{"id":935,"date":"2026-10-06T11:14:28","date_gmt":"2026-10-06T18:14:28","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/?p=935"},"modified":"2026-10-07T20:54:56","modified_gmt":"2026-10-08T03:54:56","slug":"introducing-windbg-mcp-debug-with-natural-language-grounded-in-evidence","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/introducing-windbg-mcp-debug-with-natural-language-grounded-in-evidence\/","title":{"rendered":"Introducing WinDbg MCP: Debug with natural language, grounded in evidence"},"content":{"rendered":"<p><span data-contrast=\"auto\">Debugging rarely starts with a clear answer. An app crashes, a service hangs, a driver fails, or a kernel dump offers few clues. Whether you\u2019re working with a live target, crash dump, or Time Travel Debugging (TTD) trace, the first question is the same: <\/span><b><span data-contrast=\"auto\">Where do I start, and what should I investigate next?<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Today we\u2019re introducing <\/span><a href=\"https:\/\/aka.ms\/windbg\/download\"><b><span data-contrast=\"none\">WinDbg MCP<\/span><\/b><\/a><span data-contrast=\"auto\">, a natural-language interface for WinDbg built on Model Context Protocol (MCP). It connects AI clients such as <\/span><a href=\"https:\/\/apps.microsoft.com\/detail\/xpdc8mmrvcf73p?hl=en-US&amp;gl=US\"><span data-contrast=\"none\">GitHub Copilot CLI<\/span><\/a><span data-contrast=\"auto\"> and <\/span><a href=\"https:\/\/apps.microsoft.com\/detail\/xp9khm4bk9fz7q?hl=en-US&amp;gl=US\"><span data-contrast=\"none\">Visual Studio Code<\/span><\/a><span data-contrast=\"auto\"> to an active WinDbg session, so you can investigate user-mode and kernel-mode crashes and hangs in plain language, grounded in debugger evidence.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><span data-contrast=\"auto\">With safeguards on by default and AI-initiated actions visible in WinDbg, you move from symptoms to evidence-backed hypotheses and clear next steps while staying in control.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The <\/span><a href=\"https:\/\/github.com\/microsoft\/win-dev-skills\/tree\/main\/plugins\/windbg\"><b><span data-contrast=\"none\">Diagnostician<\/span><\/b><\/a><span data-contrast=\"auto\"> skill adds a structured, repeatable root-cause workflow for apps, services, UMDF drivers, and kernel-mode drivers. It treats pattern matches as hypotheses, tests alternatives, and delivers candidate root causes with targeted next steps and clear evidence gaps.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><strong>What is WinDbg MCP?<\/strong><\/h3>\n<p><span data-contrast=\"auto\">WinDbg MCP is an MCP server in WinDbg that connects AI clients to a live WinDbg session through a local proxy. You can ask an AI client to inspect the current target, run debugger commands, review diagnostics and source code, visualize debugger data, or create scripts for repeatable analysis.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Currently, officially supported AI clients are <\/span><a href=\"https:\/\/apps.microsoft.com\/detail\/xp9khm4bk9fz7q?hl=en-US&amp;gl=US\"><span data-contrast=\"none\">Visual Studio Code<\/span><\/a><span data-contrast=\"auto\"> and <\/span><a href=\"https:\/\/apps.microsoft.com\/detail\/xpdc8mmrvcf73p?hl=en-US&amp;gl=US\"><span data-contrast=\"none\">GitHub Copilot CLI<\/span><\/a><span data-contrast=\"auto\">. <\/span><a href=\"https:\/\/claude.com\/product\/claude-code\"><span data-contrast=\"none\">Claude Code<\/span><\/a><span data-contrast=\"auto\"> may work if you disable cross-prompt injection protection, which we don\u2019t recommend.\u00a0<\/span><span data-ccp-props=\"{&quot;335559739&quot;:0}\">See\u00a0<em>Using other MCP clients<\/em>\u00a0in\u00a0<strong>Get Started<\/strong>\u00a0for details.<\/span><\/p>\n<h3><strong>Why we built it<\/strong><\/h3>\n<p><span data-contrast=\"auto\">We built WinDbg MCP so <span class=\"TrackChangeTextInsertion TrackedChange SCXW204042774 BCX8\"><span class=\"TextRun SCXW204042774 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW204042774 BCX8\">in GitHub Copilot CLI <\/span><\/span><\/span><span class=\"TrackChangeTextInsertion TrackedChange SCXW204042774 BCX8\"><span class=\"TextRun SCXW204042774 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW204042774 BCX8\">or VS<\/span><\/span><\/span><span class=\"TrackChangeTextInsertion TrackedChange SCXW204042774 BCX8\"><span class=\"TextRun SCXW204042774 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW204042774 BCX8\"> Code Copilot\u00a0<\/span><\/span><\/span>you can ask something as simple as: <\/span><i><span data-contrast=\"auto\">\u201cRoot cause this crash, show the supporting evidence, and state any unverified assumptions.