如何编写无人值守WinDbg脚本实现断点、延迟及无GUI命令行调试?
Got it, let's walk through how to set up fully unattended debugging with WinDbg—no GUI, automatic breakpoint setup, pause-on-hit, and delayed continue. Here's the step-by-step breakdown:
Core Command-Line Solution (Single Line)
You can pack all logic into a single WinDbg command using the -c parameter to run a sequence of commands. This skips the GUI entirely and runs everything headless:
"C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\windbg.exe" -pn my-executable.exe -nh -c "bu 0x1337; g; .sleep 5000; g; q"
Let's break down what each part does:
-pn my-executable.exe: Attaches WinDbg to the running process matchingmy-executable.exe-nh: Skips loading WinDbg's initialization files (critical for unattended mode—avoids unexpected default behavior)-c "...":Executes the command sequence inside the quotes, in order:bu 0x1337: Sets an unresolved breakpoint at the absolute address0x1337(usebainstead if you need a hardware breakpoint, butbuworks for absolute addresses here)g: Resumes execution of the target process, waiting for the breakpoint to hit.sleep 5000: Pauses the debugger (and target process) for 5000 milliseconds (5 seconds—adjust this value as needed)g: Resumes execution again after the delayq: Exits WinDbg once the post-delay continue is done (omit this if you want to keep the debugger open)
Alternative: Use a Script File (For Longer/Complex Logic)
If your command sequence gets unwieldy, put it in a text script file (e.g., debug_script.txt) for better readability:
# debug_script.txt bu 0x1337 # Set address breakpoint g # Run until breakpoint hits .sleep 5000 # Pause for 5 seconds g # Resume execution q # Exit WinDbg
Then call it with WinDbg using the $< command to load the script:
"C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\windbg.exe" -pn my-executable.exe -nh -c "$<debug_script.txt"
Handling Repeat Breakpoint Hits
If you need the delay-and-continue logic to trigger every time the breakpoint is hit (not just once), modify the breakpoint command to include the sleep and continue directly:
"C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\windbg.exe" -pn my-executable.exe -nh -c "bu 0x1337 \".sleep 5000; g\"; g"
Or in script form:
bu 0x1337 ".sleep 5000; g" # Auto-run sleep+continue every time breakpoint hits g # Start the process running
This way, every time the breakpoint is triggered, the debugger automatically pauses for the specified duration, then resumes execution—no manual intervention needed.
Key Notes
- Match WinDbg architecture to your target process: Use the x86 version of WinDbg if your app is 32-bit, x64 if it's 64-bit.
- Verify the address
0x1337is valid for your target process—if it's not, the breakpoint will never trigger. - If you need to debug a process starting from launch (not attach to a running one), replace
-pn my-executable.exewith-g my-executable.exeto launch the process and immediately resume execution after attaching.
内容的提问来源于stack exchange,提问作者BullyWiiPlaza

