x64dbg-MCP Server
Native x64dbg plugin exposing full debugger control for AI-assisted reverse engineering via MCP.
- Skill Road
- x64dbg-MCP Server
Categories
Description
The x64dbg-MCP Server is a native plugin for x64dbg, the popular open-source debugger for Windows binaries. According to the README in the official repository github.com/duty1g/x64dbg-mcp-server, the plugin exposes "the debugger's full functionality over HTTP" for the Model Context Protocol, letting an MCP-capable AI assistant control x64dbg programmatically: setting breakpoints, stepping through code, reading memory, dumping registers, and more. The plugin is developed by duty1g, a developer focused on red teaming and reverse engineering; it is not an official product of the x64dbg core team but an independent community plugin that runs directly inside x64dbg. For Skill Road this is a distinct, previously uncovered use case: while existing coding and browser-automation servers such as Playwright MCP or Chrome DevTools MCP target web applications, the x64dbg-MCP Server targets malware analysis, security research, and reverse engineering of compiled Windows programs at the machine-code level.
Feature set and tools
Per the README, the plugin provides 84 MCP tools and 22 event callbacks for full debugger control. The tool range spans basic functions such as loading an executable, attaching to a running process, or executing arbitrary x64dbg commands, through to deep analysis capabilities during an active debug session: disassembling single instructions or entire functions, reading and patching memory, reading and setting registers, breakpoints of every kind (software, hardware, conditional, exception, memory), thread and call-stack management, module/import/export analysis, wildcard pattern scanning, string extraction, cross-reference lookups, and specialized tools such as detecting the original entry point of packed executables or reading the structured-exception-handler chain and the process environment block. This effectively covers the whole workflow a human would otherwise perform manually inside the x64dbg UI, and makes it accessible to an AI assistant through natural language.
Architecture and installation
According to the vendor, the plugin is written in the Zig programming language, has no external runtime dependencies, and ships as a single binary for both x32 and x64 architectures of x64dbg. Installation consists of copying the contents of the dist/ folder from a release into the x64dbg root directory; on the next launch, x64dbg loads the plugin automatically and starts a local HTTP server, by default on port 9094 for the x64 build and port 9095 for the x32 build. Both Streamable HTTP and SSE are supported as transports, so both newer and legacy MCP clients can connect. Building the plugin from source requires Zig 0.16-dev or later per the README; builds can be produced from Windows, WSL, Linux, or macOS, though only a Windows plugin is shipped, since x64dbg itself only runs on Windows.
Authentication and security notes
Per the documentation, every request to the MCP server requires a Bearer token that is auto-generated on first run; requests without a valid token are rejected with HTTP 401. A configuration dialog in the plugins menu lets you change the bind address, port, and token, with the server automatically restarting after saving. The vendor explicitly notes in the README that communication runs over unencrypted HTTP and that the server should therefore not be exposed to untrusted networks, since it provides full control over the debugged process, including memory access and code execution. A dedicated disclaimer section states that the tool is intended solely for legitimate reverse engineering, malware analysis, security research, and educational purposes, and that proper authorization is always required before analyzing third-party software.
License, maturity, and fit
The repository is MIT licensed and therefore fully open source. Immediately before this entry was created, the GitHub API reported exactly 2,029 stars and 206 forks at current release v1.4 from 2026-09-17; these figures are a point-in-time popularity snapshot, not a security or quality guarantee. The server itself is free and requires no registration or account, only x64dbg as the target software and, for building from source, Zig as the build tool. Because the tool grants full process control over debugged programs, it clearly targets technically proficient users from security research, red teaming, and malware analysis rather than general software development.
Who benefits from the x64dbg-MCP Server?
The server is particularly useful for reverse engineers, malware analysts, and security researchers who already use x64dbg as a standard tool and want an AI assistant to support or automate recurring analysis steps — for example, finding the original entry point of packed samples, systematically scanning memory for patterns, or logging a walk through a control flow. It is less suited to general application development or to users without experience in low-level debugging, since the exposed tools give direct, unfiltered access to process memory and code execution, and misreading the output can quickly lead to incorrect analysis conclusions.
Requirements
x64dbg on Windows (x32 or x64) and an MCP-capable client; building from source additionally requires Zig 0.16-dev or later.
Installation instructions
Copy the contents of the dist/ folder from a release into the x64dbg root directory, launch x64dbg, and store the Bearer token generated on first run as an Authorization header in the MCP client. Only expose the server locally or on trusted networks, since the connection is unencrypted.
Authentication
Bearer token authentication, auto-generated on first run and required on every request; rotatable via the configuration dialog in the plugins menu.
Required access permissions
Full access to the debugged process: reading and writing memory, changing registers, setting breakpoints, executing code, and pausing or terminating processes.
Transmitted or stored data
Tool calls access the memory and state of the locally running x64dbg process directly; results return to the connected MCP client over unencrypted HTTP.
Security risks
An unencrypted HTTP connection, full process control including memory access and code execution, and exposure on untrusted networks can compromise the debugged system. According to the vendor, use only for legitimate reverse engineering with proper authorization.
License and costs
- License
- MIT
- Cost
- free
The plugin is MIT licensed and free, with no registration or account required. It requires your own installation of x64dbg.
Alternatives
Not recorded yet.
At a glance
- Provider
- duty1g
- Status
- Community
- Deployment
- Local
- Current version
- v1.4
- GitHub stars
- 2,029
- Last reviewed
- 21.09.2026
Repository and documentation
Categories
Supported clients
Related guides
Guides and background related to this entry.
Set up the Fakechat plugin for Claude Code
Install the Fakechat plugin, start Claude Code with the channels flag, and test messages and files through a local browser interface.
30.09.2026
Setting up Laravel Boost
Install Laravel Boost in a Laravel application and connect it to Claude Code, Cursor, or Codex.
29.09.2026
Set up the Azure DevOps MCP Server
Start Set up the Azure DevOps MCP Server with verified links, minimal permissions, and a safe first test.
25.09.2026
Installing a Claude Code plugin
Installing a plugin from the official Anthropic marketplace – using the Code Review plugin as an example.
24.09.2026