x32dbg MCP Server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@x32dbg MCP ServerSet a breakpoint at 0x401000 and show disassembly"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
x32dbg MCP Server
Full-Featured Model Context Protocol (MCP) server for x32dbg debugger
Give Claude direct access to 48+ comprehensive x32dbg debugging capabilities through natural language!
šÆ What is This?
This project connects x32dbg (Windows debugger) to Claude AI through the Model Context Protocol (MCP). You can:
Debug programs using natural language
Ask Claude to analyze functions, find crypto, set breakpoints
Get real-time debugging context and assistance
Automate reverse engineering workflows
Related MCP server: IDAssistMCP
š Quick Start
Prerequisites
x32dbg installed (download here)
Python 3.8+ (download here)
Visual Studio 2019+ with C++ support (for compiling plugin)
Claude Desktop or Claude Code (VSCode extension)
Installation
1. Build the Plugin
Just double-click build.bat - it handles everything!
# OR manually:
cmake -S . -B build32 -A Win32 -DBUILD_BOTH_ARCHES=OFF
cmake --build build32 --config ReleaseThe compiled plugin will be at: build/MCPx64dbg.dp32
2. Install the Plugin
Copy the plugin to your x32dbg plugins folder:
C:\Program Files\x64dbg\release\x32\plugins\MCPx64dbg.dp323. Setup Python MCP Server
# Install dependencies
pip install mcp requests
# Test the server
python mcp_server.py4. Configure Your Claude App
Console:
claude mcp add x32dbg python C:\Tools\mcp_server.py --transport stdio --env X64DBG_URL=http://127.0.0.1:8888ā ļø IMPORTANT: Claude Desktop and Claude Code (VSCode) use different configuration files!
Option A: Claude Desktop (Standalone App)
Edit: %APPDATA%\Claude\claude_desktop_config.json (Windows) or ~/Library/Application Support/Claude/claude_desktop_config.json (Mac/Linux)
{
"mcpServers": {
"x32dbg": {
"command": "python",
"args": ["C:\\path\\to\\x64dbgMCP\\mcp_server.py"],
"env": {
"X64DBG_URL": "http://127.0.0.1:8888",
"X64DBG_TIMEOUT": "30"
}
}
}
}Option B: Claude Code (VSCode Extension) ā You're probably using this!
Create .vscode/settings.json in your workspace:
{
"claude.mcpServers": {
"x32dbg": {
"command": "python",
"args": ["C:\\path\\to\\x64dbgMCP\\mcp_server.py"],
"env": {
"X64DBG_URL": "http://127.0.0.1:8888",
"X64DBG_TIMEOUT": "30"
}
}
}
}Then restart VSCode completely!
ā Verify Installation
Start x32dbg
Check plugin loaded: Press
ALT+Lto open logs, you should see:[MCP] Plugin loading... [MCP] HTTP server started on port 8888Test HTTP API: Open browser to
http://127.0.0.1:8888/statusStart Claude Desktop and verify x32dbg server appears in MCP settings
š Usage Examples
Basic Debugging
You: "Set a breakpoint at 0x401000 and show me the disassembly"
Claude: [Uses set_breakpoint and disassemble_at tools]Function Analysis
You: "Analyze the current function"
Claude: [Uses analyze_function prompt, gets registers, disassembles, analyzes flow]Memory Operations
You: "Read 32 bytes from ESP and show me the stack contents"
Claude: [Uses get_register("esp") and read_memory tools]Automation
You: "Find all calls to GetProcAddress in the current module"
Claude: [Uses get_modules, searches memory, sets breakpoints]š§ Available Tools (48+)
š See API-REFERENCE.md for complete API documentation
Core Operations (8)
Status & control, command execution, debugging control
Register read/write, memory read/write
Disassembly, module listing
Pattern & Memory Search (3)
find_pattern_in_memory- Search for byte patternsmemory_search- Find all occurrencessearch_and_replace_pattern- Pattern replacement
Symbol & Analysis (15)
get_symbols- List functions, imports, exportsset_label/get_label/delete_label/get_all_labels- Label managementset_comment/get_comment/delete_comment/get_all_comments- Comment managementresolve_label- Resolve label names to addresses
Stack Operations (3)
stack_push/stack_pop/stack_peek- Stack manipulation
Function Operations (4)
add_function/get_function_info/delete_function/get_all_functions
Bookmark Operations (4)
set_bookmark/check_bookmark/delete_bookmark/get_all_bookmarks
Assembler Operations (2) š
assemble_instruction- Assemble to bytecodeassemble_and_patch- Assemble and write to memory
CPU Flag Operations (3) š
get_cpu_flag/set_cpu_flag- Read/write individual flagsget_all_cpu_flags- Get all flags at once (ZF, OF, CF, PF, SF, TF, AF, DF, IF)
Miscellaneous Utilities (3)
parse_expression- Evaluate complex expressionsresolve_api_address- Find API addresses in debuggeeresolve_label_address- Label resolution
šØ MCP Resources
Resources provide Claude with contextual information:
debugger://status- Current debugging statedebugger://modules- Loaded modules list
š MCP Prompts
Prompts guide Claude for common tasks:
analyze_function- Start function analysis workflowfind_crypto- Search for crypto patternstrace_execution- Setup execution tracing
šļø Architecture
Claude Desktop/VSCode
ā (MCP Protocol)
mcp_server.py (Python)
ā (HTTP REST API)
MCPx64dbg.dp32 (C++ Plugin)
ā (x64dbg SDK)
x32dbg.exeš Troubleshooting
Plugin Not Loading
Check logs (ALT+L in x32dbg)
Ensure plugin is in correct folder
Try restarting x32dbg
HTTP Server Not Responding
Check port 8888 is not in use:
netstat -ano | findstr 8888Check firewall settings
Try changing port in plugin (recompile needed)
MCP Server Can't Connect
Ensure x32dbg is running with plugin loaded
Test manually:
curl http://127.0.0.1:8888/statusCheck X64DBG_URL environment variable
Request Timeout Errors
If you see "Request timed out - is x32dbg running?" frequently:
Cause: Some debugging operations (like run, step_over, setting breakpoints while running) can take longer than the default 30-second timeout, especially if the debugger needs to run to a distant breakpoint.
