PluginBench
MCP Server
Maintained
MIT

MCP Server for WinDbg Crash Analysis MCP Server

io.github.svnscha/mcp-windbg

AI-powered Windows crash dump analysis and kernel debugging via WinDbg/CDB.

What is the MCP Server for WinDbg Crash Analysis MCP server?

The MCP Server for WinDbg Crash Analysis is a Model Context Protocol server that bridges AI models with Windows debuggers (CDB and KD) to analyze crash dumps, debug live user-mode processes, and perform kernel debugging in natural language. It wraps WinDbg/CDB commands so an LLM can run real debugger operations and reason about the output for root-cause analysis.

This server lets you analyze Windows crash dumps, debug live processes, and troubleshoot kernel issues by describing what you want in natural language. An AI assistant drives WinDbg or KD commands, interprets the output, and helps you find the root cause of crashes, hangs, and driver issues. It supports batch triage of multiple dumps, remote debugging over TCP/pipes, kernel debugging over KDNET, and can redact sensitive data before output leaves your machine.

How to install MCP Server for WinDbg Crash Analysis

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • CDB_PATH

    Custom path to cdb.exe (optional)

  • _NT_SYMBOL_PATH

    Symbol path for Windows debugging (optional, defaults to Microsoft symbol server)

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "mcp-windbg": {
      "command": "uvx",
      "args": [
        "mcp-windbg"
      ],
      "env": {
        "CDB_PATH": "<YOUR_CDB_PATH>",
        "_NT_SYMBOL_PATH": "<YOUR__NT_SYMBOL_PATH>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • list_dumps — List crash dump files in a directory
  • open_cdb_dump — Open and triage a crash dump
  • open_cdb_remote — Attach to a user-mode remote debug server (-remote)
  • open_kd_session — Attach to a kernel target (-k, KDNET / named pipe / serial)
  • run_cdb_command — Run a command on a user-mode session
  • run_kd_command — Run a command on a kernel session
  • close_cdb_session — Close a user-mode session
  • close_kd_session — Close a kernel session (resumes the target machine)
  • send_ctrl_break — Break into a running live session

Use cases

  • Analyze a Windows crash dump to find the faulting frame and root cause of an exception
  • Debug a live user-mode process by breaking in and inspecting state over a remote connection
  • Triage multiple crash dumps in a folder to find common signatures and patterns
  • Debug kernel-mode issues, driver bugchecks, and boot-time problems over KDNET or named pipes
  • Run debugger commands and interpret output via natural language prompts from an AI assistant

MCP Server for WinDbg Crash Analysis MCP server FAQ

What is the MCP Server for WinDbg Crash Analysis?

It is a Python wrapper around Windows debuggers (CDB and KD) that lets AI models like Claude run real debugger commands and reason about crash dumps, live process debugging, and kernel debugging through natural language prompts.

Is it free?

Yes, it is open-source under the MIT license and available on PyPI as `mcp-windbg`.

What are the system requirements?

Windows with Debugging Tools for Windows (or WinDbg from the Microsoft Store), Python 3.10+, and an MCP-compatible client like Claude Code, GitHub Copilot, Cursor, or Windsurf.

How do I install it in Claude Code or VS Code?

Install via `pip install mcp-windbg`, then register it with your client using the provided configuration (e.g., `claude mcp add mcp-windbg` for Claude Code, or JSON config for VS Code/Copilot).

Do I need authentication or API keys?

No, it runs locally on your Windows machine and does not require external authentication. You only need the Windows Debugging Tools installed.

Can it redact sensitive data?

Yes, you can provide a `--filter-script` to redact PII and secrets from tool arguments and output before they leave your machine.

README (reference)

Source of truth, from the repository.

MCP Server for WinDbg Crash Analysis

CI Docs PyPI License: MIT Platform: Windows Python 3.10+

A Model Context Protocol server that bridges AI models with WinDbg for crash dump analysis, user-mode remote debugging, and kernel debugging.

<!-- mcp-name: io.github.svnscha/mcp-windbg -->

Overview

This server drives the Windows debuggers - CDB for user mode (dumps and -remote) and KD for kernel targets (-k) - so you can debug in natural language: "Show me the call stack and explain this access violation" or "Open a kernel session and tell me which driver bugchecked."

It is not a magical auto-fix. It is a Python wrapper around cdb.exe / kd.exe that lets an LLM run real debugger commands and reason about the output.

Features

  • Crash dump analysis - open a .dmp/.mdmp/.hdmp and get automated triage (!analyze -v, stacks, modules, threads) in a single call.
  • User-mode remote debugging - attach to a live cdb/WinDbg debug server (-remote) over TCP, a named pipe, or COM, and break in on demand.
  • Kernel debugging - attach to a kernel target (-k, driven by kd.exe) over KDNET, a named pipe, or serial; the server waits for the target and breaks in for you.
  • Run any WinDbg/KD command - drive an open session with arbitrary commands (kb, !process 0 0, !heap, lm, ...) described in natural language.
  • Session ids - every open returns a session id; several sessions (dumps, remote, kernel) can be open at once and are addressed independently.
  • Resilient live sessions - per-call timeouts, and a slow live command that outruns its timeout is broken into with CTRL+BREAK and the session resynchronized instead of wedging.
  • Multi-dump triage - discover and compare many dumps across a directory.
  • Text filter hooks - a --filter-script can redact PII/secrets from tool arguments and output before they leave the machine.
  • stdio or HTTP - run locally over stdio, or as a streamable-HTTP service you drive from another machine.

