PluginBench
MCP Server
Active
MIT

io.github.bromoket/x64dbg MCP Server

io.github.bromoket/x64dbg

AI-powered reverse engineering and debugging for x64dbg—23 tools to control breakpoints, memory, disassembly, and anti-debug bypasses via plain English.

What is the io.github.bromoket/x64dbg MCP server?

The x64dbg MCP Server is a bridge that lets Claude, Cursor, and other AI clients control the x64dbg debugger through natural language. It exposes 23 tools across 153 REST endpoints—from setting breakpoints and reading memory to disassembling code, tracing execution, and dumping PE files—all running locally on 127.0.0.1 with no data leaving your machine.

This server connects your AI assistant directly to x64dbg, letting you debug and reverse-engineer binaries by talking in plain English instead of manually scripting. Set breakpoints, inspect memory, disassemble functions, trace execution, search for patterns, bypass anti-debug checks, and dump modules—all without touching the GUI. Ideal for analyzing VMProtect'd code, finding anti-cheat logic, decoding obfuscated strings, and mapping detection routines.

How to install io.github.bromoket/x64dbg

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • X64DBG_MCP_HOST

    Host where the x64dbg plugin REST API listens

  • X64DBG_MCP_PORT

    Port where the x64dbg plugin REST API listens

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "x64dbg": {
      "command": "npx",
      "args": [
        "-y",
        "x64dbg-mcp-server"
      ],
      "env": {
        "X64DBG_MCP_HOST": "<YOUR_X64DBG_MCP_HOST>",
        "X64DBG_MCP_PORT": "<YOUR_X64DBG_MCP_PORT>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • Control — Run, step, pause, execute raw commands, run scripts, and evaluate expressions
  • CPU & Memory — Read/write registers (including AVX-512), read/write/allocate/protect memory, and inspect memory map
  • Stack — Inspect call stack, SEH chain, and return addresses
  • Code Analysis — Disassemble, assemble, find xrefs, analyze basic blocks, generate CFG, and detect loops
  • Breakpoints & Tracing — Set software/hardware/memory/conditional/logging breakpoints, batch operations, and access trace logs
  • Symbols & Search — Manage labels, comments, bookmarks; perform AOB pattern and string scanning
  • Process & System — Inspect threads/TEB, handles, TCP connections, PEB; hide debugger and bypass anti-debug checks
  • Patching & Dumping — Apply byte patches, dump PE files, fix import address tables, and patch exports

Use cases

  • Trace and analyze VMProtect'd or obfuscated code by setting breakpoints and stepping through execution in natural language
  • Find and disable anti-cheat or anti-debug mechanisms by searching for patterns and bypassing detection logic
  • Dump and repair packed or protected binaries, fixing import tables and exporting modified modules
  • Decode XOR'd strings and class names by reading memory and searching for patterns across the target process
  • Map detection and validation logic by tracing execution, inspecting registers, and analyzing disassembled code

io.github.bromoket/x64dbg MCP server FAQ

What is the x64dbg MCP Server?

It's a bridge that lets AI assistants like Claude control x64dbg through natural language. You install a C++ plugin inside x64dbg and a TypeScript server on your machine; they communicate over stdio, exposing 23 debugging and reverse-engineering tools.

Is it free?

Yes. The server is MIT-licensed and open-source. x64dbg itself is also free and open-source.

How do I install it in Cursor or Claude?

Download the plugin DLL from the latest release and drop it in your x64dbg plugins folder. Then add the server config to your client's MCP settings: `{ "command": "npx", "args": ["-y", "x64dbg-mcp-server"] }`. Full per-client instructions are in the docs.

Does it require authentication?

No by default. For extra security against other local processes, you can set an optional auth token in the plugin's Settings and pass it via the `X64DBG_MCP_TOKEN` environment variable.

Does any data leave my machine?

No. The plugin binds to 127.0.0.1 only, and the server uses stdio. All traffic stays on localhost—no remote access, no telemetry, no data leaves your machine.

What can I do with it?

Set breakpoints, read/write memory, disassemble code, trace execution, search for byte patterns, dump PE files, fix imports, bypass anti-debug checks, inspect threads and handles, and more—all by asking your AI assistant in plain English.

README (reference)

Source of truth, from the repository.

x64dbg MCP Server

npm version MCP Registry License: MIT

Drive x64dbg with your AI. Talk to Claude, Cursor, Windsurf, Cline, or any MCP client in plain English and it sets breakpoints, reads memory, disassembles, traces, dumps PEs, and bypasses anti-debug — live, inside the debugger.

