Debugview

作者 microsoft354361d83247无许可证收录于 2026年10月8日更新于 2026年10月8日

Sysinternals DebugView CLI (DbgViewCli) for capturing and analyzing usermode and kernel-mode Windows debug output from the command line. USE FOR: capturing OutputDebugString output, kernel DbgPrint/KdPrint capture, boot-time debug logging, remote debug monitoring, filtering debug output by PID or process name, crash dump analysis, automated debug capture with bounded execution. DO NOT USE FOR: non-Windows platforms, application-level logging frameworks (log4j, serilog), Azure Monitor or cloud telemetry, ETW tracing (use WPR/xperf instead), user-mode crash dumps (use WinDbg). Triggers: "debug output", "DbgView", "DebugView", "kernel debug", "capture debug logs", "boot logging", "OutputDebugString", "DbgPrint", "KdPrint", "remote debug monitor", "debug capture CLI".

精选包含脚本Software Development
AI 生成的概览

使用 Sysinternals DebugView CLI 从命令行捕获并分析 Windows 用户模式和内核模式调试输出。

功能
该技能封装 Sysinternals DebugView CLI(dbgviewcli.exe),用于实时捕获来自 OutputDebugString 以及内核 DbgPrint/KdPrint 的 Windows 调试输出。它支持包含/排除过滤、按 PID 或进程名过滤,可通过时长、行数或等待模式限定运行范围,并支持文本/CSV/XML 输出、日志文件、启动时日志、远程监控、崩溃转储分析以及运行时暂停/恢复/停止控制。技能附带用于检测、限时捕获和启动日志的 PowerShell 脚本,以及关于驱动 IOCTL、输出格式和远程协议的参考文档。
适用场景
适用于脚本化或由智能体驱动的 Windows 调试捕获,例如收集 OutputDebugString 输出、内核调试日志、启动时日志或远程调试监控。不适用于非 Windows 平台、应用日志框架、云遥测、ETW 跟踪或用户模式崩溃转储。
运行要求
需要 Windows Vista 或更高版本(x64 或 ARM64),并将独立的 dbgviewcli.exe 放在 PATH 中或通过完整路径引用;内核和启动捕获需要管理员权限,并且需要 Dbgv.sys 驱动。技能附带 PowerShell 脚本和参考文档,远程监控使用 TCP 端口 2020-2030。

Sysinternals DebugView CLI (DbgViewCli)

Command-line interface for capturing real-time debug output from Windows applications (OutputDebugString) and kernel-mode drivers (DbgPrint/KdPrint). Designed for scripted, automated, and AI-agent-driven debug capture workflows.

Installation

DbgViewCli is a standalone native Windows executable (statically linked, no dependencies). Place dbgviewcli.exe in PATH or reference the full path.

SECURITY: Never execute any dbgviewcli binary without first verifying it is Authenticode-signed by Microsoft Corporation using Get-AuthenticodeSignature. Reject any binary that is unsigned or signed by a different publisher.

bash
# No package manager install — copy binary to a PATH locationcopy dbgviewcli.exe C:\Tools\

Requirements

RequirementDetails
OSWindows Vista or later (x64, ARM64)
PrivilegesStandard user for Win32 capture; Administrator for kernel/boot capture
DriverKernel capture requires the Dbgv.sys driver (auto-extracted and loaded)

Core Workflow

1. Detect/status check   →  dbgviewcli --status2. Start capture          →  dbgviewcli [options]3. Filter output          →  --filter/--exclude/--pid-filter/--process-filter4. Bounded execution      →  --duration/--max-lines/--wait-for5. Output/log results     →  stdout or --log <file>6. Stop                   →  Ctrl+C or automatic exit on bounds

Command-Line Parameters

Capture Control

ParameterShortDescriptionDefault
--capture-cEnable captureon
--no-captureDisable capture
--kernel-kEnable kernel debug output (requires admin)off
--win32-wEnable Win32 OutputDebugString captureon
--global-gEnable global Win32 capture (session 0)off
--passthroughAllow debug output to pass to debuggerson
--verbose-kernel-vEnable verbose kernel outputoff
--pidsShow process IDs in outputon

Filtering

ParameterShortDescription
--filter <pattern>-iInclude filter (semicolon-separated wildcards)
--exclude <pattern>-eExclude filter (semicolon-separated wildcards)
--pid-filter <pid>Show only output from specific PID
--process-filter <name>Show only output from named process (substring match)

Bounded Execution (AI-Agent Friendly)

ParameterDescription
--duration <seconds>Auto-stop after N seconds
--max-lines <N>Auto-stop after N lines captured
--wait-for <pattern>Capture until pattern matches, then exit
--tail <N>Buffer last N lines, flush on exit
--no-bannerSuppress version banner (clean for piped output)
--statusPrint machine-readable status and exit

Time Display

ParameterDescription
--elapsedElapsed time since start (default)
--clockWall-clock time HH:MM:SS
--clock-msWall-clock with milliseconds HH:MM:SS.mmm

Output Format

ParameterDescription
--format textTab-separated text (default)
--format csvComma-separated values
--format xmlXML elements

Logging

ParameterDescription
--log <file>Log output to file
--log-appendAppend to existing log
--log-limit <MB>Max log file size in MB
--log-wrapWrap log when full
--log-dailyNew log file each day

Boot Logging (Requires Admin)

