Windows diagnostics

WinSleuth

Finds out why Windows crashed, and shows its reasoning.

WinSleuth diagnoses Windows instability: blue screens, freezes, hardware errors and driver conflicts. It gathers the evidence Windows already has, correlates it and explains what it thinks is wrong, with the reasoning attached so you can disagree. A finding it cannot support, it does not make.

  • Rust
  • Windows 10/11
  • Crash dump parsing
  • Desktop UI
  • HTML / JSON reports
License: Apache-2.0 or MIT
PowerShell
# Scan, raising a UAC prompt for full evidence
winsleuth scan --elevate

# A shareable report
winsleuth scan --format html --output report.html

# Watch for crashes as they happen
winsleuth monitor --webhook "https://..."

What it does

01

Names the driver that crashed you

Parses crash dumps directly, with no WinDbg or symbol setup, and resolves the faulting instruction even after a reboot or driver removal.

02

Finds known-vulnerable drivers

Hashes every loaded kernel driver against a curated list and the loldrivers.io corpus, and reports whether Memory Integrity is really on.

03

Says when it broke

Finds the point where your crash rate changed and lists the updates, installs and driver packages around it.

04

Verifies signatures properly

Recognises catalog-signed drivers, and does not mistake WHQL-attested vendor drivers for Windows components.

05

Ranks by confidence

Merges findings with the same root cause: WHEA errors, a 0x124 stop code and old firmware become one hardware verdict.

06

Honest about blind spots

An unelevated scan reports which evidence it could not see instead of declaring the machine healthy.

How it's built

Providers collect, the core correlates, rules emit findings:

  1. Providers

    Collect raw state concurrently behind traits: drivers, events, dumps, devices and changes.

  2. Core

    Normalises, correlates, scores and persists the evidence.

  3. Analysis

    Heuristics, stop-code decoding and changepoint search.

  4. Output

    Console, HTML, JSON, a desktop window and redacted evidence bundles for support desks.

Engineering highlights

  • The most important test asserts that a healthy machine produces no findings at all.
  • Tested against fixture machines: healthy, failing disk, hardware fault, driver fault, regression and vulnerable driver.
  • "verify --suspects" arms Driver Verifier only against implicated drivers, prints the recovery procedure and asks first.
  • Only one command touches the network: fetching the vulnerable-driver list.

Quick start

Terminal
git clone https://github.com/esgaltur/WinSleuth.git
cd WinSleuth
cargo build --release
.\target\release\winsleuth.exe scan --elevate

The full documentation is in the repository on GitHub.

More projects