x64dbg MCP Server
Enables AI assistants to perform reverse engineering and debugging of Windows executables through x64dbg, with tools for loading executables, controlling execution, analyzing memory and security, and generating reports.
README
x64dbg MCP Server
A production-level Model Context Protocol server that exposes x64dbg reverse-engineering and debugging capabilities to AI assistants (Claude, Windsurf Cascade, Cursor, etc.).
Architecture
┌─────────────────┐ STDIO/JSON-RPC ┌──────────────────┐ TCP (JSON) ┌──────────────┐
│ AI Assistant │ ◄───────────────► │ MCP Server │ ◄──────────► │ x64dbg │
│ (Claude, etc.) │ │ (Node.js / TS) │ port 27042 │ + Bridge │
└─────────────────┘ └──────────────────┘ │ Plugin │
└──────────────┘
Two components:
- MCP Server (
src/) — TypeScript Node.js process. Speaks MCP over STDIO to the AI host and connects to the bridge over TCP. - Bridge Plugin (
plugin/) — A lightweight C loader plugin embeds Python 3.10+ inside x64dbg. The Python bridge script callsx64bridge.dlldirectly viactypes— no x64dbgpy dependency. Exposes a local TCP server that translates MCP requests into x64dbg Bridge SDK calls.
Features
Auto-Launch & PE Detection
- Automatically detects PE architecture (x86 / x64) by reading the PE header
- Launches the correct debugger variant (
x32dbgorx64dbg) with the target executable - Waits for the bridge plugin TCP port to become reachable, then connects — zero manual setup
Core Debugging (12 tools)
load_executable— Load PE file, auto-detect x86/x64, auto-launch debugger, break on entrycontinue_execution/step_into/step_over/step_outrun_to_address— Run until a specific addressset_breakpoint— Software, hardware (execute/read/write/access), and memory BPs with conditions and log textremove_breakpoint/list_breakpointsterminate_session/list_sessionsexecute_command— Run any raw x64dbg command
Memory & Registers (9 tools)
read_memory/write_memory/search_memory— Hex patterns with wildcards, ASCII/Unicode textget_memory_map— Full virtual memory layout with protection and module infoget_registers/set_register— GP, flags, segment, debug, FPU/SSE registersget_call_stack— Backtrace with return addresses, module names, and symbolsget_threads/switch_thread— Thread enumeration and context switching
Static & Dynamic Analysis (10 tools)
disassemble— With metadata (is_call, is_jump, reference targets, comments)analyze_function— Boundaries, size, call graph (callers + callees), leaf detectionget_cross_references— Code and data xrefs (to/from/both)list_functions— With module filtering, name search, and paginationget_modules/get_imports/get_exports— With DLL and function name filtersfind_strings— ASCII + Unicode with content filtering and min-length controlget_pe_header— Full PE structure: DOS/NT headers, sections, data directories, entropytrace_execution— Record instruction trace with optional register snapshots
Security Analysis (5 tools)
detect_packing— Entropy analysis, known packer signatures, import count heuristics, confidence scoringanalyze_suspicious_apis— Cross-reference imports against 100+ malware-associated APIs in 10 categoriesdetect_anti_debug— IsDebuggerPresent, timing checks, PEB flags, TLS callbacks, int 2D/3, with bypass suggestionscheck_section_anomalies— W+X sections, unusual names, zero raw-size, high entropy detectiongenerate_security_report— Consolidated first-pass triage of all security checks with overall risk level
Total: 36 tools
Prerequisites
- Windows (x64dbg is Windows-only)
- Node.js ≥ 20
- Python 3.10+ installed system-wide
- CMake 3.15+ + MSVC or MinGW — only needed to build the C loader from source (pre-built binaries are included in the npm package)
x64dbg itself is downloaded automatically by
npm installif not already present.
