More free tools →

Denied

Why does this app crash? Procmon already recorded the answer - it is just buried under 400,000 rows of noise. Drop a Procmon CSV and get the read an experienced admin would give you: the denied access that mattered, the DLL that never turned up, the file a scanner had locked, and everything that looks scary but is fine.

Runs entirely in your browser. Nothing is uploaded, stored, or sent to us.

1Capture small: pick what you are troubleshooting

The number one Procmon mistake is capturing everything and drowning. Filter before you capture and the file stays small, the analysis stays sharp, and the export takes seconds. Pick your situation and follow the exact clicks:

The save step matters: in the Save dialog, choose CSV and "Events displayed using current filter". That choice is the difference between a 5 MB file and a 500 MB one.

2Drop the CSV here

No capture handy? Analyze a sample capture to see what the report looks like.

This reads one capture. The fix usually needs the fleet.

When the culprit turns out to be a missing AV exclusion, a broken ACL, or a half-broken install, the other three hundred machines are next. RFF is the fast RMM: push the fix everywhere as a script or a policy, watch it land in real time, and keep the inventory that tells you which machines even have the app.

Start free for 100 endpoints

How to actually read a Procmon capture

Process Monitor is the most powerful troubleshooting tool on Windows, and most people use five percent of it. The barrier is not the capture - it is knowing which of 400,000 events is the signal. An experienced admin scans for a handful of patterns: ACCESS DENIED on a path the failing process actually needs, a chain of NAME NOT FOUND probes for a DLL that never resolves, a SHARING VIOLATION where the other process turns out to be the antivirus, a process that exits with a crash status right after one of the above. This tool encodes that scan and runs it on your file, locally.

What it checks

The noise: what Procmon shows you that is fine

Half of Procmon's intimidation is that a healthy machine produces thousands of alarming-looking results. These are the codes that scare people and mean nothing. The analyzer counts them in your capture and sets them aside, so what remains is worth reading:

BUFFER OVERFLOWthe app asked Windows how big a buffer it needs. An API handshake, nothing overflowed.
BUFFER TOO SMALLsame handshake as BUFFER OVERFLOW - the call is retried with a bigger buffer.
NAME NOT FOUNDapps probe for optional files and registry keys constantly. Only a pattern of these right before a failure matters.
PATH NOT FOUNDsame as NAME NOT FOUND, one level up - the folder does not exist.
NO SUCH FILEa probe for a file that is not there. Same family as NAME NOT FOUND.
REPARSEregistry or filesystem redirection doing its job (WOW64, symlinks). Not an error.
FAST IO DISALLOWEDan internal filter-driver detail. Harmless.
NO MORE ENTRIESa directory or key enumeration reached its end. That is how enumeration stops.
NO MORE FILESa directory listing reached its end.
END OF FILEa read reached the end of the file. Normal.
FILE LOCKED WITH ONLY READERSmemory-mapped file coordination. Normal.
FILE LOCKED WITH WRITERSmemory-mapped file coordination. Normal.
IS DIRECTORYthe app opened a folder the way it opens files. Routine.
INVALID DEVICE REQUESTa capability probe against a device that does not support it. Routine.
INVALID PARAMETERusually a capability probe, not a bug you can act on from here.
NOT REPARSE POINTa probe checking whether a path is a link. It is not. Fine.
KEY DELETEDa handle to a registry key that was deleted - usually teardown order, not a fault.
CANCELLEDan I/O was cancelled, commonly an oplock break or a closing handle. Usually benign.
NOT IMPLEMENTEDa capability probe against something Windows does not support. Routine.
OPLOCK NOT GRANTEDfile-lock negotiation between processes. Routine.

FAQ

What Procmon filter should I set before capturing?

Filter before you capture, not after. For a crashing app: Process Name is yourapp.exe, Include. For suspected antivirus interference: filter on Path begins with the app's folders instead, so the scanners stay visible. The recipes on this page give the exact clicks for each situation, and a narrow capture keeps the CSV small enough to analyze anywhere.

How do I save a Procmon capture as CSV?

In Procmon: File, then Save, choose CSV (Comma-Separated Values) as the format, and pick "Events displayed using current filter". That last choice is what keeps the file small - it exports only what your filter shows, not everything Procmon buffered.

Can this read a .PML file?

Not directly - a .PML is Procmon's binary format. Open the PML in Procmon and re-save it as CSV (File, Save, CSV format), then drop the CSV here.

Is ACCESS DENIED in Procmon always a problem?

No. Security agents deny access to their own files and keys as self-protection, and apps routinely probe locations they do not strictly need. The signal is a process being denied access on a path it needs and then failing right after. This tool does that correlation for you: denied events are weighed by whether the process crashed or misbehaved afterwards.

What does BUFFER OVERFLOW mean in a Procmon trace?

It is not an attack and not a bug. The app asked Windows how big a buffer it needs for a value, Windows answered "bigger than what you passed", and the app retries with the right size. It is one of the most common results in any trace and it is completely normal.

Is my capture uploaded anywhere?

No. The CSV is read and analyzed entirely in your browser - nothing is uploaded, stored, or sent to us. That matters more than usual here, because a Procmon capture contains every file path, registry value name, and process command line on the machine. You can verify in your browser's developer tools: there is no upload request.

Open source

Denied is MIT-licensed at github.com/deadarcher/denied. The analysis engine on this page is byte-identical to the one in the repo, and our CI fails the build if they ever drift. Self-host it with one line of Docker:

docker run --rm -p 8080:80 ghcr.io/deadarcher/denied:latest

Wrong verdict on a real capture? Open an issue, with the CSV if you can share it - that is exactly the feedback that tunes the heuristics.

Built by the RFF team. More free Windows tools.