ntoseye
Drive the ntoseye Windows kernel debugger from Python, and run it from the command line.
The standalone SDK uses the 0.37 API; see docs/sdk.md for
address-space-bound views, run control, and the 0.36 migration table. The
package also installs the ntoseye command (the REPL, ntoseye mcp, dap,
and gdbserver), which runs Python custom commands from
~/.ntoseye/commands/: uv tool install ntoseye or pipx install ntoseye.
Install
pip install ntoseye
Or build from source into a virtualenv with maturin:
cd python
python3 -m venv .venv
source .venv/bin/activate
pip install maturin
maturin develop --release
Or build a wheel and install it:
cd python
maturin build --release --out dist
pip install dist/ntoseye-*.whl
Quick start
import ntoseye
with ntoseye.attach() as dbg: # defaults to the kd backend
print(dbg.inspect.version())
for proc in dbg.processes:
print(proc.pid, proc.name)
For read-only inspection of a paused VM, select backend="memory". Processes
are handles keyed by PID (dbg.processes[pid]); memory and modules for a
specific process are available through proc.memory and proc.modules.
Type stubs
ntoseye/_ntoseye.pyi is generated from the extension by PyO3's
introspection: signatures come from the Rust types and docstrings from the
doc comments. After changing the Rust surface, regenerate it and commit the
result (CI fails when the checked-in stub differs from a fresh one):
maturin develop --release --generate-stubs
Tests
pip install pytest mypy
pytest tests # target-free surface tests
mypy --strict -p ntoseye # the stub and package type-check
NTOSEYE_TEST_BACKEND=kd NTOSEYE_TEST_CONNECT=/tmp/ntoseye-kd.sock pytest tests
The last line also runs tests/test_live.py against a guest: it breaks in,
steps, sets breakpoints on hot kernel functions, and resumes the guest.
Releasing portable wheels
Release wheels are built by .github/workflows/release.yml with PyO3/maturin-action on native GitHub runners:
- Linux x86-64 and ARM64 build on
ubuntu-22.04andubuntu-24.04-arminside thequay.io/pypa/manylinux_2_28_*images, producingmanylinux_2_28wheels. - Apple Silicon uses the native ARM64
macos-14runner.
Each wheel then passes twine check and the target-free tests (tests/test_surface.py) in a clean virtual environment before upload.
To reproduce a Linux release wheel locally (from the repository root, Docker required):
docker run --rm -e CARGO_TARGET_DIR=/tmp/target -e HOST_IDS="$(id -u):$(id -g)" \
-v "$PWD":/io -w /io/python quay.io/pypa/manylinux_2_28_$(uname -m) bash -c '
dnf install -y clang &&
curl -sSf https://sh.rustup.rs | sh -s -- -y --profile minimal &&
source ~/.cargo/env &&
/opt/python/cp312-cp312/bin/pip install maturin &&
/opt/python/cp312-cp312/bin/maturin build --release --out dist --compatibility manylinux_2_28 &&
chown -R "$HOST_IDS" dist'
Release files for ntoseye 0.37.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Built distributions (wheels)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| ntoseye-0.37.1-cp39-abi3-manylinux_2_28_x86_64.whl | CPython 3.9 | abi3 | Linux glibc 2.28+ x86-64 | Details |
| ntoseye-0.37.1-cp39-abi3-manylinux_2_28_aarch64.whl | CPython 3.9 | abi3 | Linux glibc 2.28+ ARM64 | Details |
| ntoseye-0.37.1-cp39-abi3-macosx_11_0_arm64.whl | CPython 3.9 | abi3 | macOS 11.0+ ARM64 | Details |
Total release size: 29.4 MB
Release files / ntoseye-0.37.1-cp39-abi3-manylinux_2_28_x86_64.whl
| Download URL | ntoseye-0.37.1-cp39-abi3-manylinux_2_28_x86_64.whl |
|---|---|
| Size | 10.1 MB |
| Tags | CPython 3.9 Linux glibc 2.28+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
fbd219064bf0fdc721d4a95f7d7471c763ff274a0ce7bc6da44208582c93372b
|
|
BLAKE2b-256 checksum How to use checksums |
4d5a62d61a03cd902860ffd66b9a1e697be83e4745c6fedd3eddd250062c1c9b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.
Transparency logRelease files / ntoseye-0.37.1-cp39-abi3-manylinux_2_28_aarch64.whl
| Download URL | ntoseye-0.37.1-cp39-abi3-manylinux_2_28_aarch64.whl |
|---|---|
| Size | 10.2 MB |
| Tags | CPython 3.9 Linux glibc 2.28+ ARM64 abi3 |
|
SHA-256 checksum How to use checksums |
6554c814661cccd524cf8fcedc50f305ce8182693f74fd7d88659ebe1f812736
|
|
BLAKE2b-256 checksum How to use checksums |
a3aff11c8b0ab4412468adeee35ba97200c7a3dd890a01501296760b7a425177
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.
Transparency logRelease files / ntoseye-0.37.1-cp39-abi3-macosx_11_0_arm64.whl
| Download URL | ntoseye-0.37.1-cp39-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 9.1 MB |
| Tags | CPython 3.9 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
6406499f90bb2e2b26516963db8710ab58758a80236295d32ee6bec30c85be6c
|
|
BLAKE2b-256 checksum How to use checksums |
d88ab09ae8f20884346a126420948b2d975c2272e11974c9305f169c69d5d1c3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.
Transparency log