Documentation
Driver installation
One small kernel component, installed on purpose with administrator rights.
1. What the driver is
CommMonitor captures at the driver level. A filter attaches to the serial device stack and observes the requests that pass through it, so the application that owns the port keeps working.
- Service name: CommMonitorDrv12x
- Device path: the application talks to \\.\ComDrv12x
- Driver file: nt6\ComDrv12Ex64.sys inside the package, copied to the Windows driver directory on install
- Per-port configuration: a bitmap of 39 serial control codes and 28 IRP major function codes
2. Installing it
There are two entry points, and both end in the same place:
- The application offers to install or start the driver when you press Start and the service is not running.
- CommMonitor.exe --install-driver does the same thing from a command line, and asks for elevation if it is not already elevated.
Installation is idempotent. If the service is already running, nothing is changed and no elevation is needed.
3. Why there is no uninstall
A filter driver sits inside a live device stack. Stopping it underneath an application that is holding the port can leave the device in an undefined state, so the product deliberately offers no uninstall action.
If you need the machine clean, remove the service with the standard Windows service tools while no serial application is running, or reimage. Test the product on a machine you can reimage before you roll it out.
4. Reading the driver state
The status bar and the Problems panel report the service state using these names:
- not installed
- The service does not exist on this machine.
- stopped
- The service exists but is not running.
- running
- Capture can start.
- starting / stopping / pausing / resuming
- A transition is in progress; wait for it to settle.
- unknown
- The state could not be queried - usually a permissions problem.
Access denied means the application is not elevated; a missing driver file means the package was unpacked incompletely.
5. Antivirus and endpoint protection
A kernel driver that other software did not install is exactly the sort of component endpoint protection is designed to question. If installation is blocked, check the product's quarantine and reputation features first, and verify the driver hash from integrity.txt before you decide.
We do not publish a claim about code-signing or reputation: those change with each build. What you can verify is the hash, and what we can do is answer specific questions about what the driver does.

