Contents Menu Expand Light mode Dark mode Auto light/dark, in light mode Auto light/dark, in dark mode Skip to content
ntoseye
Logo
ntoseye

Getting started

  • Install
  • Quickstart
  • Tutorial: a first session
  • Coming from WinDbg
  • Troubleshooting
  • Command line

Setting up a target

  • Choosing a backend
  • KVM/QEMU
  • VMware Workstation
  • UTM (macOS, Apple Silicon)
  • KDNET

Using ntoseye

  • Using the REPL
  • Breakpoints and watchpoints
  • Memory and paging
  • Symbols and source
  • Crash dumps
  • Driver replacement map (.kdfiles)

Platform topics

  • VBS and the Windows hypervisor
  • WOW64 processes

Integrations

  • Editor integration (DAP)
  • Disassembler integration (GDB remote protocol)
  • MCP integration

Scripting

  • Python SDK
  • Custom REPL commands
  • Python API
    • AddressModule
    • Breakpoint
    • BreakpointIterator
    • Breakpoints
    • Cpu
    • CpuIterator
    • Cpus
    • Debugger
    • Device
    • Diagnostic
    • Driver
    • DriverIterator
    • Drivers
    • Exceptions
    • Export
    • Field
    • Frame
    • Heap
    • HeapIterator
    • Heaps
    • Inspect
    • Memory
    • MemoryRegion
    • MemoryRegionIterator
    • MemorySearchMatch
    • Module
    • ModuleIterator
    • Modules
    • Msrs
    • NameIterator
    • Process
    • Processes
    • ProcessIterator
    • Record
    • RecordIterator
    • Regions
    • Registers
    • Section
    • SecureKernel
    • Stop
    • Struct
    • Symbol
    • Symbols
    • Thread
    • ThreadIterator
    • Threads
    • Trustlet
    • Type
    • Types
    • Watchpoint

Reference

  • Commands
    • Execution and stack
    • Breakpoints and events
    • Memory and disassembly
    • Symbols, types, and expressions
    • Processes and modules
    • User mode
    • CPU
    • Memory manager
    • Objects and I/O
    • Security
    • Analysis
    • Target control
    • Session
  • Expressions

Internals

  • VBS internals
  • Reading memory over KD
  • Rust crate API (docs.rs)

Resources

  • Source code
  • Releases
  • Bug reports
  • Discussions
  • PyPI package
  • crates.io
Back to top
View this page
Edit this page

Commands¶

Every command the REPL accepts, grouped as .hh lists them. The text is the REPL’s own help: .hh <command> prints the same.

  • Execution and stack
  • Breakpoints and events
  • Memory and disassembly
  • Symbols, types, and expressions
  • Processes and modules
  • User mode
  • CPU
  • Memory manager
  • Objects and I/O
  • Security
  • Analysis
  • Target control
  • Session
Next
Execution and stack
Previous
Watchpoint
Copyright © dmaivel
Made with Sphinx and @pradyunsg's Furo