\u201d<\/span><\/i><span data-contrast=\"auto\"> Getting from a symptom to a defensible root cause used to mean knowing which WinDbg commands to run, how to read their output, and what evidence to gather next. That was a high bar for new developers and a time sink for experienced ones.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Now you describe the problem in natural language, and skills such as Diagnostician add a repeatable process for gathering evidence, testing hypotheses, and flagging what remains unknown. New users can start without mastering the command set and learn as they go by watching the AI-driven commands run in WinDbg. Experienced engineers can move faster through repetitive analysis and focus on validating the root cause and choosing the right fix.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><strong>Get Started<\/strong><\/h3>\n<p>WinDbg MCP is included starting with version 1.2610.1001.0 and available from the <a href=\"https:\/\/apps.microsoft.com\/detail\/9PGJGD53TN86?hl=en-us&amp;gl=US&amp;ocid=pdpshare\">Microsoft Store<\/a> and <a href=\"https:\/\/aka.ms\/windbg\/download\">WinDbg download page<\/a>.<\/p>\n<ol>\n<li>Open WinDbg and go to\u00a0<strong>MCP service settings<\/strong>.<\/li>\n<li>Ensure\u00a0<strong>Enable Server<\/strong>\u00a0is selected and choose\u00a0<strong>VS Code<\/strong>\u00a0or\u00a0<strong>GitHub Copilot CLI<\/strong>.<\/li>\n<li>Select\u00a0<strong>Install MCP<\/strong>\u00a0to register WinDbg with the selected client.<\/li>\n<li>Select\u00a0<strong>MCP Service<\/strong>, review the Privacy and Security Warning and the Secure Mode option, and then select <strong>Yes<\/strong> to start the service.<\/li>\n<li>Load or attach to a debugging target.<\/li>\n<li>Select\u00a0<strong>Open Chat<\/strong>\u00a0and start your investigation.<\/li>\n<\/ol>\n<p>The following demo shows a user connecting GitHub Copilot CLI to an active WinDbg session and beginning an investigation: <a href=\"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-content\/uploads\/sites\/64\/2026\/10\/WinDbg-MCP-GHCP-CLI-Debugging-Video.mp4\">View demo full size<\/a><\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-content\/uploads\/sites\/64\/2026\/10\/WinDbg-MCP-GHCP-CLI-Debugging-GIF.gif\"><img decoding=\"async\" class=\"alignnone size-full wp-image-963\" src=\"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-content\/uploads\/sites\/64\/2026\/10\/WinDbg-MCP-GHCP-CLI-Debugging-GIF.gif\" alt=\"WinDbg MCP GHCP CLI Debugging GIF image\" width=\"1280\" height=\"720\" \/><\/a><\/p>\n<p>For detailed setup instructions and prerequisites, see <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/debuggercmds\/set-up-windbg-mcp\">Set up and use WinDbg MCP<\/a>. To report a problem or suggest an improvement, visit the\u00a0<a title=\"\" draggable=\"false\" href=\"https:\/\/github.com\/microsoft\/WinDbg-Feedback\/issues\" data-href=\"https:\/\/github.com\/microsoft\/WinDbg-Feedback\/issues\">WinDbg Feedback repository<\/a>.<\/p>\n<p><strong>Using other MCP clients:<\/strong> Other MCP-compatible clients, such as Codex and Claude Code, may work with custom configuration on a best-effort basis. <span class=\"TextRun SCXW80627336 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW80627336 BCX8\">Because these clients <\/span><span class=\"NormalTextRun SCXW80627336 BCX8\">don\u2019t<\/span><span class=\"NormalTextRun SCXW80627336 BCX8\"> currently support MCP sampling, using them <\/span><\/span><span class=\"TextRun SCXW80627336 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW80627336 BCX8\">require<\/span><\/span><span class=\"TrackChangeTextInsertion TrackedChange SCXW80627336 BCX8\"><span class=\"TextRun SCXW80627336 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW80627336 BCX8\">s<\/span><\/span><\/span><span class=\"TextRun SCXW80627336 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW80627336 BCX8\"> turning off cross-prompt injection protection. Consider the reduced protection before connecting to a target.<\/span><\/span><span class=\"EOP SCXW80627336 BCX8\" data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><strong>Example debugging flow<\/strong><\/h3>\n<p>Imagine opening a crash dump without knowing where the failure began.