Denied
Why does this app crash? Procmon already recorded the answer - it is just buried under 400,000 rows of noise. Drop a Procmon CSV and get the read an experienced admin would give you: the denied access that mattered, the DLL that never turned up, the file a scanner had locked, and everything that looks scary but is fine.
Runs entirely in your browser. Nothing is uploaded, stored, or sent to us.1Capture small: pick what you are troubleshooting
The number one Procmon mistake is capturing everything and drowning. Filter before you capture and the file stays small, the analysis stays sharp, and the export takes seconds. Pick your situation and follow the exact clicks:
The save step matters: in the Save dialog, choose CSV and "Events displayed using current filter". That choice is the difference between a 5 MB file and a 500 MB one.
2Drop the CSV here
No capture handy? Analyze a sample capture to see what the report looks like.
This reads one capture. The fix usually needs the fleet.
When the culprit turns out to be a missing AV exclusion, a broken ACL, or a half-broken install, the other three hundred machines are next. RFF is the fast RMM: push the fix everywhere as a script or a policy, watch it land in real time, and keep the inventory that tells you which machines even have the app.
Start free for 100 endpointsHow to actually read a Procmon capture
Process Monitor is the most powerful troubleshooting tool on Windows, and most people use five percent of it. The barrier is not the capture - it is knowing which of 400,000 events is the signal. An experienced admin scans for a handful of patterns: ACCESS DENIED on a path the failing process actually needs, a chain of NAME NOT FOUND probes for a DLL that never resolves, a SHARING VIOLATION where the other process turns out to be the antivirus, a process that exits with a crash status right after one of the above. This tool encodes that scan and runs it on your file, locally.
What it checks
- Crashes, decoded - exit codes are translated (0xC0000135 is "a required DLL was not found", 0xC0000005 is an access violation, 1603 is the MSI fatal error) and correlated with the failures captured in the moments before the exit.
- Access denied that matters - denied events are clustered per path and weighed by what happened next. A security agent protecting its own keys is noise; an app denied on its own config and then dying is the answer.
- DLL search chains - a process probing folder after folder for the same DLL and never finding it, with API-set stubs (api-ms-win-*) correctly ignored because those miss by design.
- Locked files - SHARING VIOLATION clusters, including naming the likely holder when a scanner touched the same file moments earlier.
- Scanners stepping on each other - two real-time engines active at once, and any product shadow-scanning the same files your app touches, which is what a missing exclusion looks like in a trace.
- The loudest process - when one process is most of the capture, it is named, and a process hammering one path thousands of times gets called what it is: a polling or self-repair loop.
The noise: what Procmon shows you that is fine
Half of Procmon's intimidation is that a healthy machine produces thousands of alarming-looking results. These are the codes that scare people and mean nothing. The analyzer counts them in your capture and sets them aside, so what remains is worth reading:
BUFFER OVERFLOW | the app asked Windows how big a buffer it needs. An API handshake, nothing overflowed. |
BUFFER TOO SMALL | same handshake as BUFFER OVERFLOW - the call is retried with a bigger buffer. |
NAME NOT FOUND | apps probe for optional files and registry keys constantly. Only a pattern of these right before a failure matters. |
PATH NOT FOUND | same as NAME NOT FOUND, one level up - the folder does not exist. |
NO SUCH FILE | a probe for a file that is not there. Same family as NAME NOT FOUND. |
REPARSE | registry or filesystem redirection doing its job (WOW64, symlinks). Not an error. |
FAST IO DISALLOWED | an internal filter-driver detail. Harmless. |
NO MORE ENTRIES | a directory or key enumeration reached its end. That is how enumeration stops. |
NO MORE FILES | a directory listing reached its end. |
END OF FILE | a read reached the end of the file. Normal. |
FILE LOCKED WITH ONLY READERS | memory-mapped file coordination. Normal. |
FILE LOCKED WITH WRITERS | memory-mapped file coordination. Normal. |
IS DIRECTORY | the app opened a folder the way it opens files. Routine. |
INVALID DEVICE REQUEST | a capability probe against a device that does not support it. Routine. |
INVALID PARAMETER | usually a capability probe, not a bug you can act on from here. |
NOT REPARSE POINT | a probe checking whether a path is a link. It is not. Fine. |
KEY DELETED | a handle to a registry key that was deleted - usually teardown order, not a fault. |
CANCELLED | an I/O was cancelled, commonly an oplock break or a closing handle. Usually benign. |
NOT IMPLEMENTED | a capability probe against something Windows does not support. Routine. |
OPLOCK NOT GRANTED | file-lock negotiation between processes. Routine. |
FAQ
What Procmon filter should I set before capturing?
Filter before you capture, not after. For a crashing app: Process Name is yourapp.exe, Include. For suspected antivirus interference: filter on Path begins with the app's folders instead, so the scanners stay visible. The recipes on this page give the exact clicks for each situation, and a narrow capture keeps the CSV small enough to analyze anywhere.
How do I save a Procmon capture as CSV?
In Procmon: File, then Save, choose CSV (Comma-Separated Values) as the format, and pick "Events displayed using current filter". That last choice is what keeps the file small - it exports only what your filter shows, not everything Procmon buffered.
Can this read a .PML file?
Not directly - a .PML is Procmon's binary format. Open the PML in Procmon and re-save it as CSV (File, Save, CSV format), then drop the CSV here.
Is ACCESS DENIED in Procmon always a problem?
No. Security agents deny access to their own files and keys as self-protection, and apps routinely probe locations they do not strictly need. The signal is a process being denied access on a path it needs and then failing right after. This tool does that correlation for you: denied events are weighed by whether the process crashed or misbehaved afterwards.
What does BUFFER OVERFLOW mean in a Procmon trace?
It is not an attack and not a bug. The app asked Windows how big a buffer it needs for a value, Windows answered "bigger than what you passed", and the app retries with the right size. It is one of the most common results in any trace and it is completely normal.
Is my capture uploaded anywhere?
No. The CSV is read and analyzed entirely in your browser - nothing is uploaded, stored, or sent to us. That matters more than usual here, because a Procmon capture contains every file path, registry value name, and process command line on the machine. You can verify in your browser's developer tools: there is no upload request.
Open source
Denied is MIT-licensed at github.com/deadarcher/denied. The analysis engine on this page is byte-identical to the one in the repo, and our CI fails the build if they ever drift. Self-host it with one line of Docker:
docker run --rm -p 8080:80 ghcr.io/deadarcher/denied:latest Wrong verdict on a real capture? Open an issue, with the CSV if you can share it - that is exactly the feedback that tunes the heuristics.