ntoseye
View on GitHubWinDbg-like kernel debugger for Windows, from Linux and macOS
WinDbg-style Windows kernel and user-mode debugger that runs on Linux and macOS via KDNET, KVM/QEMU, VMware, UTM or offline crash dumps. Ships a Python SDK, DAP editor integration, and an MCP server, but it is a debugging/reverse-engineering tool, not an AI product.
Use Cases
Debug a Windows kernel inside a VM from Linux or macOSAnalyze Windows crash dumps offlineDevelop and debug Windows drivers with host-served imagesReverse engineer or triage malware in a Windows guestSource-level debugging in VS Code/Emacs/nvim over DAPDrive debugger sessions from an LLM agent via the MCP serverAutomate debugger tasks with the Python SDK
Built With
- Language
- Rust
- Frameworks
- rmcp · tokio · axum · pyo3 · serde · schemars · DAP · MCP · iced-x86 · pdb2
Tags
windbg · kernel-debugger · windows · reverse-engineering · malware-analysis · mcp · dap · kvm · qemu · vmware · utm · kdnet · crash-dump-analysis · pdb-symbols · hypervisor · rust