IDA Pro MCP Multi
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@IDA Pro MCP Multiopen crypto.dll and scan for vulnerabilities"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
IDA Pro MCP Multi
π Based on: This project is developed based on mrexodia/ida-pro-mcp, extending it with multi-instance support and vulnerability scanning capabilities.
A powerful MCP Server for AI-assisted reverse engineering in IDA Pro, with support for analyzing multiple binaries simultaneously.
Why This Project?
The original ida-pro-mcp is an excellent tool for AI-assisted reverse engineering, but we encountered limitations in real-world scenarios:
Problem 1: Single Instance Limitation
When reverse engineering complex software, you often need to analyze multiple related binaries:
A main executable (
main.exe)Multiple DLLs/shared libraries (
helper.dll,crypto.dll, etc.)Third-party libraries
The original project only supports one IDA instance at a time, making cross-binary analysis tedious and inefficient.
Problem 2: No Built-in Vulnerability Detection
Security researchers need to quickly identify potentially dangerous code patterns. Manually searching for vulnerable function calls is time-consuming.
Related MCP server: Ghidra MCP Server
New Features
π Multi-Instance Support
Analyze multiple binaries simultaneously with a Gateway architecture:
AI Client ββMCPββ> Gateway (port 13337) ββ> IDA Instance 1 (main.exe, port 13338)
ββ> IDA Instance 2 (helper.dll, port 13339)
ββ> IDA Instance 3 (crypto.dll, port 13340)How It Works:
The first IDA instance automatically starts a Gateway Server (port 13337)
Each subsequent IDA instance registers with the Gateway and gets a unique port
AI clients connect to the Gateway, which routes requests to the appropriate instance
Instance Management Tools:
Tool | Description |
| List all registered IDA instances |
| Switch the default target instance (by ID or binary name) |
| Get info about the current default instance |
| Check if an instance is responding |
| Auto-search and open a library file in a new IDA instance |
Auto-Open Library:
When analyzing a program that uses external libraries, you can ask AI to open them automatically:
Searches the current directory and subdirectories for the library file
Auto-detects architecture (x86/x64/ARM)
Opens in IDA Pro with automatic analysis (no dialogs)
MCP plugin starts automatically after loading
Targeting Specific Instances:
Most tools accept an optional target parameter:
{
"method": "decompile",
"params": {
"addr": "0x401000",
"target": "helper.dll"
}
}Legacy Mode:
To disable multi-instance support:
IDA_MCP_LEGACY=1π Vulnerability Scanning
Comprehensive vulnerability scanning to identify potentially dangerous function calls with advanced detection:
Tools:
Tool | Description |
| Scan binary for vulnerabilities, returns summary |
| Get detailed findings for a specific category |
| Scan a specific function for vulnerability patterns |
| List all vulnerability categories and associated functions |
Supported Vulnerability Categories (11 categories, 150+ dangerous functions):
Category | Dangerous Functions | Description |
Format String | printf, sprintf, scanf, snprintf, syslog, etc. | Non-constant format strings, %s without width limit |
Buffer Overflow | strcpy, memcpy, gets, recv, fread, etc. | Unbounded copies, controllable sizes, %s in scanf |
Command Injection | system, popen, exec*, CreateProcess, ShellExecute, etc. | Non-constant commands |
Integer Overflow | malloc, calloc, realloc, alloca, VirtualAlloc, etc. | Potentially overflowing sizes |
Use After Free | free, delete, HeapFree, VirtualFree, etc. | Potential UAF/double-free |
Path Traversal | fopen, open, CreateFile, CopyFile, etc. | Controllable paths |
SQL Injection | sqlite3_exec, mysql_query, PQexec, etc. | Non-constant SQL queries |
Unchecked Return | malloc, setuid, setgid, chdir, etc. | Missing return value checks |
Race Condition | access, stat, lstat, etc. | TOCTOU vulnerabilities |
Information Leak | write, send, sendto, fwrite, etc. | Potentially leaking data |
Signed Comparison | strncmp, memcmp, memchr, etc. | Size parameters with signed comparison |
Detection Features:
Format String Analysis: Checks for non-constant format strings AND dangerous
%sspecifiers without width limitsstrlen Check: Detects if
strlen()was called before unbounded copy operationsReturn Value Check: Verifies if return values from malloc/setuid/etc. are properly validated
MSVC Secure Functions: Handles
_ssuffix variants (strcpy_s, sprintf_s, etc.)glibc Fortified Functions: Handles
_chksuffix variants (__printf_chk, __memcpy_chk, etc.)Risk Assessment: High/Medium/Low/Info based on parameter controllability
Workflow:
Ask AI to "scan for vulnerabilities"
AI calls
vuln_scan()to get a summary by category and risk levelReview the summary and select categories for deep analysis
AI uses
vuln_scan_details(category)anddecompile()to analyze specific findings
Note: Detailed results are saved to .ida-mcp-vuln/ folder to minimize token usage.
Prerequisites
IDA Pro (8.3 or higher, 9 recommended)
Any MCP-compatible client (Claude, Cursor, VS Code, Roo Code, etc.)
