrace-Open_1.1.0_x64.msi │MSI installer (includes Full + Lite) ───────────────────────────────┼──────────────────────────────────── CMTrace-Open_1.1.0_x64.exe │Standalone full edition ───────────────────────────────┼──────────────────────────────────── CMTrace-Open-Lite_1.1.0_x64.exe│Standalone lite edition ───────────────────────────────┴────────────────────────────────────

Installer types: portable , wix

Architecture Scope Type Download SHA256
x64 portable Download A9E999E793BD1F43CB4C31B39F7E1569DD7D7364E5CA3B6FFFFF1F3F8C589AEC
arm64 portable Download 013FC381239800FC940815105F524B773EF72944A16235483497AD3D5BB50358
x64 machine wix Download 57A69DBC2145CDB50DBF3659910A4D20543D6F3F9E795CABFC00CF05C75CB0B6
arm64 machine wix Download C23A83BC4BF0B2F3E882DCDAFCEB109D3B81F60AA52B02FEC74C658E96A9E250

Details

Homepage
https://github.com/adamgell/cmtraceopen
License
MIT
Publisher
Adam Gell
Support
https://github.com/adamgell/cmtraceopen/issues

Tags

cmtraceintune

Older versions (7)

1.0.2
Architecture Scope Type Download SHA256
x64 portable Download FE09348575F353B7DFD54DB7BFBAFB38C14D3796DB70F7EC1A25EED688A7FEF9
arm64 portable Download DD843C116430CB5BEE468D84B0054920BCCA2B623CA6C085B6184AE3A03FD81F
x64 machine nullsoft Download F1A7F0BD3C93374953605B3A8279333670C20400556ED8CA4A9A3F611BB82BE5
x64 machine wix Download 8F5B7E452BAC697103A9B9E71D217F41A6696600BD7F2D0A42ADCB4510A8D250
arm64 machine nullsoft Download 213530C181001F22769E0C7AF3DBFB031891CEC145C303B6AC1B16892D28193E
arm64 machine wix Download A9B3B6800BE69DFA00807D4F2125D772C4EF35FE623097ED7885E88EC630DEA7
1.0.1
Architecture Scope Type Download SHA256
x64 portable Download 42C9C1625E6860D2B236D8DE165184141AF305CA72104393AD01E3C624B16B7C
arm64 portable Download 8C403697EF24E15EADD5BA5C57FE9FDFF00A0D22D0A47C896583C517BBD5A506
x64 machine wix Download FCA72A6E2C06FE1A389EA5891EADAAD15CA57C8609BA0E6E4FD60119DDC00E39
arm64 machine wix Download 9C9AFC120576ECE8985B0B03DF10D0C177C5FB4026393ED45A452323527267FA
1.0.0
Architecture Scope Type Download SHA256
x64 portable Download 08D19DD83243C3CE6ECDD104B4535BA27E9FFF47B5DB58BC383F1D95B9EE9107
arm64 portable Download EC38C1ED9A1BBDA10DA399777B1B82C008BE2DBE42F77893918D1D0BA90D3265
x64 machine wix Download F148A3666F67D30DC2F05D55D665101CBA1D72046A4EDFFA9947F9E821CCE119
arm64 machine wix Download 4534CB8539FE0006520DDD5BFFE46656FF0A3E23E16149BEE41D0F5C41B6DE04
0.5.1
Architecture Scope Type Download SHA256
x64 portable Download 80F6F2129137B629F81784B15912B3996DD503B0495BA3516903B2F1FC98ABA5
arm64 portable Download 926958660425D021B36F66E3E6EE9C612B4B9DCDB768F8172931DEDD437DAB69
x64 machine wix Download 53184506FCA50750E9127B5B0948EB04D2FAAAF67AEC53DBB7B109E413B8E5AA
arm64 machine wix Download 74D19E56D0A116EEBD8D5A7A1F3B45A134B3DFB5A292D85AAA921323EB2CB44A
0.5.0
Architecture Scope Type Download SHA256
x64 portable Download 64F6705ECDCEAE2FD5AB9C5DF59F3743D3E08F3360880622A764EAAD83CC9A5C
arm64 portable Download 68F219ACBA86C0026D0896E8E9407DF9B314356EB5D3AAF4E399748DC0C0D6E9
x64 machine wix Download EEFC04AC5D782E70963760E32ED2E9B63F04E57BF697ECCF0A6110EEE0D2717C
arm64 machine wix Download A6FEED90E382C732ED3348E336D06BDF0E4ACA816F99A09B88D19DA5EE019C19
0.4.0
Architecture Scope Download SHA256
arm64 Download BA816AE95AE4C41F34E105AF4E68C1D8181BB5CA4CE851D81C5036F1A43C95A4
x64 Download F82DA194B5F96BD44530002A46368699C8D48A6EC213C16CE64EE8CA69AD264B
0.3.0
Architecture Scope Download SHA256
arm64 Download 5B8A24BADD2B621A632998C935899552082AD4263CCBFE8E28C46C0C04B8D98C
x64 Download 304AA889C27385930A90273CAC1A4187FBE80F320CA0642EB8B458A283EC82B5