Sysinternals has long been the choice for both analysing malware behaviour and in penetration tests with focus on application assessments. It allows you to see exactly what a binary is really doing deep down in the Windows OS, such as reading and writing files, reading and writing registry keys and the execution of child processes, etc.
We say goodbye to RegMon and FileMon as for some time now ProcMon did their goodness anyway... so they've officially been put into a retirement home.
ProcMon and ProcDump got an overhaul - little tweaks here and there.
Grab them from Sysinternal's website here.