\u00a0Start by describing what you want to understand:<\/p>\n<table style=\"width: 94.7143%; height: 36px;\">\n<tbody>\n<tr style=\"height: 36px;\">\n<td style=\"height: 36px; width: 100%;\" width=\"623\"><em>Analyze this crash dump and identify the likely root cause. Include supporting debugger evidence and any assumptions that remain unverified.<\/em><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>WinDbg MCP can inspect the target using relevant debugger tools and organize the findings into an initial hypothesis. You can then ask what evidence supports the conclusion, which alternatives remain, and what to investigate next.<\/p>\n<h3><b><span data-contrast=\"auto\">Structured root-cause triage with Diagnostician<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Diagnostician brings Windows-specific debugging playbooks to GitHub Copilot CLI through WinDbg MCP. It runs a repeatable five-phase investigation, treats pattern matches as hypotheses, and reports candidate root causes with targeted validation steps. It supports apps, services, user-mode drivers (including UMDF), and kernel-mode drivers.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Diagnostician is part of the\u202f<\/span><a href=\"https:\/\/github.com\/microsoft\/win-dev-skills\"><span data-contrast=\"none\">windbg\u202fplugin<\/span><\/a><span data-contrast=\"auto\"> in the public\u202f<\/span><a href=\"https:\/\/github.com\/microsoft\/win-dev-skills\"><span data-contrast=\"none\">win-dev-skills<\/span><\/a><span data-contrast=\"auto\">\u202fcatalog. With Git and GitHub Copilot CLI installed, your target loaded in WinDbg, and the MCP service connected:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ol>\n<li><span data-contrast=\"auto\">Add the catalog:\u202fcopilot plugin marketplace add microsoft\/win-dev-skills<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Install the plugin:\u202fcopilot plugin install windbg@win-dev-skills<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Start a new Copilot CLI session and enter:<\/span><span data-contrast=\"auto\">\u202f<\/span><\/li>\n<\/ol>\n<table style=\"width: 94.7143%; height: 36px;\">\n<tbody>\n<tr style=\"height: 36px;\">\n<td style=\"height: 36px; width: 100%;\" width=\"623\"><em><i><span data-contrast=\"auto\">Root cause the dump in the debugger. Let the diagnostician orchestrate the debugging session, test alternative explanations, and state what evidence is missing.<\/span><\/i><\/em><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span data-contrast=\"auto\">Steps 1 and 2 are one-time setup. For a saved report, use the full investigation prompt in the windbg plugin <\/span><a href=\"https:\/\/github.com\/microsoft\/win-dev-skills\/blob\/main\/plugins\/windbg\/README.md\"><span data-contrast=\"none\">README<\/span><\/a><span data-contrast=\"auto\">. When Copilot CLI can write files, it saves a Markdown report to\u202f.diagnoses\\&lt;short-id&gt;\\&lt;yyyyMMdd-HHmmss&gt;.md\u202fin the working directory.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><i><span data-contrast=\"auto\">Using a different AI client? See the note on other MCP clients in <\/span><\/i><b><i><span data-contrast=\"auto\">Get Started<\/span><\/i><\/b><i><span data-contrast=\"auto\">, including the cross-prompt injection consideration.\u00a0<\/span><\/i><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><strong>How it works<\/strong><\/h3>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-content\/uploads\/sites\/64\/2026\/10\/WinDbgMCP-Architecture.webp\"><img decoding=\"async\" class=\"alignnone wp-image-957\" src=\"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-content\/uploads\/sites\/64\/2026\/10\/WinDbgMCP-Architecture-300x60.webp\" alt=\"WinDbgMCP Architecture image\" width=\"775\" height=\"155\" srcset=\"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-content\/uploads\/sites\/64\/2026\/10\/WinDbgMCP-Architecture-300x60.webp 300w, https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-content\/uploads\/sites\/64\/2026\/10\/WinDbgMCP-Architecture-1024x205.webp 1024w, https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-content\/uploads\/sites\/64\/2026\/10\/WinDbgMCP-Architecture-768x154.webp 768w, https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-content\/uploads\/sites\/64\/2026\/10\/WinDbgMCP-Architecture-1536x307.webp 1536w, https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-content\/uploads\/sites\/64\/2026\/10\/WinDbgMCP-Architecture-2048x410.webp 2048w\" sizes=\"(max-width: 775px) 100vw, 775px\" \/><\/a><\/p>\n<p>WinDbg MCP uses a local proxy to connect an AI client to a specific WinDbg session. The debugger connection remains local, while the AI client communicates with its configured model service according to that client\u2019s configuration and data-handling policies.