Debugview

作者 microsoft354361d83247無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Sysinternals DebugView CLI (DbgViewCli) for capturing and analyzing usermode and kernel-mode Windows debug output from the command line. USE FOR: capturing OutputDebugString output, kernel DbgPrint/KdPrint capture, boot-time debug logging, remote debug monitoring, filtering debug output by PID or process name, crash dump analysis, automated debug capture with bounded execution. DO NOT USE FOR: non-Windows platforms, application-level logging frameworks (log4j, serilog), Azure Monitor or cloud telemetry, ETW tracing (use WPR/xperf instead), user-mode crash dumps (use WinDbg). Triggers: "debug output", "DbgView", "DebugView", "kernel debug", "capture debug logs", "boot logging", "OutputDebugString", "DbgPrint", "KdPrint", "remote debug monitor", "debug capture CLI".

精選包含腳本Software Development
AI 產生的概覽

使用 Sysinternals DebugView CLI 從命令列擷取並分析 Windows 使用者模式與核心模式偵錯輸出。

功能
此技能封裝 Sysinternals DebugView CLI(dbgviewcli.exe),用於即時擷取來自 OutputDebugString 以及核心 DbgPrint/KdPrint 的 Windows 偵錯輸出。它支援包含/排除篩選、依 PID 或處理程序名稱篩選,可透過時長、行數或等待模式限定執行範圍,並支援文字/CSV/XML 輸出、記錄檔、開機時記錄、遠端監控、當機傾印分析以及執行階段暫停/繼續/停止控制。技能附帶用於偵測、限時擷取和開機記錄的 PowerShell 指令碼,以及關於驅動程式 IOCTL、輸出格式和遠端通訊協定的參考文件。
適用情境
適用於指令碼化或由代理程式驅動的 Windows 偵錯擷取,例如收集 OutputDebugString 輸出、核心偵錯記錄、開機時記錄或遠端偵錯監控。不適用於非 Windows 平台、應用程式記錄架構、雲端遙測、ETW 追蹤或使用者模式當機傾印。
執行需求
需要 Windows Vista 或更新版本(x64 或 ARM64),並將獨立的 dbgviewcli.exe 放在 PATH 中或透過完整路徑引用;核心與開機擷取需要系統管理員權限,並且需要 Dbgv.sys 驅動程式。技能附帶 PowerShell 指令碼和參考文件,遠端監控使用 TCP 連接埠 2020-2030。

Sysinternals DebugView CLI (DbgViewCli)

Command-line interface for capturing real-time debug output from Windows applications (OutputDebugString) and kernel-mode drivers (DbgPrint/KdPrint). Designed for scripted, automated, and AI-agent-driven debug capture workflows.

Installation

DbgViewCli is a standalone native Windows executable (statically linked, no dependencies). Place dbgviewcli.exe in PATH or reference the full path.

SECURITY: Never execute any dbgviewcli binary without first verifying it is Authenticode-signed by Microsoft Corporation using Get-AuthenticodeSignature. Reject any binary that is unsigned or signed by a different publisher.

bash
# No package manager install — copy binary to a PATH locationcopy dbgviewcli.exe C:\Tools\

Requirements

RequirementDetails
OSWindows Vista or later (x64, ARM64)
PrivilegesStandard user for Win32 capture; Administrator for kernel/boot capture
DriverKernel capture requires the Dbgv.sys driver (auto-extracted and loaded)

Core Workflow

1. Detect/status check   →  dbgviewcli --status2. Start capture          →  dbgviewcli [options]3. Filter output          →  --filter/--exclude/--pid-filter/--process-filter4. Bounded execution      →  --duration/--max-lines/--wait-for5. Output/log results     →  stdout or --log <file>6. Stop                   →  Ctrl+C or automatic exit on bounds

Command-Line Parameters

Capture Control

ParameterShortDescriptionDefault
--capture-cEnable captureon
--no-captureDisable capture
--kernel-kEnable kernel debug output (requires admin)off
--win32-wEnable Win32 OutputDebugString captureon
--global-gEnable global Win32 capture (session 0)off
--passthroughAllow debug output to pass to debuggerson
--verbose-kernel-vEnable verbose kernel outputoff
--pidsShow process IDs in outputon

Filtering

ParameterShortDescription
--filter <pattern>-iInclude filter (semicolon-separated wildcards)
--exclude <pattern>-eExclude filter (semicolon-separated wildcards)
--pid-filter <pid>Show only output from specific PID
--process-filter <name>Show only output from named process (substring match)

Bounded Execution (AI-Agent Friendly)

ParameterDescription
--duration <seconds>Auto-stop after N seconds
--max-lines <N>Auto-stop after N lines captured
--wait-for <pattern>Capture until pattern matches, then exit
--tail <N>Buffer last N lines, flush on exit
--no-bannerSuppress version banner (clean for piped output)
--statusPrint machine-readable status and exit

Time Display

ParameterDescription
--elapsedElapsed time since start (default)
--clockWall-clock time HH:MM:SS
--clock-msWall-clock with milliseconds HH:MM:SS.mmm

Output Format

ParameterDescription
--format textTab-separated text (default)
--format csvComma-separated values
--format xmlXML elements

Logging

ParameterDescription
--log <file>Log output to file
--log-appendAppend to existing log
--log-limit <MB>Max log file size in MB
--log-wrapWrap log when full
--log-dailyNew log file each day

Boot Logging (Requires Admin)

