io.github.svnscha/mcp-windbg
Allows AI-powered crash dump analysis and remote debugging via WinDbg commands through natural language within GitHub Copilot.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@io.github.svnscha/mcp-windbgAnalyze the crash dump at C:\dumps\app.dmp"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
MCP Server for WinDbg Crash Analysis
A Model Context Protocol server that bridges AI models with WinDbg for crash dump analysis, user-mode remote debugging, and kernel debugging.
Overview
This server drives the Windows debuggers - CDB for user mode (dumps and -remote) and KD for kernel targets (-k) - so you can debug in natural language: "Show me the call stack and explain this access violation" or "Open a kernel session and tell me which driver bugchecked."
It is not a magical auto-fix. It is a Python wrapper around cdb.exe / kd.exe that lets an LLM run real debugger commands and reason about the output.
Related MCP server: WinDbg GUI MCP Server
Features
Crash dump analysis - open a
.dmp/.mdmp/.hdmpand get automated triage (!analyze -v, stacks, modules, threads) in a single call.User-mode remote debugging - attach to a live
cdb/WinDbg debug server (-remote) over TCP, a named pipe, or COM, and break in on demand.Kernel debugging - attach to a kernel target (
-k, driven bykd.exe) over KDNET, a named pipe, or serial; the server waits for the target and breaks in for you.Run any WinDbg/KD command - drive an open session with arbitrary commands (
kb,!process 0 0,!heap,lm, ...) described in natural language.Session ids - every open returns a session id; several sessions (dumps, remote, kernel) can be open at once and are addressed independently.
Resilient live sessions - per-call timeouts, and a slow live command that outruns its timeout is broken into with CTRL+BREAK and the session resynchronized instead of wedging.
Multi-dump triage - discover and compare many dumps across a directory.
Text filter hooks - a
--filter-scriptcan redact PII/secrets from tool arguments and output before they leave the machine.stdio or HTTP - run locally over stdio, or as a streamable-HTTP service you drive from another machine.
Use cases
You have | You want to | Guide |
A | Root-cause it: exception, faulting frame, why it happened | |
A live user-mode process (via | Break in and inspect a hang or live state | |
A KD-enabled machine or VM | Debug drivers, bugchecks, and boot-time issues | |
A folder full of dumps | Triage the batch and find the common signature | |
A debugging host, but you work elsewhere | Drive it over HTTP from another machine | |
Dumps with secrets or PII | Scrub tool output before it leaves the box |
Tools
Every open_* tool returns an opaque session_id (e.g. cdb-1a2b3c4d); pass it to the matching run_*, close_*, send_ctrl_break, and wait_for_break calls. User-mode targets (dumps and -remote) run under cdb.exe; kernel targets run under kd.exe.
Tool | Purpose |
| List crash dump files in a directory |
| Open and triage a crash dump |
| Attach to a user-mode remote debug server ( |
| Attach to a kernel target ( |
| Run a command on a user-mode session |
| Run a command on a kernel session |
| Close a user-mode session |
| Close a kernel session (resumes the target machine) |
| Break into a running live session |
| Wait for a target you resumed with |
Parameters, timeouts, and the built-in triage prompts are in the tools reference.
Quick start
Claude Code in enterprise environments: when managed settings define allowedMcpServers,
plugin-bundled MCP servers may be silently skipped (Claude Code issue #32882).
I recommend installing and registering the server manually,
then optionally adding the skills or agents plugin.
The server must still be permitted by your organization's MCP policy.
Prerequisites
Windows with Debugging Tools for Windows or WinDbg from the Microsoft Store, which ship
cdb.exeandkd.exe(auto-detected).Any MCP-compatible client (Claude Code, GitHub Copilot, Claude Desktop, Cursor, Windsurf, Cline, ...).
Python is not a prerequisite in itself. Each route below states what it needs.
Install in Claude Code
Install the server plugin if needed, then optionally add skills, agents, or both:
Plugin | Server | Included workflows |
| Launched by the plugin with uvx | MCP tools only |
| Uses the uvx plugin or your own MCP connection | Four optional skills |
| Uses the uvx plugin or your own MCP connection | Optional |
Server with uvx
The shortest path: two lines, no pip install, no MCP configuration to edit. Adds the
ten tools, with symbols preconfigured. Skills and agents are installed separately.
/plugin marketplace add svnscha/mcp-windbg
/plugin install mcp-windbg-uvx@mcp-windbgNeeds uv, which supplies uvx: winget install astral-sh.uv. The
plugin uses it to fetch the pinned server from PyPI on first use, so there is nothing else to
install. See the plugin README for symbols and options.
