Generic EvidenceEvent boundary
Provider evidence enters a bounded chronological model with timestamp, source, kind, severity, summary and details. Nearby events are context unless stronger evidence supports a causal claim.
03 · Windows diagnostics · 1.3 in development · 1.2 released
A local-first Windows crash-diagnostics system built to answer a practical question: what happened around the moment my game, GPU driver, AI workload, application or PC failed?
The problem
I started CrashScope after repeatedly dealing with game, GPU and workload failures where Windows had useful evidence, but it was scattered across hardware state, application events, Windows Error Reporting and reboot history.
The useful question is rarely “did something crash?” It is “what changed around the incident, what evidence did Windows record, and which conclusions are actually supported?” CrashScope preserves sessions, incidents and nearby evidence without turning correlation into a fake root-cause claim.
The product is aimed at gamers, PC enthusiasts, hardware testers and local-AI users who want useful diagnostics without another heavyweight monitoring workload or a cloud account in the failure path.
CrashScope 1.1 → 1.2
Version 1.1 added the generic provider boundary and ConfigTrace 1.0.1. Version 1.2 keeps the lightweight Agent architecture and adds a native WPF/WebView2 desktop shell that exists only while the UI is open.
Provider evidence enters a bounded chronological model with timestamp, source, kind, severity, summary and details. Nearby events are context unless stronger evidence supports a causal claim.
The Rust sidecar is off by default, starts only while a selected workload is monitored, and remains process-isolated so provider failure cannot take CrashScope down.
CrashScope integration uncovered and validated the ConfigTrace 1.0.1 sensitive-key fix for camelCase and PascalCase fields such as apiToken, clientSecret and sessionId.
CrashScope 1.2 adds a WPF/WebView2 desktop application with true single-instance activation, native dark title-bar behavior and browser fallback while the Agent remains authoritative.
Architecture
CrashScope is a modular monolith with explicit boundaries between domain logic, Windows/hardware adapters, runtime orchestration, persistence, the local dashboard and optional external evidence providers.
The dashboard and native Desktop shell consume telemetry already produced by the central Agent. Closing the shell unloads WebView2 while the Agent can continue running; ConfigTrace remains workload-scoped and optional.
Evidence philosophy
A single high metric near a failure is not enough to prove root cause.
Preserve the observed hardware state and nearby Windows evidence, then keep the conclusion proportional to what the evidence supports.
A configuration change occurring before an incident is useful temporal evidence, not automatic causation.
CrashScope can say “Renderer changed 31.8 seconds before this incident.” It does not automatically say the change caused the incident.
Event Log and WER records can be strong evidence without being a complete explanation.
Windows evidence is correlated with session, workload and machine context before stronger language is used.
Release validation
CrashScope 1.2 closes at 266/266 automated .NET tests. The CPU and memory figures below are the final integrated 1.1 Agent/ConfigTrace measurements; they are retained as measured evidence rather than relabeled as fresh 1.2 performance data.
Primary validation passed on Ryzen 5 7500F + Radeon RX 9070 XT. Genuine second-PC automated and manual visual validation also passed on Windows 10 with Intel Core i5-3210M + Intel HD Graphics 4000. NVIDIA GPU hardware remains an unvalidated path and is not presented as tested.
Privacy + security
The API and dashboard are localhost-only rather than exposed as a remote service.
LOCALHOSTNo analytics or automatic diagnostic upload is required for normal runtime use.
LOCAL-FIRSTFinal provider-journal validation passed and the plaintext test secret was not found in the journal or CrashScope incident output.
REDACTEDConfigTrace runs as a separate process and its lifecycle is bounded to the monitored workload.
ISOLATEDRelease engineering
CrashScope 1.2.0 was built and validated locally, then published through a privacy-safe public runtime commit whose Git tree exactly matches the frozen private runtime boundary.
Validated private runtime: 3a6a3ffd9ad40943e7e5fc8be4d8faf0fc7b9912. Public v1.2.0 runtime: 8ce9c25dc40f6481bf7b782d3dae67deeb3e6cef. Shared Git tree: b23d4e4e8f79598362d8d9cc9d1a405e989ee3c6.
CrashScope-v1.2.0-win-x64.zip
SHA-256: 5cd5821800b2e5f2c4ace319a6921267414465129c704b8e50c83b1a1a932b04
CrashScope-Setup-1.2.0.exe
SHA-256: a37c012293a1c5e5aa94c823f1898a85ef0bc896b5b3cf03d870e8191050a12e
266/266 automated .NET tests passed. Installed production-preview validation also passed upgrade preservation, native-shell launch/single-instance behavior, shortcut behavior and uninstall data preservation.
Bundled ConfigTrace 1.0.1 executable SHA-256: fe1c470a58402e82e97ee529c6a6b02822430da70e65ffc5fc5a71359ad4e521.
The full engineering history remains private; public release commits preserve the exact validated Git trees while using privacy-safe public commit metadata.
CrashScope 1.3 · in development
CrashScope 1.3 is the current development line. The public 1.2.0 release remains the validated downloadable build; this page uses the current development UI as the visual state without presenting 1.3 as a released artifact.