Determine the cause of the replacement-collector kernel crash

Determine whether the replacement-collector compatibility preflight, Counter-Strike 2, PowerShell, NTFS, or an earlier optimization caused the Windows bugcheck 0x1E and associated kernel-mode failure during the measurement preflight.

Background

During a replacement-collector compatibility preflight, Windows restarted following bugcheck 0x1E. The preserved mini-kernel dump indicated a kernel-mode exception with powershell.exe as the process name and an instruction pointer of zero, while Windows Error Reporting separately identified an NTFS index-entry routine.

The paper cautions that temporal ordering alone does not establish causation and reports that no controlled reproduction was attempted after the high-severity event. The conclusion therefore treats the crash cause as unresolved rather than attributing it to a particular collector or system component.

References

The failures are already actionable results. An imprecise registry action damaged a broader startup container than intended; PresentMon-family measurement was incompatible with the target environment; and a later capture preflight was temporally associated with a kernel crash whose cause remains unknown.

Spike-Killer: Evidence-Gated LLM Assistance for Safe Performance Diagnosis on a Real Windows Workstation  (2608.21069 - Zeng et al., 21 Aug 2026) in Section 6.3, “Bugcheck During a Replacement-Collector Preflight”; reiterated in the Conclusion