An intermittent blue-screen report becomes easier to investigate when Windows saves a usable memory dump, stop code and time. A dump can be absent if storage is full, the page file is unsuitable or settings were changed by a so-called optimizer. Microsoft's guidance describes automatic, kernel and complete dump options and their disk requirements. Prepare collection before the next crash, then share only with a trusted support channel because dumps can contain sensitive fragments of memory.
Before you start
Back up important data and record the stop code, recent driver or update changes and exact crash time. Check system-drive free space and whether the page file is system managed. Decide who will receive the evidence; a public upload of a memory dump may reveal document text, secrets or browsing data. If hardware is unstable, do not deliberately induce a crash.Do it step by step
- Open Advanced system settings > Startup and Recovery > Settings. Record the current Write debugging information selection and dump file path.
- Choose Automatic memory dump as a practical default unless a qualified support engineer requests another type. Verify the system-managed page file and adequate free space.
- After a natural repeat crash, note the stop code and restart time. Do not repeatedly force power cycles merely to generate data.
- Check whether Windows wrote a dump at the configured path and whether its timestamp matches the incident. Look at Event Viewer for related system errors without assuming the first red event is the cause.
- Keep the dump securely. Send it only to the PC maker, Microsoft or a trusted professional through their approved private channel, along with model, build, stop code and repro steps.
- Apply one supported driver or firmware change at a time and watch whether the crash recurs. Retain the original dump until the root cause and stable fix are established.