Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
MCP server for x64dbg control
This project connects an MCP client to x64dbg so you can run debugger actions in plain language. The C++ plugin runs inside x64dbg, and the TypeScript server bridges requests over localhost with typed tools and endpoints.
Builders who want their agent to steer x64dbg while they analyze binaries.
You can ask your agent to set breakpoints, inspect memory, trace code, and dump PEs without manual scripting.
What it does
Debugger control tools
Run, step, pause, evaluate expressions, send raw commands, and execute scripts from the agent.
Memory and CPU inspection
Read and write memory, allocate and protect pages, inspect registers, and view stack-related state.
Code analysis tools
Disassemble, assemble, search xrefs, inspect basic blocks and CFGs, and follow loops.
Breakpoints and tracing
Create software, hardware, memory, conditional, and logging breakpoints, then collect trace logs.
Symbols and search
List and search labels, comments, bookmarks, byte patterns, and strings inside the target.
Process and patching tools
Inspect threads, handles, TCP, PEB data, hide the debugger, patch bytes, dump PE files, and fix imports.
How to get it
- 1Download x64dbg_mcp.dp64 / .dp32 from the latest release and drop them in
x64dbg/x64/plugins/x64dbg_mcp.dp64 ← 64-bit targets x64dbg/x32/plugins/x64dbg_mcp.dp32 ← 32-bit targets
- 2…or build + install it yourself (auto-detects your x64dbg — no path editing)
.\build.ps1 -Install
README
x64dbg MCP Server
Drive x64dbg with your AI. Talk to Claude, Cursor, Windsurf, Cline, or any MCP client in plain English and it sets breakpoints, reads memory, disassembles, traces, dumps PEs, and bypasses anti-debug — live, inside the debugger.
23 mega-tools over 153 REST endpoints, fully typed with Zod. A C++ plugin runs inside
x64dbg; a tiny TypeScript server bridges it to your client over stdio. Everything stays on
127.0.0.1 — nothing leaves your machine.
Latest — v2.3.0
- Hardened & crash-proof. A malformed HTTP request can no longer crash x64dbg; the plugin server drains connections cleanly on stop and ships an optional auth token (CORS is locked down).
- Real data from more tools.
imports/exports,symbolssearch/list,patcheslist, andstringsnow return actual parsed results instead of pointing you at a GUI view.- Live trace status. New
/api/trace/status(+tracing status) reports whether a trace is running, and the exception/trace tools now honor every parameter they accept.- Plus the v2.2.x fixes: x32dbg loads on current snapshots, and requests no longer time out on long operations.
What it looks like
"Set a breakpoint on CreateFileW and run the program"
"Disassemble the current function and explain what it does"
"Search for 48 8B ?? 48 85 C0 in the main module and disassemble the hits"
"Hide the debugger and bypass the anti-debug checks"
"Trace into the VM dispatcher and log every instruction to a file"
"Dump the main module to disk and fix the import table"
Real use: tracing VMProtect'd code, finding anti-cheat scanner threads, decoding XOR'd class names, mapping detection logic — all by asking, no manual scripting.
Install
1 · Plugin (inside x64dbg)
Download x64dbg_mcp.dp64 / .dp32 from the
latest release and drop them in:
x64dbg/x64/plugins/x64dbg_mcp.dp64 ← 64-bit targets
x64dbg/x32/plugins/x64dbg_mcp.dp32 ← 32-bit targets
…or build + install it yourself (auto-detects your x64dbg — no path editing):
.\build.ps1 -Install
Start x64dbg; the log shows [MCP] x64dbg MCP Server started on 127.0.0.1:27042.
2 · Server (your AI client)
No install — just point your client at npx. Claude Code:
{
"mcpServers": {
"x64dbg": {
"type": "stdio",
"command": "cmd",
"args": ["/c", "npx", "-y", "x64dbg-mcp-server"]
}
}
}
Claude Desktop / Cursor / Windsurf / Cline use the same block without the cmd /c wrapper:
{ "command": "npx", "args": ["-y", "x64dbg-mcp-server"] }.
Full per-client paths are in the reference.
3 · Go
Open a target in x64dbg and start talking to your assistant.
Tools at a glance
23 action-based tools spanning the whole debugger:
- Control — run/step/pause, raw commands, scripts, expression eval
- CPU & memory — registers (incl. AVX-512), read/write/alloc/protect, memory map
- Stack — call stack, SEH chain, return addresses
- Code analysis — disassemble, assemble, xrefs, basic blocks, CFG, loops
- Breakpoints & tracing — software/hardware/memory/conditional/logging, batch, trace logs
- Symbols & search — labels, comments, bookmarks, AOB pattern + string scan
- Process & system — threads/TEB, handles, TCP, PEB, anti-debug hide
- Patching & dumping — byte patches, PE dump, IAT fix, patch export
Every tool, action, and endpoint is documented in docs/REFERENCE.md.
Links
- Full reference — tools, architecture, build, config, troubleshooting
- npm: x64dbg-mcp-server
- Releases — prebuilt plugin DLLs
- x64dbg — the debugger
Security
The plugin binds to 127.0.0.1 only; the server talks pure stdio. All traffic stays on
localhost — no remote access, no telemetry, no data leaves your machine. For defense against
other local processes, set a token in the plugin's Settings and pass it via
X64DBG_MCP_TOKEN — every request must then carry it.
Author
bromo — GitHub. Built with Claude Code. MIT.
Files in the repo
- docs
- plugin
- server
- .gitignore
- build.ps1
- install.ps1
- LICENSE
- PROMOTION.md
- README.md
Discussion (0)
Ask about usage, or say what you built with itSign in to join the discussion.
No comments yet. Be the first to say what this is good for.
More connectors
High-performance code intelligence MCP server. Indexes codebases into a persistent knowledge graph — average repo in milliseconds. 158 languages, sub-ms queries, 99% fewer tokens. Single static binary, zero dependencies.

Universal provider proxy for OpenAI Codex & Claude Code — use any LLM (Claude, Gemini, Grok, DeepSeek, Ollama…) with Codex CLI, App, SDK, and Claude Code
Git-native persistent memory for AI coding agents. Implements Google OKF v0.2 with sub-300µs in-memory BM25 search, embedded MCP server, and progressive disclosure. Slashes token bloat by 80% with zero external databases or dependencies. Built in pure Go.
Local-first code intelligence graph for MCP and CLI. Builds a persistent map of your codebase so AI coding tools read only what matters, with benchmarked context reductions on reviews and large-repo workflows.
Stop your AI from making things up — it proposes, deterministic tools decide, every claim checked against ground truth with evidence. Grounded facts and context survive resets. Reverse engineering is the proving ground. MCP server + CLI.