Skip to content

Repository files navigation

ntoseye

logo

license release crates.io docs.rs

A WinDbg-like Windows debugger for Linux and macOS, with support for kernel-mode and user-mode debugging of virtual and physical machines, and offline crash-dump analysis.

Showcase

Debugging via REPL Debugging via VSCode + DAP
repl vscode

Features

Supported Windows

ntoseye supports 64-bit AMD64 and ARM64 Windows 10 and 11 targets.

Supported hypervisors

ntoseye supports any target that Windows can debug over KDNET. KVM/QEMU, VMware Workstation, and UTM guests additionally get KDCOM, GDB, and memory-only backends.

Files and network access

ntoseye downloads symbols and images from Microsoft's official symbol server when required. Config, cache, and REPL state live under ~/.ntoseye:

  • ~/.ntoseye/commands/ for custom scripted commands
  • ~/.ntoseye/symbols/ for PDBs and images, a symbol store in the symstore layout that WinDbg, IDA, Ghidra, and rizin read
  • ~/.ntoseye/aliases for command aliases
  • ~/.ntoseye/history for persistent REPL history
  • ~/.ntoseye/sites/ for breakpoint instructions a session has planted that the target would not take out itself (user-mode sites, and kernel sites over the gdb backend), restored by the next attach if that session dies

Getting started

Install

ntoseye runs on Linux (x86-64, ARM64) and macOS on Apple Silicon. Every method below installs the same debugger; they differ in whether it embeds Python, which custom commands need, and in what they need installed first:

Method Custom commands Needs
Shell script no nothing
uv or pipx yes Python 3.9 or newer
cargo yes Rust, and Python 3.9 or newer with its development files (python3-dev on Debian and Ubuntu)
pip, for the Python SDK yes Python 3.9 or newer

Shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/dmaivel/ntoseye/releases/latest/download/ntoseye-installer.sh | sh

Installs a prebuilt binary to ~/.local/bin.

uv or pipx

uv tool install ntoseye    # or: pipx install ntoseye

Installs the ntoseye command in its own environment.

cargo

cargo install ntoseye

Builds the release from crates.io, linked against your Python.

Python SDK

To drive the debugger from your own Python code, install the same package into your project's environment:

pip install ntoseye

This also puts the ntoseye command in that environment. See the Python SDK documentation.

Building from source

git clone https://github.com/dmaivel/ntoseye.git
cd ntoseye
cargo build --release

Like cargo install, a default build embeds Python and needs its development files. To build without it:

cargo build --release --no-default-features --features cli,mcp,dap,gdbserver

To build the documentation site, whose command and SDK references are generated from the source (this runs cargo):

pip install -r docs/requirements.txt
sphinx-build -b dirhtml -n -W docs docs/_build/html

For a live preview that rebuilds as you edit, pip install sphinx-autobuild and run sphinx-autobuild -b dirhtml docs docs/_build/html (served at http://127.0.0.1:8000).

Usage

Quickstart

If you are using QEMU/KVM, VMware, or UTM, you can use ntoseye configure for easy setup. Otherwise, look at KDNET instructions.

  1. Power off the Windows VM.
  2. Run ntoseye configure and select the hypervisor, virtual machine, and debugger backend. Note the Run command it prints.
  3. Start the VM, run the printed guest setup commands in Administrator PowerShell, and reboot.
  4. Run the command saved in step 2.

Run ntoseye status at any time to inspect configured transports, assigned guest ports, endpoints, and launch commands without changing a VM.

Hypervisor setup

ntoseye configure handles automatic setup for supported libvirt, VMware Workstation, and UTM guests. For plain QEMU or manual configuration, see the KVM/QEMU, VMware, and UTM setup guides.

For any other target, follow the KDNET guide instead; configure is not needed.

Not sure which backend to use?

See the backend comparison table.

Documentation

The full documentation is at ntoseye.com. The debugger also documents itself: run ntoseye --help for command-line arguments, press tab in the REPL for completions and descriptions of commands, symbols, and types, and run .hh <command> for a command's full help. The site's command reference is built from that same help.

Credits

Functionality regarding initialization of guest information was written with the help of the following sources:

Releases

Sponsor this project

Packages

Contributors

Languages