Installation
For Users Who Have Installed the Original ida-pro-mcp
If you have previously installed the original ida-pro-mcp, you need to uninstall it first and then force reinstall:
# Uninstall old versions
"D:\your\path\to\ida\python311\python.exe" -m pip uninstall -y ida-pro-mcp ida-pro-mcp-multi
# Force reinstall the new version
"D:\your\path\to\ida\python311\python.exe" -m pip install --no-cache-dir --force-reinstall --upgrade git+https://github.com/QYmag1c/ida-pro-mcp-multi
# Reinstall IDA plugin and configure MCP clients
"D:\your\path\to\ida\python311\Scripts\ida-pro-mcp.exe" --install
# View MCP configuration
"D:\your\path\to\ida\python311\Scripts\ida-pro-mcp.exe" --configThen restart IDA Pro and your MCP client.
Fresh Installation
Step 1: Install MCP Package
Open a terminal in IDA's Python directory and run:
# Navigate to IDA's Python directory
cd "D:\your\path\to\ida\python311"
# Install the MCP package
python.exe -m pip install --upgrade git+https://github.com/QYmag1c/ida-pro-mcp-multiStep 2: Install IDA Plugin and Configure MCP Clients
# Install IDA plugin and configure MCP clients
"D:\your\path\to\ida\python311\Scripts\ida-pro-mcp.exe" --install
# View MCP configuration for manual setup
"D:\your\path\to\ida\python311\Scripts\ida-pro-mcp.exe" --configNote: Replace D:\your\path\to\ida with your actual IDA Pro installation path.
Step 3: Restart
Important: Restart IDA Pro and your MCP client completely for the installation to take effect.
Verify Installation
Open IDA Pro and load a binary
Go to Edit β Plugins β MCP (or press
Ctrl+Alt+M)You should see
[MCP] Server startedin the output window
Architecture
src/ida_pro_mcp/
βββ server.py # MCP server + instance management tools
βββ gateway.py # Gateway Server for multi-instance routing
βββ ida_mcp.py # IDA plugin loader (registers with Gateway)
βββ ida_mcp/
βββ api_core.py # Core functions (decompile, disasm, etc.)
βββ api_analysis.py # Analysis operations
βββ api_vuln.py # Vulnerability scanning (NEW)
βββ api_memory.py # Memory operations
βββ api_types.py # Type operations
βββ api_modify.py # Modification operations
βββ api_stack.py # Stack frame operations
βββ api_debug.py # Debugger operations
βββ ...All Available Tools
This project includes all tools from the original project, plus the new multi-instance and vulnerability scanning features.
Instance Management (NEW)
list_instances(),switch_instance(),get_current_instance(),check_instance_health()
Vulnerability Scanning (NEW)
vuln_scan(),vuln_scan_details(),vuln_scan_function(),vuln_categories()
Core Functions
lookup_funcs(),int_convert(),list_funcs(),list_globals(),imports(),decompile(),disasm(),xrefs_to(),callees()
Modification Operations
set_comments(),patch_asm(),declare_type(),rename()
Memory Operations
get_bytes(),get_int(),get_string(),get_global_value(),patch(),put_int()
Analysis Operations
py_eval(),analyze_funcs(),find_regex(),find_bytes(),find_insns(),find(),basic_blocks(),callgraph()
Type Operations
set_type(),infer_types(),read_struct(),search_structs()
Stack Operations
stack_frame(),declare_stack(),delete_stack()
Debugger Operations (requires --unsafe flag)
dbg_start(),dbg_exit(),dbg_continue(),dbg_step_into(),dbg_step_over(), etc.
Acknowledgments
Original project: mrexodia/ida-pro-mcp
License
MIT License - See LICENSE for details.
This server cannot be deployed
Maintenance
Related MCP Connectors
Hunt zero-days by talking to binaries. 40+ tools. Hosted, OAuth + SSO, invite: hi@byteray.ai
Real-time CVE, exploit, and vulnerability intelligence for AI assistants (350K+ CVEs, 115K+ PoCs)
AI pentesting: run scans, triage vulnerabilities, review PRs, manage schedules and assets.
AI-powered threat intelligence, smart contract auditing, and cybersecurity OSINT.
Related MCP Servers
- AlicenseCqualityDmaintenanceEnables AI-assisted reverse engineering in IDA Pro by providing tools to analyze binaries, decompile functions, manage comments, search patterns, and interact with the IDA database through natural language.562MIT
- AlicenseNot gradedqualityCmaintenanceBridges Ghidra's reverse engineering capabilities with AI tools through 179 specialized tools for automated binary analysis and documentation. It supports full read/write access for function decompilation, renaming, and cross-binary documentation transfer in both GUI and headless modes.Apache 2.0
- AlicenseNot gradedqualityDmaintenanceEnables LLM clients like Claude to interact with IDA Pro for binary analysis, decompilation, cross-references, patching, and more via 41 MCP tools, 8 resources, and 7 guided prompts.52MIT
- AlicenseNot gradedqualityDmaintenanceAn enhanced MCP server for IDA Pro that integrates bulk binary export, multi-instance management via Broker mode, and 80+ analysis tools for AI-assisted reverse engineering.6MIT