Use cases

You haveYou want toGuide
A .dmp from a crashRoot-cause it: exception, faulting frame, why it happenedAnalyze a crash dump
A live user-mode process (via cdb -server)Break in and inspect a hang or live stateDebug a remote target
A KD-enabled machine or VMDebug drivers, bugchecks, and boot-time issuesDebug a kernel target
A folder full of dumpsTriage the batch and find the common signatureTriage multiple dumps
A debugging host, but you work elsewhereDrive it over HTTP from another machineDebug from another machine
Dumps with secrets or PIIScrub tool output before it leaves the boxRedact sensitive data

Tools

Every open_* tool returns an opaque session_id (e.g. cdb-1a2b3c4d); pass it to the matching run_*, close_*, and send_ctrl_break calls. User-mode targets (dumps and -remote) run under cdb.exe; kernel targets run under kd.exe.

ToolPurpose
list_dumpsList crash dump files in a directory
open_cdb_dumpOpen and triage a crash dump
open_cdb_remoteAttach to a user-mode remote debug server (-remote)
open_kd_sessionAttach to a kernel target (-k, KDNET / named pipe / serial)
run_cdb_commandRun a command on a user-mode session
run_kd_commandRun a command on a kernel session
close_cdb_sessionClose a user-mode session
close_kd_sessionClose a kernel session (resumes the target machine)
send_ctrl_breakBreak into a running live session

Parameters, timeouts, and the built-in triage prompts are in the tools reference.

Quick start

Prerequisites

[!TIP] In enterprise environments, MCP server usage might be restricted by organizational policies. Check with your IT team about AI tool usage and ensure you have the necessary permissions before proceeding.

Install

pip install mcp-windbg

Configure your client. The two most common setups are below; see the client configuration guide for Claude Desktop, Copilot CLI, Autohand Code, HTTP, and from-source.

Claude Code - register the server from the command line:

claude mcp add mcp-windbg -s user -e _NT_SYMBOL_PATH="SRV*C:\Symbols*https://msdl.microsoft.com/download/symbols" -- python -m mcp_windbg

VS Code (GitHub Copilot) - press F1 and select MCP: Open User Configuration to enable it in every workspace:

{
    "servers": {
        "mcp_windbg": {
            "type": "stdio",
            "command": "python",
            "args": ["-m", "mcp_windbg"],
            "env": {
                "_NT_SYMBOL_PATH": "SRV*C:\\Symbols*https://msdl.microsoft.com/download/symbols"
            }
        }
    }
}

Restart your client, then start debugging:

Analyze the crash dump at C:\dumps\app.dmp
Connect to tcp:Port=5005,Server=192.168.0.100 and show me the current thread state
Open a kernel session on net:port=50000,key=1.2.3.4, run !analyze -v, and tell me which driver bugchecked

Server options (--cdb-path, --kd-path, --symbols-path, --filter-script, --transport, ...) are documented in the command-line reference.

Documentation

svnscha.github.io/mcp-windbg

TopicDescription
Getting startedSetup and your first crash dump analysis
Analyze a crash dumpRoot-cause an exception: faulting frame, why it happened
Debug a remote targetBreak into a live user-mode process and inspect a hang
Debug a kernel targetDrivers, bugchecks, and boot-time issues over KDNET or a pipe
Triage multiple dumpsScan a folder and find the common signature
Debug from another machineRun the server over HTTP and drive it remotely
Redact sensitive dataScrub secrets from tool output before it leaves the box
ReferenceTools, prompts, CLI options, and client configuration
TroubleshootingCommon issues and solutions
DevelopmentRun from a local checkout and point a client at the dev build

Blog

Read about the development journey: The Future of Crash Analysis: AI Meets WinDbg

License

MIT

Related MCP servers

Read, create, and modify Microsoft Word documents

0
Python
MIT
View repository →
CHchomptron logo

chomptron

Active

Generate a recipe from ingredients on hand, with optional dietary restrictions. Free.

0
JavaScript
MIT
View repository →

Compile a used-vehicle report from a VIN or listing. Free preview; unlock full writeups for $12.99.

View repository →
SPspendtron logo

spendtron

Active

Finds the GitHub Actions workflow eating your CI bill and suggests fix diffs, verified against runs.

0
JavaScript
MIT
View repository →
VEVectr logo

Vectr

Active

Semantic codebase search + persistent working memory for AI code editors. Local, no API key.

2
Python
MIT
View repository →

Transcript-based audio editing: transcribe audio, edit by word ID, export edited audio.