23 mega-tools over 153 REST endpoints, fully typed with Zod. A C++ plugin runs inside x64dbg; a tiny TypeScript server bridges it to your client over stdio. Everything stays on 127.0.0.1 — nothing leaves your machine.

Latest — v2.3.0

  • Hardened & crash-proof. A malformed HTTP request can no longer crash x64dbg; the plugin server drains connections cleanly on stop and ships an optional auth token (CORS is locked down).
  • Real data from more tools. imports/exports, symbols search/list, patches list, and strings now return actual parsed results instead of pointing you at a GUI view.
  • Live trace status. New /api/trace/status (+ tracing status) reports whether a trace is running, and the exception/trace tools now honor every parameter they accept.
  • Plus the v2.2.x fixes: x32dbg loads on current snapshots, and requests no longer time out on long operations.

Download the v2.3.0 plugins →


What it looks like

"Set a breakpoint on CreateFileW and run the program"
"Disassemble the current function and explain what it does"
"Search for 48 8B ?? 48 85 C0 in the main module and disassemble the hits"
"Hide the debugger and bypass the anti-debug checks"
"Trace into the VM dispatcher and log every instruction to a file"
"Dump the main module to disk and fix the import table"

Real use: tracing VMProtect'd code, finding anti-cheat scanner threads, decoding XOR'd class names, mapping detection logic — all by asking, no manual scripting.

Install

1 · Plugin (inside x64dbg)

Download x64dbg_mcp.dp64 / .dp32 from the latest release and drop them in:

x64dbg/x64/plugins/x64dbg_mcp.dp64    ← 64-bit targets
x64dbg/x32/plugins/x64dbg_mcp.dp32    ← 32-bit targets

…or build + install it yourself (auto-detects your x64dbg — no path editing):

.\build.ps1 -Install

Start x64dbg; the log shows [MCP] x64dbg MCP Server started on 127.0.0.1:27042.

2 · Server (your AI client)

No install — just point your client at npx. Claude Code:

{
  "mcpServers": {
    "x64dbg": {
      "type": "stdio",
      "command": "cmd",
      "args": ["/c", "npx", "-y", "x64dbg-mcp-server"]
    }
  }
}

Claude Desktop / Cursor / Windsurf / Cline use the same block without the cmd /c wrapper: { "command": "npx", "args": ["-y", "x64dbg-mcp-server"] }. Full per-client paths are in the reference.

3 · Go

Open a target in x64dbg and start talking to your assistant.

Tools at a glance

23 action-based tools spanning the whole debugger:

  • Control — run/step/pause, raw commands, scripts, expression eval
  • CPU & memory — registers (incl. AVX-512), read/write/alloc/protect, memory map
  • Stack — call stack, SEH chain, return addresses
  • Code analysis — disassemble, assemble, xrefs, basic blocks, CFG, loops
  • Breakpoints & tracing — software/hardware/memory/conditional/logging, batch, trace logs
  • Symbols & search — labels, comments, bookmarks, AOB pattern + string scan
  • Process & system — threads/TEB, handles, TCP, PEB, anti-debug hide
  • Patching & dumping — byte patches, PE dump, IAT fix, patch export

Every tool, action, and endpoint is documented in docs/REFERENCE.md.

Links

Security

The plugin binds to 127.0.0.1 only; the server talks pure stdio. All traffic stays on localhost — no remote access, no telemetry, no data leaves your machine. For defense against other local processes, set a token in the plugin's Settings and pass it via X64DBG_MCP_TOKEN — every request must then carry it.

Author

bromo — GitHub. Built with Claude Code. MIT.

Related MCP servers

Product analytics for user flows: aha moments, retention, funnels, per-user dot plots. YC method.

1
Python
MIT
View repository →

AI browser tools with Chrome CDP. Navigate, screenshot, interact. Multi-provider failover.

5
TypeScript
MIT
View repository →

Give your AI agent a cloud browser it can navigate, click, and extract data from.

3.4k
TypeScript
Apache-2.0
View repository →

Test web and mobile apps on real devices and browsers using natural language commands within your IDE.

145
TypeScript
AGPL-3.0
View repository →

Real-time Bitcoin regime-switch signals from three independent sensors. Free tier available.

TypeScript MCP server for Canvas LMS — 165 tools across 42 domains.

3
TypeScript
MIT
View repository →