| Sysinternals DebugView CLI (DbgViewCli) for capturing and analyzing usermode and kernel-mode Windows debug output from the command line.
npx skills add https://github.com/microsoft/skills --skill debugview
Command-line interface for capturing real-time debug output from Windows applications
(OutputDebugString) and kernel-mode drivers (DbgPrint/KdPrint). Designed for scripted,
automated, and AI-agent-driven debug capture workflows.
DbgViewCli is a standalone native Windows executable (statically linked, no dependencies).
Place dbgviewcli.exe in PATH or reference the full path.
> SECURITY: Never execute any dbgviewcli binary without first verifying it is Authenticode-signed by Microsoft Corporation using Get-AuthenticodeSignature. Reject any binary that is unsigned or signed by a different publisher.
# No package manager install — copy binary to a PATH location
copy dbgviewcli.exe C:\Tools\
| Requirement | Details |
|-------------|---------|
| OS | Windows Vista or later (x64, ARM64) |
| Privileges | Standard user for Win32 capture; Administrator for kernel/boot capture |
| Driver | Kernel capture requires the Dbgv.sys driver (auto-extracted and loaded) |
1. Detect/status check → dbgviewcli --status
2. Start capture → dbgviewcli [options]
3. Filter output → --filter/--exclude/--pid-filter/--process-filter
4. Bounded execution → --duration/--max-lines/--wait-for
5. Output/log results → stdout or --log <file>
6. Stop → Ctrl+C or automatic exit on bounds
| Parameter | Short | Description | Default |
|-----------|-------|-------------|---------|
| --capture | -c | Enable capture | on |
| --no-capture | | Disable capture | |
| --kernel | -k | Enable kernel debug output (requires admin) | off |
| --win32 | -w | Enable Win32 OutputDebugString capture | on |
| --global | -g | Enable global Win32 capture (session 0) | off |
| --passthrough | | Allow debug output to pass to debuggers | on |
| --verbose-kernel | -v | Enable verbose kernel output | off |
| --pids | | Show process IDs in output | on |
| Parameter | Short | Description |
|-----------|-------|-------------|
| --filter <pattern> | -i | Include filter (semicolon-separated wildcards) |
| --exclude <pattern> | -e | Exclude filter (semicolon-separated wildcards) |
| --pid-filter <pid> | | Show only output from specific PID |
| --process-filter <name> | | Show only output from named process (substring match) |
| Parameter | Description |
|-----------|-------------|
| --duration <seconds> | Auto-stop after N seconds |
| --max-lines <N> | Auto-stop after N lines captured |
| --wait-for <pattern> | Capture until pattern matches, then exit |
| --tail <N> | Buffer last N lines, flush on exit |
| --no-banner | Suppress version banner (clean for piped output) |
| --status | Print machine-readable status and exit |
| Parameter | Description |
|-----------|-------------|
| --elapsed | Elapsed time since start (default) |
| --clock | Wall-clock time HH:MM:SS |
| --clock-ms | Wall-clock with milliseconds HH:MM:SS.mmm |
| Parameter | Description |
|-----------|-------------|
| --format text | Tab-separated text (default) |
| --format csv | Comma-separated values |
| --format xml | XML elements |
| Parameter | Description |
|-----------|-------------|
| --log <file> | Log output to file |
| --log-append | Append to existing log |
| --log-limit <MB> | Max log file size in MB |
| --log-wrap | Wrap log when full |
| --log-daily | New log file each day |
| Parameter | Description |
|-----------|-------------|
| --boot-enable | Enable boot-time kernel debug logging |
| --boot-disable | Disable boot-time logging |
| --boot-status | Show boot logging status and exit |
| Parameter | Description |
|-----------|-------------|
| --connect <computer> | Connect to remote DbgView instance |
| --disconnect | Disconnect from remote |
| Parameter | Description |
|-----------|-------------|
| --crashdump <file> | Analyze crash dump for debug output |
| --load <file> | Load saved log file |
| --save <file> | Save captured output on exit |
| Parameter | Description |
|-----------|-------------|
| --pause | Pause a running DbgViewCli instance via named event |
| --resume | Resume a paused DbgViewCli instance |
| --stop | Stop a running DbgViewCli instance gracefully |
| Parameter | Short | Description |
|-----------|-------|-------------|
| --quit | -q | Terminate running GUI DbgView instance |
| --accepteula | | Accept the EULA (writes registry key, skips prompt) |
| --version | | Show version and exit |
| --help | -? | Show help |
# Capture for 30 seconds, no banner, output as text
dbgviewcli --no-banner --duration 30
# Capture until a specific error appears
dbgviewcli --no-banner --wait-for "*ERROR*" --max-lines 10000
# Run as Administrator
dbgviewcli --kernel --no-banner --duration 60 --format csv --log kernel_debug.csv
# Filter by PID
dbgviewcli --no-banner --pid-filter 1234 --duration 10