Installation
From npm (recommended)
npm install -g x64dbg-mcp
postinstall runs automatically and handles:
| Step | What happens |
|---|---|
| x64dbg | Downloads latest snapshot from GitHub if not found locally |
| Plugin files | Deploys .dp64 / .dp32 loader + Python bridge to x64dbg plugins/ |
| Python | Detects Python install dir, sets PYTHON_HOME_X64 / PYTHON_HOME_X86 |
.env |
Creates with all detected settings and defaults |
After install, only two manual steps remain:
npm run doctor # verify everything is in order
# then configure your AI client (see Usage section)
From source
git clone https://github.com/your-org/x64dbg-mcp
cd x64dbg-mcp
npm install # downloads x64dbg, deploys .py files, writes .env
npm run build # compile TypeScript → dist/
npm run install-plugin # compile C loader (x64+x32), deploy to x64dbg
npm run doctor # verify
x64dbg already installed elsewhere? Set
X64DBG_PATHin.envbefore runningnpm run install-plugin, or pass-X64dbgPath "C:\path\to\x64dbg"to the script.
Manual plugin installation (alternative to install-plugin)
cd plugin\loader
# 64-bit
cmake -B build64 -A x64
cmake --build build64 --config Release
$p64 = "C:\x64dbg\release\x64\plugins"
Copy-Item build64\Release\x64dbg_mcp_loader.dp64 $p64
Copy-Item ..\x64dbg_mcp_bridge.py $p64
Copy-Item ..\x64dbg_bridge_sdk.py $p64
# 32-bit
cmake -B build32 -A Win32 -DBUILD_32BIT=ON
cmake --build build32 --config Release
$p32 = "C:\x64dbg\release\x32\plugins"
Copy-Item build32\Release\x64dbg_mcp_loader.dp32 $p32
Copy-Item ..\x64dbg_mcp_bridge.py $p32
Copy-Item ..\x64dbg_bridge_sdk.py $p32
npm run install-plugin does all of the above (both architectures by default). Pass -No32 to skip 32-bit.
Configuration
npm install creates .env automatically. To adjust, edit it directly or run npm run setup for an interactive wizard.
# x64dbg path (auto-detected)
X64DBG_PATH=C:\x64dbg
# Python install directories — avoids copying DLLs into the plugins folder.
# The C loader checks these first; falls back to PATH if unset.
PYTHON_HOME_X64=C:\Python314
PYTHON_HOME_X86=C:\Python312-32
# Bridge
BRIDGE_HOST=127.0.0.1
BRIDGE_PORT=27042
# Logging / limits
LOG_LEVEL=info
MAX_SESSIONS=5
SESSION_TIMEOUT_MS=3600000
| Variable | Default | Description |
|---|---|---|
X64DBG_PATH |
auto-detected | x64dbg installation directory |
PYTHON_HOME_X64 |
(auto-detected) | Python 64-bit dir — loader Priority 1; no DLL copy needed |
PYTHON_HOME_X86 |
(auto-detected) | Python 32-bit dir — used by .dp32 loader |
BRIDGE_PORT |
27042 |
TCP port the Python bridge listens on |
LOG_LEVEL |
info |
error / warn / info / debug |
MAX_SESSIONS |
5 |
Maximum concurrent debug sessions |
SESSION_TIMEOUT_MS |
3600000 |
Session idle timeout (ms) |
Usage
Configure your AI host
Note: You no longer need to manually start x64dbg. The MCP server auto-launches the correct debugger when you call
load_executable.
