Windows x64dbg/x32dbg debugging with guarded sessions, breakpoints, memory and runtime evidence.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
https://github.com/user-attachments/assets/07b813eb-4175-4f14-b21b-602548906398
x64dbg MCP gives an MCP client guarded control of a real x64dbg or x32dbg session. It turns live debugging into a replayable reverse-engineering workflow: bind the exact process, observe runtime facts, recover useful artifacts, validate them independently, and hand the evidence to IDA.
| Workflow | Representative tools | Result |
|---|---|---|
| Launch and bind | InitDebuggee, AttachToProcess, LaunchFileUnderDebugger, WaitForBreakpoint | Reproducible process and session identity |
| Live control | RegisterGet, RegisterSet, MemoryRead, MemoryWrite, DebugSetBreakpoint, SetHardwareBreakpoint | Controlled execution, memory and breakpoint changes |
| Runtime evidence | RunNativeTrace, GetNativeTrace, StartApiTrace, StartHeapTrace, GetBasicBlockCoverage, WaitForBreakpointCapture | Instruction paths, API/heap calls, exceptions and executed blocks |
| Key and unpack recovery | SearchStrings, ScanMemoryStrings, PatternFindMem, FindOEP, RunUntilOEP, FindIATCandidates, InspectRuntimeIAT | Comparisons, strings, OEP and runtime import candidates |
| Dump and repair | WriteMiniDump, DumpModuleRaw, DumpPeFromMemory, ScanMemoryForPEImages, FixDumpImports, ValidateDump, ExportPatchedFile | Replayable dumps and independently checked PE artifacts |
| IDA evidence handoff | ExportRuntimeEvidence, ImportStaticAnnotations, SyncBreakpoints, ResolveModuleRva | Hash/RVA-addressed comments, labels, coverage and API facts |
The complete catalog, parameters and response contracts are in the
tool reference. The compact profile keeps routine
model-facing responses short; detail="full" and the full profile expose
the complete evidence when it is needed.
Download the combined Windows bundle from Releases. It contains both native plugins and the Python backend:
plugins\MCPx64dbg.dp64 for x64dbgplugins\MCPx64dbg.dp32 for x32dbgruntime\src and runtime\requirements.txtruntime\tools\bin\managed_probeClose x64dbg/x32dbg. Open PowerShell in the folder containing the downloaded ZIP, then run the block below. It asks where to keep the MCP bundle and where x64dbg is already installed; no drive or installation directory is assumed. Keep the same PowerShell window open for the client-specific commands below.
Add the server to ~\.codex\config.toml. Replace the three angle-bracketed
values with the absolute paths printed by the setup block. TOML single-quoted
strings preserve Windows backslashes as written.
For normal target startup, call InitDebuggee directly with the EXE path. It
detects x86/x64, starts the matching debugger from X64DBG_ROOT, waits for the
bridge and opens the target. A separate BridgeHello preflight or manual
debugger-path search is not required.
Optional installation check: start x64dbg or x32dbg and verify the bridge:
GetScyllaHideStatus.installed and integrationReady describe the MCP
InjectorCLI/HookLibrary backend. guiPluginPresent describes only the optional
x64dbg GUI plugin; it is not required for MCP injection.
ScyllaHide is opt-in: launch tools default to use_scyllahide="off", and
auto also skips injection. Use force with an explicit profile when needed.
The CLI backend stages a private INI beside the injector and targets the exact
PID. Its compatibility configuration disables NtContinueHook and
KillAntiAttach together to avoid the reproduced continuation crash; the
result reports these overrides. This does not guarantee that every third-party
profile is compatible with every target or Windows build.
Add the same stdio server to Claude Code with the user scope. This command uses the paths selected by the setup block instead of embedding a machine-specific location:
Alternatively, run claude mcp add and enter the same command, arguments and
environment interactively.
Use the client's MCP JSON configuration. For Claude Desktop on Windows, the
file is %APPDATA%\Claude\claude_desktop_config.json. Generate a JSON block
with the actual paths selected above:
Cursor, VS Code MCP, Windsurf and other stdio clients use the same
command/args/env contract; only the location of their JSON file differs.
The IDA workflow is designed for the rison1337/ida-pro-mcp-fusion fork. x64dbg MCP does not pretend to be an IDA replacement and does not silently mutate an unrelated database. Instead:
ExportRuntimeEvidence writes a versioned evidence document containing the
target SHA-256, architecture, module RVAs, executed blocks, API calls,
comments, labels and functions.ResolveModuleRva and the coordinator normalize live addresses to the
static image identity.tools/ida_evidence_coordinator.py validates that the open Fusion database
has the same SHA-256 and architecture, then creates deterministic
set_name, set_comments, define_func and coverage/API comment actions.No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/x64dbg-mcp)<a href="https://allmcps.com/mcp/x64dbg-mcp"><img src="https://allmcps.com/api/badge/x64dbg-mcp?style=directory" alt="X64dbg MCP on AllMCPs" /></a>