Collecting user-mode dumps is the most important step in the postmortem debugging. Without properly collected memory dumps, it is almost impossible to figure out the culprit if the issue comes from the field. By configuring the default postmortem debugger, such as drwtsn32, adplus, or windbg, Windows allows the user to collect the memory dumps when applications or services crash. Starting with Windows Server 2008 and Windows Vista with Service Pack 1 (SP1), Windows allows the user to collect the user-mode dumps by configuring
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps key.