Claude Desktop
Add to claude_desktop_config.json:
{
"mcpServers": {
"x64dbg-mcp": {
"command": "node",
"args": ["C:\\path\\to\\x64dbg-mcp\\dist\\server.js"]
}
}
}
Windsurf / Cascade
{
"mcpServers": {
"x64dbg-mcp": {
"command": "node",
"args": ["C:\\path\\to\\x64dbg-mcp\\dist\\server.js"],
"env": { "BRIDGE_PORT": "27042" }
}
}
}
Start debugging
Ask your AI assistant:
"Load C:\samples\target.exe and analyze it for suspicious behavior"
The AI will use the MCP tools to:
load_executable→ load the binarygenerate_security_report→ run all security checksdisassemble→ inspect suspicious codeset_breakpoint+continue_execution→ dynamic analysis
Example Workflows
Crash Analysis
User: "My program crashes at startup, help me debug it"
AI: load_executable → continue_execution → get_call_stack →
read_memory → get_registers → disassemble
Malware Triage
User: "Analyze this suspicious binary"
AI: load_executable → generate_security_report →
analyze_suspicious_apis → detect_anti_debug →
find_strings → get_imports
Reverse Engineering
User: "Find the license check function"
AI: load_executable → find_strings (filter: "license") →
get_cross_references → analyze_function →
disassemble → trace_execution
Development
npm run ci # Full local pipeline: build + lint + test + python + C loader
npm run ci -- --no-loader # Skip C loader (no CMake needed)
npm run dev # Sync .py files to bundled x64dbg, then run via tsx
npm run sync-plugin # Manually sync plugin/*.py → x64dbg/release/x*/plugins/
npm run setup-x64dbg # Download/update bundled x64dbg snapshot
npm run setup-x64dbg -- --force # Force re-download
npm run setup-x64dbg -- --tag snapshot_2024-09-10_00-00 # Pin to specific version
npm run build # Compile TypeScript → dist/
npm run lint # ESLint src/**/*.ts
npm test # Unit tests (no x64dbg required)
npm run inspector # Launch MCP Inspector UI
npm run clean # Remove dist/
npm run dev automatically syncs Python source files to the bundled x64dbg via the predev
hook before starting the server — no manual copy needed during development.
Testing
# TypeScript unit tests (SessionManager, BridgeClient, launcher, config)
npm test
# Python bridge offline tests (no x64dbg required)
python plugin/test_bridge.py
# Full environment check
npm run doctor
CI (.github/workflows/ci.yml) runs all three jobs on every push:
ts: build + lint + test on Node 20 and 22python: syntax check + logic tests on Python 3.11loader: CMake build (x64 + x32), artifacts saved toplugin/loader/prebuilt/
On tagged releases (v*), CI also publishes to npm with the prebuilt binaries included.
Project Structure
x64dbg-mcp/
├── src/
│ ├── server.ts # Entry point, MCP server, graceful shutdown
│ ├── bridge.ts # TCP client — reconnect, request/response tracking
│ ├── launcher.ts # PE arch detection, debugger spawn, bridge poll
│ ├── session.ts # Session lifecycle & GC
│ ├── config.ts # Config from env / .env
│ ├── logger.ts # Winston logger (stderr only)
│ ├── types.ts # Shared TypeScript types
│ └── tools/
│ ├── index.ts # Tool registration barrel
│ ├── debug.ts # Core debugging (12 tools)
│ ├── memory.ts # Memory & registers (9 tools)
│ ├── analysis.ts # Analysis (10 tools)
│ └── security.ts # Security analysis (5 tools)
├── plugin/
│ ├── x64dbg_mcp_bridge.py # TCP server + handler dispatch
│ ├── x64dbg_bridge_sdk.py # ctypes bindings to x64bridge.dll
│ ├── test_bridge.py # Offline unit tests (no x64dbg required)
│ ├── loader/
│ │ ├── x64dbg_mcp_loader.c # C plugin — embeds Python 3
│ │ ├── CMakeLists.txt
│ │ └── prebuilt/ # Pre-built .dp64/.dp32 (populated by CI)
│ └── README.md
├── scripts/
│ ├── postinstall.mjs # Runs after npm install — downloads x64dbg, deploys plugin, writes .env
│ ├── setup-x64dbg.mjs # npm run setup-x64dbg — download/update x64dbg snapshot
│ ├── setup.mjs # npm run setup — interactive .env wizard
│ ├── doctor.mjs # npm run doctor — pre-flight diagnostics
│ ├── sync-plugin.mjs # npm run sync-plugin — sync .py to bundled x64dbg (predev hook)
│ ├── ci.mjs # npm run ci — local CI pipeline
│ └── install-plugin.ps1 # npm run install-plugin — compile C loader & deploy
├── test/
│ └── basic.test.ts # Node.js built-in test runner
├── .github/
│ └── workflows/
│ └── ci.yml # CI + npm publish on tag
├── eslint.config.mjs
├── tsconfig.json
├── package.json
├── .env.example
└── README.md
License
MIT
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。