Solution: Increase the timeout via environment variable:
{
"claude.mcpServers": {
"x32dbg": {
"command": "python",
"args": ["C:\\path\\to\\x64dbgMCP\\mcp_server.py"],
"env": {
"X64DBG_URL": "http://127.0.0.1:8888",
"X64DBG_TIMEOUT": "60"
}
}
}
}Adjust the timeout value (in seconds) based on your needs:
Default:
30seconds (general debugging)Recommended:
60seconds (complex analysis)Long runs:
120+seconds (waiting for rare events)
Build Errors
Ensure Visual Studio is installed with C++ support
Ensure CMake is in PATH
Check
deps/pluginsdkfolder exists
š¦ Repository Structure
x64dbgMCP/
āāā build.bat # One-click build script
āāā mcp_server.py # Python MCP server (950+ lines, 48 tools)
āāā src/
ā āāā MCPx64dbg.cpp # C++ plugin main file (modular, 650+ lines)
āāā include/ # Modular handler headers (8 files)
ā āāā mcp_common.h # Common utilities and helpers
ā āāā mcp_handlers_pattern.h # Pattern/memory search
ā āāā mcp_handlers_annotation.h # Symbols/labels/comments
ā āāā mcp_handlers_stack.h # Stack operations
ā āāā mcp_handlers_function.h # Functions/bookmarks
ā āāā mcp_handlers_misc.h # Misc utilities
ā āāā mcp_handlers_assembler.h # Assembler operations
ā āāā mcp_handlers_flags.h # CPU flags
āāā deps/
ā āāā pluginsdk/ # x64dbg SDK headers
āāā build/
ā āāā MCPx64dbg.dp32 # Compiled plugin
āāā CMakeLists.txt # Build configuration
āāā API-REFERENCE.md # Complete API documentation
āāā MCPx64dbg_old.cpp.backup # Original version (backup)
āāā README.md # This filešÆ Features
ā Full x64dbg SDK Integration - 48+ tools covering all major x64dbg APIs ā Modular Architecture - Clean, maintainable C++ with organized header files ā Complete Debugging Toolkit - Memory, registers, breakpoints, symbols, labels, comments ā Advanced Pattern Search - Find byte patterns, search and replace ā Stack Operations - Direct stack manipulation ā Function Analysis - Define, analyze, and manage functions ā Assembler Support - Assemble instructions, patch memory on the fly ā CPU Flag Control - Read/write all CPU flags (ZF, OF, CF, PF, SF, TF, AF, DF, IF) ā JSON Responses - Structured data for Claude ā MCP Resources & Prompts - Contextual information and guided workflows ā Cross-Process - No DLL injection needed ā Safe - Comprehensive error handling ā Fast - Direct x64dbg SDK access
š¤ Contributing
This is a comprehensive full-featured implementation of x64dbgMCP with major improvements:
Version 3.0 (Current)
⨠48+ MCP tools (up from 16)
šļø Modular C++ architecture with 8 organized header files
š Complete x64dbg SDK integration - pattern search, symbols, labels, comments, stack, functions, bookmarks, assembler, CPU flags
š Comprehensive API documentation
šÆ Production-ready with robust error handling
š Assembler support - assemble & patch on the fly
š CPU flag control - read/write all CPU flags
Version 2.0 (Previous)
63% code reduction in C++ plugin
Complete Python rewrite with proper MCP support
Added resources and prompts
Version 1.0 (Original)
Basic x64dbg MCP integration
š License
MIT License - Do whatever you want with this!
š Credits
Original idea from Wasdubya/x64dbgMCP
Built for the x64dbg debugger
Uses Anthropic's Model Context Protocol (MCP)
š Links
x64dbg - The debugger
MCP Documentation - Protocol docs
Claude Desktop - Get Claude
Happy Reversing! š
This server cannot be deployed
Maintenance
Related MCP Connectors
Hosted MCP server connecting claude.ai, ChatGPT and other AI apps to your own computer
- QuallaaOAuthcom.quallaa
Talk to your public-facing AI from any MCP client ā Claude, ChatGPT, Cursor, Cline, Windsurf.
Use AI models for chat, image, and video generation from Claude Code and other MCP hosts.
Enable secure connectivity between Sentry issues and debugging data, and LLM clients, using a Model Context Protocol (MCP) server.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceEnables AI-assisted reverse engineering and debugging through x64dbg integration. Provides 40+ tools for breakpoint management, memory operations, register manipulation, code analysis, process control, and advanced debugging features.22-
- AlicenseNot gradedqualityDmaintenanceEnables LLM clients like Claude to interact with IDA Pro for binary analysis, decompilation, cross-references, patching, and more via 41 MCP tools, 8 resources, and 7 guided prompts.52MIT
- AlicenseNot gradedqualityDmaintenanceConnects AI agents to IDA Pro and x64dbg for unified static and dynamic reverse engineering, enabling coordinated analysis, debugging, and patch planning through a local MCP daemon.15MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI assistants to control the x64dbg debugger through natural language, providing tools for breakpoints, memory, disassembly, tracing, PE dumping, and anti-debug bypass, all locally via stdio.123MIT