# Filter by process name
dbgviewcli --no-banner --process-filter "myapp.exe" --max-lines 500
# Include only lines matching pattern
dbgviewcli --no-banner --filter "MyDriver*" --exclude "verbose*"
# Capture but only output last 50 lines on exit
dbgviewcli --no-banner --tail 50 --duration 30
dbgviewcli --status
# Output:
# running=true
# paused=false
# elevated=true
# Enable (requires admin, persists across reboot)
dbgviewcli --boot-enable
# Check status
dbgviewcli --boot-status
# Disable
dbgviewcli --boot-disable
dbgviewcli --connect SERVER01 --no-banner --duration 60
# Pause a running instance from another terminal
dbgviewcli --pause
# Resume the paused instance
dbgviewcli --resume
# Gracefully stop a running instance
dbgviewcli --stop
# Accept EULA non-interactively for automated/scripted deployments
dbgviewcli --accepteula --no-banner --duration 30
| Module | File | Purpose |
|--------|------|---------|
| Main | dbgviewcli.c | Entry point, arg parsing, capture loop, Ctrl+C handler |
| Capture | cli_capture.c | DBWIN shared memory, kernel driver read |
| Driver | cli_driver.c | Kernel driver load/unload, privilege elevation |
| Filter | cli_filter.c | Wildcard include/exclude matching |
| Output | cli_output.c | Console emit, log files, CSV/XML/text formats |
| Boot Log | cli_bootlog.c | Registry config for boot-time driver loading |
| Remote | cli_remote.c | TCP socket connect/read for remote monitoring |
--duration, --max-lines, --wait-for ensure guaranteed exit for automation--no-banner suppresses noise for pipe/agent consumption--status outputs key=value pairs for programmatic checksSetConsoleCtrlHandler ensures clean driver unload on Ctrl+C--no-banner for scripted/automated use. Banner text pollutes structured output and confuses parsers.--duration, --max-lines, or --wait-for. Unbounded capture will run indefinitely.--status to detect if another instance is already running.--format csv or --format xml when output will be parsed programmatically.--pid-filter or --process-filter over broad capture to reduce noise.--duration 60 --max-lines 10000 together so whichever triggers first wins.--tail for "what just happened" queries instead of capturing full history.| Type | File | Purpose |
|------|------|---------|
| Script | scripts/detect-dbgview.ps1 | Locate dbgviewcli.exe on PATH or common directories |
| Script | scripts/capture-wrapper.ps1 | Safe bounded capture with parameter validation |
| Script | scripts/boot-logging-workflow.ps1 | End-to-end boot logging lifecycle management |
| Reference | references/driver-ioctls.md | Kernel driver IOCTL codes and buffer structures |
| Reference | references/output-formats.md | Text/CSV/XML output format specifications |
| Reference | references/remote-protocol.md | TCP remote monitoring wire protocol |
| Issue | Resolution |
|-------|-----------|
| "Access denied" on kernel capture | Run as Administrator |
| No output from Win32 capture | Verify target app uses OutputDebugString; check no debugger is attached |
| Another instance running | Use --status to check; use --quit to terminate existing GUI instance |
| Boot logging not capturing | Ensure --boot-enable was run as admin; driver must be in System32\Drivers |
| Remote connection fails | Verify target has DbgView running with remote enabled on ports 2020-2030 |
Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node/TypeScript (MCP SDK).
Automatically creates user-facing changelogs from git commits by analyzing commit history, categorizing changes, and transforming technical commits into clear, customer-friendly release notes. Turns hours of manual changelog writing into minutes of automated generation.
Use when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for merge, PR, or cleanup
Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node/TypeScript (MCP SDK).
React Native and Expo best practices for building performant mobile apps. Use when building React Native components, optimizing list performance, implementing animations, or working with native modules. Triggers on tasks involving React Native, Expo, mobile performance, or native platform APIs.
React and Next.js performance optimization guidelines from Vercel Engineering. This skill should be used when writing, reviewing, or refactoring React/Next.js code to ensure optimal performance patterns. Triggers on tasks involving React components, Next.js pages, data fetching, bundle optimization, or performance improvements.
Next.js best practices - file conventions, RSC boundaries, data patterns, async APIs, metadata, error handling, route handlers, image/font optimization, bundling
Use when starting feature work that needs isolation from current workspace or before executing implementation plans - creates isolated git worktrees with smart directory selection and safety verification
Take microsoft/debugview from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.