ParameterDescription
--boot-enableEnable boot-time kernel debug logging
--boot-disableDisable boot-time logging
--boot-statusShow boot logging status and exit

Remote Monitoring

ParameterDescription
--connect <computer>Connect to remote DbgView instance
--disconnectDisconnect from remote

Crash Dump & File Operations

ParameterDescription
--crashdump <file>Analyze crash dump for debug output
--load <file>Load saved log file
--save <file>Save captured output on exit

Runtime Control (Inter-Process)

ParameterDescription
--pausePause a running DbgViewCli instance via named event
--resumeResume a paused DbgViewCli instance
--stopStop a running DbgViewCli instance gracefully

Miscellaneous

ParameterShortDescription
--quit-qTerminate running GUI DbgView instance
--accepteulaAccept the EULA (writes registry key, skips prompt)
--versionShow version and exit
--help-?Show help

Usage Examples

Basic Win32 Capture (bounded)

bash
# Capture for 30 seconds, no banner, output as textdbgviewcli --no-banner --duration 30
# Capture until a specific error appearsdbgviewcli --no-banner --wait-for "*ERROR*" --max-lines 10000

Kernel Debug Capture (requires admin)

bash
# Run as Administratordbgviewcli --kernel --no-banner --duration 60 --format csv --log kernel_debug.csv

Process-Specific Filtering

bash
# Filter by PIDdbgviewcli --no-banner --pid-filter 1234 --duration 10
# Filter by process namedbgviewcli --no-banner --process-filter "myapp.exe" --max-lines 500

Pattern-Based Filtering

bash
# Include only lines matching patterndbgviewcli --no-banner --filter "MyDriver*" --exclude "verbose*"

Tail Mode (recent context)

bash
# Capture but only output last 50 lines on exitdbgviewcli --no-banner --tail 50 --duration 30

Status Check (machine-readable)

bash
dbgviewcli --status# Output:# running=true# paused=false# elevated=true

Boot Logging

bash
# Enable (requires admin, persists across reboot)dbgviewcli --boot-enable
# Check statusdbgviewcli --boot-status
# Disabledbgviewcli --boot-disable

Remote Monitoring

bash
dbgviewcli --connect SERVER01 --no-banner --duration 60

Runtime Control (Pause/Resume/Stop)

bash
# Pause a running instance from another terminaldbgviewcli --pause
# Resume the paused instancedbgviewcli --resume
# Gracefully stop a running instancedbgviewcli --stop

EULA Acceptance (Unattended)

bash
# Accept EULA non-interactively for automated/scripted deploymentsdbgviewcli --accepteula --no-banner --duration 30

Architecture

ModuleFilePurpose
Maindbgviewcli.cEntry point, arg parsing, capture loop, Ctrl+C handler
Capturecli_capture.cDBWIN shared memory, kernel driver read
Drivercli_driver.cKernel driver load/unload, privilege elevation
Filtercli_filter.cWildcard include/exclude matching
Outputcli_output.cConsole emit, log files, CSV/XML/text formats
Boot Logcli_bootlog.cRegistry config for boot-time driver loading
Remotecli_remote.cTCP socket connect/read for remote monitoring

Key Design Decisions

  1. Static CRT linking — No DLL dependencies, runs on any Windows system
  2. stdout/stderr separation — Debug output → stdout; errors/status → stderr
  3. Bounded execution — --duration, --max-lines, --wait-for ensure guaranteed exit for automation
  4. Clean output — --no-banner suppresses noise for pipe/agent consumption
  5. Machine-readable status — --status outputs key=value pairs for programmatic checks
  6. Graceful shutdown — SetConsoleCtrlHandler ensures clean driver unload on Ctrl+C

Best Practices

  1. Always use --no-banner for scripted/automated use. Banner text pollutes structured output and confuses parsers.
  2. Always bound execution with --duration, --max-lines, or --wait-for. Unbounded capture will run indefinitely.
  3. Check status before capture — Use --status to detect if another instance is already running.
  4. Use --format csv or --format xml when output will be parsed programmatically.
  5. Prefer --pid-filter or --process-filter over broad capture to reduce noise.
  6. Run as Administrator only when needed — kernel and boot logging require elevation; Win32 capture does not.
  7. Combine bounds for safety — Use --duration 60 --max-lines 10000 together so whichever triggers first wins.
  8. Use --tail for "what just happened" queries instead of capturing full history.

Bundled Resources

TypeFilePurpose
Scriptscripts/detect-dbgview.ps1Locate dbgviewcli.exe on PATH or common directories
Scriptscripts/capture-wrapper.ps1Safe bounded capture with parameter validation
Scriptscripts/boot-logging-workflow.ps1End-to-end boot logging lifecycle management
Referencereferences/driver-ioctls.mdKernel driver IOCTL codes and buffer structures
Referencereferences/output-formats.mdText/CSV/XML output format specifications
Referencereferences/remote-protocol.mdTCP remote monitoring wire protocol

Troubleshooting

IssueResolution
"Access denied" on kernel captureRun as Administrator
No output from Win32 captureVerify target app uses OutputDebugString; check no debugger is attached
Another instance runningUse --status to check; use --quit to terminate existing GUI instance
Boot logging not capturingEnsure --boot-enable was run as admin; driver must be in System32\Drivers
Remote connection failsVerify target has DbgView running with remote enabled on ports 2020-2030

来源与署名

来源:microsoft/skills位于.github/skills/debugview提交354361d

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架