x64dbg-MCP Server
A native MCP plugin for the x64dbg debugger: the agent drives debugging over HTTP, sets breakpoints, steps through code, reads and patches memory
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Grants full control over the debugged process: memory reads and writes, patches, arbitrary debugger commands
- The server listens on all interfaces by default and access is guarded only by a token
Install
Manual install
{
"mcpServers": {
"x64dbg": {
"type": "http",
"url": "http://localhost:9094/",
"headers": {
"Authorization": "Bearer YOUR_TOKEN_HERE"
}
}
}
}MCP client config fragment for the streamable HTTP transport. Take the token from the plugin config dialog. Legacy clients can use SSE at http://localhost:9094/sse.
This is third-party code. Review the repository files before installing.
What it does
The plugin loads into the x64dbg debugger and exposes its functions over MCP on top of HTTP, so a connected agent drives debugging programmatically. Through a set of tools the agent loads an executable or attaches to a process, sets software and hardware breakpoints, steps through instructions, reads registers, the call stack, modules and threads, disassembles code and searches memory for strings. It has reverse-engineering tools: finding the entry point after unpacking, dumping a module, PE analysis, reading function arguments and tracing. Memory can be read and also patched, and every tool response carries a debugger state line and a queue of events. The plugin is written in Zig, builds into a single dependency-free binary for x32 and x64, supports streamable HTTP and SSE transports, and requires a Bearer token on every request.
Who it is for. For reverse engineers, malware analysts and security researchers who work in x64dbg and want to drive debugging through an agent.
Good fit when
- You need to run an x64dbg debugging session through an agent: breakpoints, stepping, reading registers and memory
- You need to unpack a sample: find the entry point, dump a module, analyze the PE
- You need to tie malware or binary analysis to the agent's reasoning
Not a fit when
- You do not have x64dbg or the task is not about Windows and native debugging
- You have no right to analyze the binary or process in question
Example request
Load calc.exe, break at the entry point and show the current registersLimitations
The plugin runs inside x64dbg, which means Windows, and needs the debugger installed. By default the server binds to 0.0.0.0, so when reachable over the network anyone with the token controls the debugger, so the token must be protected and the bind address limited. There is no npm or PyPI package: install by copying the built plugin into the x64dbg folder or by building from the Zig source. The tool grants full control over the debugged process, including memory writes and patches.
How to disable. Remove the plugin files from the x64dbg folder and restart the debugger. Delete the server entry from the MCP client configuration.
MCP
- Transport
- http, sse
- Authentication
- API key
Security check
- Grants full control over the debugged process: memory reads and writes, patches, arbitrary debugger commands
- The server listens on all interfaces by default and access is guarded only by a token
README in short
The README presents the plugin as a native MCP server for x64dbg that exposes debugger functions over HTTP and lets any compatible agent drive debugging: breakpoints, stepping, memory reads, register dumps and more. The plugin is built in Zig, dependency-free, into a single binary that cross-compiles to x32 and x64 from any host. It supports streamable HTTP and SSE transports and requires Bearer token authentication, generated on first run. The server starts automatically when x64dbg launches, and ports and token change in the config dialog. MIT licensed.
FAQ
Where do I get the token?
The token is generated on first run of the server and is required on every request. You can change the address, port and token in the config dialog from the Plugins menu.
Is this legal?
Debugging and reverse engineering are standard work in malware analysis, security research and inspecting your own binaries. Use the tool only on programs and processes you are allowed to analyze.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents