BSOD · reviewed 2026-09-01

Windows memory dump evidence helper

A small memory dump can preserve bug-check parameters and a limited view of the crash state. It can support diagnosis but does not automatically prove a root cause.

High for dump location and evidence handlingNot determined by dump presence alone

The reviewed result loads below this input and changes only when you select a relevant context.

Runs in this browser — no upload, no account, nothing stored

Ctrl/ + Enter

Real cases
Resume a saved session — paste a Resume Capsule

The capsule is validated and restored only in this browser. An invalid capsule changes nothing.

Crawlable evidence ledger

What this diagnostic record establishes

Confirmed

  • Windows can store small dump files under %SystemRoot%\Minidump when crash-dump settings and the page file permit it.

Not confirmed

  • The presence of a dump does not mean an online tool can safely or correctly identify the root cause.
  • A highlighted module is not automatically the component that initiated the crash.
Applicable versions
Windows 11 on a currently supported release; Windows 10 only where Microsoft or the device vendor still supports the installed edition
Review status
verified · 2026-09-01
Evidence still needed
Crash time; Dump timestamp; Stop Code; File size; Whether dumps are created repeatedly

Context changes the route

What evidence do you have now?

A minidump exists

Likely layer: Crash evidence

First safe check: Match the dump to the crash before sharing it

Expected: You will know whether the file belongs to the incident you are diagnosing.

No minidump appears

Likely layer: Crash-dump configuration or page-file boundary

First safe check: Check the current dump setting without changing it yet

Expected: You will identify whether the system is configured to create a small dump and where Windows expects to write it.

Before any second repair step

Verify the observation and preserve the evidence

After the first safe check, record whether the reviewed intermediate result occurred, whether the original problem was retested, and the exact output. An expected observation is not automatically a repair.

Outcome boundaries

  1. Observed as expected
  2. Observed something different
  3. Result unclear
  4. Could not complete the check

Then separately record whether the original problem still occurs, was not reproduced once, or has not been retested yet. Every session ends in stop, one repeat of the same check, one named missing fact, or escalation—never an open-ended repair sequence.

Evidence fields for this task

  • Exact crash timeLocal date and time from the most recent crash
  • Trigger or workloadStartup, sleep/wake, game, update, idle, or unknown
  • Recurrence patternOnce, count, frequency, and whether the Stop Code repeats
  • Minidump statusExists/missing and the time shown; do not upload it here

The browser-local Evidence Pack combines the selected context, safe action, actual observation, sources, review date, missing evidence, and stop boundary. It can be copied or printed without creating an account or uploading a log.

Review trail

Official and first-party sources