ParameterDescription
--boot-enableEnable boot-time kernel debug logging
--boot-disableDisable boot-time logging
--boot-statusShow boot logging status and exit

Remote Monitoring

ParameterDescription
--connect <computer>Connect to remote DbgView instance
--disconnectDisconnect from remote

Crash Dump & File Operations

ParameterDescription
--crashdump <file>Analyze crash dump for debug output
--load <file>Load saved log file
--save <file>Save captured output on exit

Runtime Control (Inter-Process)

ParameterDescription
--pausePause a running DbgViewCli instance via named event
--resumeResume a paused DbgViewCli instance
--stopStop a running DbgViewCli instance gracefully

Miscellaneous

ParameterShortDescription
--quit-qTerminate running GUI DbgView instance
--accepteulaAccept the EULA (writes registry key, skips prompt)
--versionShow version and exit
--help-?Show help

Usage Examples

Basic Win32 Capture (bounded)

bash
# Capture for 30 seconds, no banner, output as textdbgviewcli --no-banner --duration 30
# Capture until a specific error appearsdbgviewcli --no-banner --wait-for "*ERROR*" --max-lines 10000

Kernel Debug Capture (requires admin)

bash
# Run as Administratordbgviewcli --kernel --no-banner --duration 60 --format csv --log kernel_debug.csv

Process-Specific Filtering

bash
# Filter by PIDdbgviewcli --no-banner --pid-filter 1234 --duration 10
# Filter by process namedbgviewcli --no-banner --process-filter "myapp.exe" --max-lines 500

Pattern-Based Filtering

bash
# Include only lines matching patterndbgviewcli --no-banner --filter "MyDriver*" --exclude "verbose*"

Tail Mode (recent context)

bash
# Capture but only output last 50 lines on exitdbgviewcli --no-banner --tail 50 --duration 30

Status Check (machine-readable)

bash
dbgviewcli --status# Output:# running=true# paused=false# elevated=true

Boot Logging

bash
# Enable (requires admin, persists across reboot)dbgviewcli --boot-enable
# Check statusdbgviewcli --boot-status
# Disabledbgviewcli --boot-disable

Remote Monitoring

bash
dbgviewcli --connect SERVER01 --no-banner --duration 60

Runtime Control (Pause/Resume/Stop)

bash
# Pause a running instance from another terminaldbgviewcli --pause
# Resume the paused instancedbgviewcli --resume
# Gracefully stop a running instancedbgviewcli --stop

EULA Acceptance (Unattended)

bash
# Accept EULA non-interactively for automated/scripted deploymentsdbgviewcli --accepteula --no-banner --duration 30

Architecture

ModuleFilePurpose
Maindbgviewcli.cEntry point, arg parsing, capture loop, Ctrl+C handler
Capturecli_capture.cDBWIN shared memory, kernel driver read
Drivercli_driver.cKernel driver load/unload, privilege elevation
Filtercli_filter.cWildcard include/exclude matching
Outputcli_output.cConsole emit, log files, CSV/XML/text formats
Boot Logcli_bootlog.cRegistry config for boot-time driver loading
Remotecli_remote.cTCP socket connect/read for remote monitoring

Key Design Decisions

  1. Static CRT linking — No DLL dependencies, runs on any Windows system
  2. stdout/stderr separation — Debug output → stdout; errors/status → stderr
  3. Bounded execution — --duration, --max-lines, --wait-for ensure guaranteed exit for automation
  4. Clean output — --no-banner suppresses noise for pipe/agent consumption
  5. Machine-readable status — --status outputs key=value pairs for programmatic checks
  6. Graceful shutdown — SetConsoleCtrlHandler ensures clean driver unload on Ctrl+C

Best Practices

  1. Always use --no-banner for scripted/automated use. Banner text pollutes structured output and confuses parsers.
  2. Always bound execution with --duration, --max-lines, or --wait-for. Unbounded capture will run indefinitely.
  3. Check status before capture — Use --status to detect if another instance is already running.
  4. Use --format csv or --format xml when output will be parsed programmatically.
  5. Prefer --pid-filter or --process-filter over broad capture to reduce noise.
  6. Run as Administrator only when needed — kernel and boot logging require elevation; Win32 capture does not.
  7. Combine bounds for safety — Use --duration 60 --max-lines 10000 together so whichever triggers first wins.
  8. Use --tail for "what just happened" queries instead of capturing full history.

Bundled Resources

TypeFilePurpose
Scriptscripts/detect-dbgview.ps1Locate dbgviewcli.exe on PATH or common directories
Scriptscripts/capture-wrapper.ps1Safe bounded capture with parameter validation
Scriptscripts/boot-logging-workflow.ps1End-to-end boot logging lifecycle management
Referencereferences/driver-ioctls.mdKernel driver IOCTL codes and buffer structures
Referencereferences/output-formats.mdText/CSV/XML output format specifications
Referencereferences/remote-protocol.mdTCP remote monitoring wire protocol

Troubleshooting

IssueResolution
"Access denied" on kernel captureRun as Administrator
No output from Win32 captureVerify target app uses OutputDebugString; check no debugger is attached
Another instance runningUse --status to check; use --quit to terminate existing GUI instance
Boot logging not capturingEnsure --boot-enable was run as admin; driver must be in System32\Drivers
Remote connection failsVerify target has DbgView running with remote enabled on ports 2020-2030

來源與署名

來源:microsoft/skills位於.github/skills/debugview提交354361d

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架