Registering the server yourself
If you would rather not use the plugin, or you already run the package:
pip install mcp-windbg
claude mcp add mcp-windbg -s user -e _NT_SYMBOL_PATH="SRV*C:\Symbols*https://msdl.microsoft.com/download/symbols" -- python -m mcp_windbgNeeds Python 3.10 or higher. Add either optional plugin below for guided workflows or an agent.
Skills for an existing server
After installing the uvx plugin or registering mcp-windbg yourself, optionally add the four skills:
/plugin marketplace add svnscha/mcp-windbg
/plugin install mcp-windbg-skills@mcp-windbgInvoke /mcp-windbg-skills:analyze-dump, /mcp-windbg-skills:debug-remote,
/mcp-windbg-skills:kernel-debug, or /mcp-windbg-skills:windbg-doctor.
This plugin uses your configured MCP connection and adds no server, runtime,
symbol settings, or crash-analyst agent. It works with a native executable,
Python installation, or HTTP service exposing the mcp-windbg tools.
Install this plugin alongside uvx for the server and skills together, or omit it to use just the tools.
When upgrading from a version that bundled skills, install this plugin to keep the workflows;
their invocation prefix changes from /mcp-windbg: to /mcp-windbg-skills:.
The server's built-in MCP prompts
remain available independently of these plugins. See the
plugin guide for updating or switching plugins.
Agents for an existing server
/plugin marketplace add svnscha/mcp-windbg
/plugin install mcp-windbg-agents@mcp-windbgAsk: "Use the mcp-windbg-agents:crash-analyst agent on C:\dumps\app.dmp". It investigates the dump and returns a verdict, evidence, and next steps through your existing MCP connection. It requires neither uvx nor the skills plugin. When upgrading from a version that bundled the agent, install this plugin to keep it.
Install in another client
pip install mcp-windbgNeeds Python 3.10 or higher. Then point the client at python -m mcp_windbg. For VS Code
(GitHub Copilot), press F1 and select MCP: Open User Configuration to enable it in every
workspace:
{
"servers": {
"mcp_windbg": {
"type": "stdio",
"command": "python",
"args": ["-m", "mcp_windbg"],
"env": {
"_NT_SYMBOL_PATH": "SRV*C:\\Symbols*https://msdl.microsoft.com/download/symbols"
}
}
}
}See the client configuration guide for Claude Desktop, Copilot CLI, Autohand Code, HTTP, and from-source setups.
Start debugging
Restart your client, then ask for what you want:
Analyze the crash dump at C:\dumps\app.dmp
Connect to tcp:Port=5005,Server=192.168.0.100 and show me the current thread state
Open a kernel session on net:port=50000,key=1.2.3.4, run !analyze -v, and tell me which driver bugcheckedServer options (--cdb-path, --kd-path, --symbols-path, --filter-script, --transport, ...) are documented in the command-line reference.
Documentation
Topic | Description |
Setup and your first crash dump analysis | |
Root-cause an exception: faulting frame, why it happened | |
Break into a live user-mode process and inspect a hang | |
Drivers, bugchecks, and boot-time issues over KDNET or a pipe | |
Scan a folder and find the common signature | |
Run the server over HTTP and drive it remotely | |
Scrub secrets from tool output before it leaves the box | |
Tools, prompts, CLI options, and client configuration | |
Common issues and solutions | |
Run from a local checkout and point a client at the dev build |
Blog
Read about the development journey: The Future of Crash Analysis: AI Meets WinDbg
License
MIT
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Live browser debugging for AI assistants — DOM, console, network via MCP.
Shared debugging memory for AI coding agents
Hunt zero-days by talking to binaries. 40+ tools. Hosted, OAuth + SSO, invite: hi@byteray.ai
Connects AI assistants to QCDatabase.AI for everyday construction quality-control work.
Related MCP Servers
- AlicenseNot gradedqualityNot gradedmaintenanceBridges AI models with WinDbg to analyze Windows crash dumps and perform remote debugging through natural language queries, enabling execution of debugger commands and automated crash analysis.-
- FlicenseNot gradedqualityDmaintenanceEnables AI assistants to interact with the WinDbg GUI through the Model Context Protocol using a PyKD-based plugin integration. It supports executing debugger commands, inspecting registers, reading memory, and performing automated crash analysis via natural language.4-
- AlicenseNot gradedqualityAmaintenanceEnables AI assistants to analyze binaries, debug processes, and inspect kernel state using Ghidra, x64dbg, WinDbg, and ILSpyCmd.7Apache 2.0
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to analyze Windows crash dumps by providing structured data on exceptions, threads, modules, and source context, with safe patch, build, and test execution.5MIT