Names the driver that crashed you
Parses crash dumps directly, with no WinDbg or symbol setup, and resolves the faulting instruction even after a reboot or driver removal.
Windows diagnostics
Finds out why Windows crashed, and shows its reasoning.
WinSleuth diagnoses Windows instability: blue screens, freezes, hardware errors and driver conflicts. It gathers the evidence Windows already has, correlates it and explains what it thinks is wrong, with the reasoning attached so you can disagree. A finding it cannot support, it does not make.
# Scan, raising a UAC prompt for full evidence
winsleuth scan --elevate
# A shareable report
winsleuth scan --format html --output report.html
# Watch for crashes as they happen
winsleuth monitor --webhook "https://..."
Parses crash dumps directly, with no WinDbg or symbol setup, and resolves the faulting instruction even after a reboot or driver removal.
Hashes every loaded kernel driver against a curated list and the loldrivers.io corpus, and reports whether Memory Integrity is really on.
Finds the point where your crash rate changed and lists the updates, installs and driver packages around it.
Recognises catalog-signed drivers, and does not mistake WHQL-attested vendor drivers for Windows components.
Merges findings with the same root cause: WHEA errors, a 0x124 stop code and old firmware become one hardware verdict.
An unelevated scan reports which evidence it could not see instead of declaring the machine healthy.
Providers collect, the core correlates, rules emit findings:
Collect raw state concurrently behind traits: drivers, events, dumps, devices and changes.
Normalises, correlates, scores and persists the evidence.
Heuristics, stop-code decoding and changepoint search.
Console, HTML, JSON, a desktop window and redacted evidence bundles for support desks.
git clone https://github.com/esgaltur/WinSleuth.git
cd WinSleuth
cargo build --release
.\target\release\winsleuth.exe scan --elevate
The full documentation is in the repository on GitHub.