<\/p>\n<p>When you ask a question, the AI client can invoke relevant WinDbg MCP tools based on the request. WinDbg performs the requested debugger actions and returns the results to the client for analysis. The actions remain visible in WinDbg so you can review what was run and validate the resulting findings. Only one active MCP client can connect to a WinDbg session at a time. If multiple sessions are available, you can select the one you want to investigate.<\/p>\n<h3><strong>Built-in security protections<\/strong><\/h3>\n<p>WinDbg MCP includes safeguards designed for AI-assisted debugging. AI-initiated actions are recorded in logs, providing an auditable record of what was run.<\/p>\n<p><strong>Secure Mode<\/strong>\u00a0restricts high-risk operations, including loading or executing untrusted code, launching processes, and performing unsafe file operations. The option to enter Secure Mode is selected by default when you start MCP. Start MCP before connecting to a target for full Secure Mode. If a target is already connected, WinDbg enters partial Secure Mode and displays a warning. Once enabled, Secure Mode remains active until WinDbg restarts.<\/p>\n<p><strong>Cross-prompt injection protection<\/strong>\u00a0checks debugger command output for content that could mislead the AI into unsafe actions. For protected operations, WinDbg uses the AI client\u2019s configured model service to classify the output and blocks content identified as potentially unsafe. This protection requires a client that supports and permits MCP sampling and may use additional AI tokens.<\/p>\n<p>Disable these protections only when working with an authorized target in a trusted environment and when doing so is permitted by your organization\u2019s security and data-handling policies. For details, see the <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/debuggercmds\/windbg-mcp-overview\">WinDbg MCP overview<\/a>.<\/p>\n<h3><strong>Use AI-assisted debugging responsibly<\/strong><\/h3>\n<p>Built-in safeguards reduce risk, but AI-generated findings may still be incomplete or incorrect. Validate important conclusions against the target state and evidence visible in WinDbg, and review any generated or modified scripts before running them.<\/p>\n<p>The AI client may send debugging context to its configured model service. Use WinDbg MCP only with authorized targets and in accordance with your organization\u2019s AI, security, privacy, and data-handling policies.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Debugging rarely starts with a clear answer. An app crashes, a service hangs, a driver fails, or a kernel dump offers few clues. Whether you\u2019re working with a live target, crash dump, or Time Travel Debugging (TTD) trace, the first question is the same: Where do I start, and what should I investigate next?\u00a0 Today [&hellip;]<\/p>\n","protected":false},"author":218665,"featured_media":76,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-935","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-performance-diagnostics"],"acf":[],"blog_post_summary":"<p>Debugging rarely starts with a clear answer. An app crashes, a service hangs, a driver fails, or a kernel dump offers few clues. Whether you\u2019re working with a live target, crash dump, or Time Travel Debugging (TTD) trace, the first question is the same: Where do I start, and what should I investigate next?\u00a0 Today [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-json\/wp\/v2\/posts\/935","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-json\/wp\/v2\/users\/218665"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-json\/wp\/v2\/comments?post=935"}],"version-history":[{"count":2,"href":"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-json\/wp\/v2\/posts\/935\/revisions"}],"predecessor-version":[{"id":982,"href":"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-json\/wp\/v2\/posts\/935\/revisions\/982"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-json\/wp\/v2\/media\/76"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-json\/wp\/v2\/media?parent=935"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-json\/wp\/v2\/categories?post=935"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/performance-diagnostics\/wp-json\/wp\/v2\/tags?post=935"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}