x64dbg-MCP Server

Native x64dbg plugin exposing full debugger control for AI-assisted reverse engineering via MCP.

Description

The x64dbg-MCP Server is a native plugin for x64dbg, the popular open-source debugger for Windows binaries. According to the README in the official repository github.com/duty1g/x64dbg-mcp-server, the plugin exposes "the debugger's full functionality over HTTP" for the Model Context Protocol, letting an MCP-capable AI assistant control x64dbg programmatically: setting breakpoints, stepping through code, reading memory, dumping registers, and more. The plugin is developed by duty1g, a developer focused on red teaming and reverse engineering; it is not an official product of the x64dbg core team but an independent community plugin that runs directly inside x64dbg. For Skill Road this is a distinct, previously uncovered use case: while existing coding and browser-automation servers such as Playwright MCP or Chrome DevTools MCP target web applications, the x64dbg-MCP Server targets malware analysis, security research, and reverse engineering of compiled Windows programs at the machine-code level.

Feature set and tools

Per the README, the plugin provides 84 MCP tools and 22 event callbacks for full debugger control. The tool range spans basic functions such as loading an executable, attaching to a running process, or executing arbitrary x64dbg commands, through to deep analysis capabilities during an active debug session: disassembling single instructions or entire functions, reading and patching memory, reading and setting registers, breakpoints of every kind (software, hardware, conditional, exception, memory), thread and call-stack management, module/import/export analysis, wildcard pattern scanning, string extraction, cross-reference lookups, and specialized tools such as detecting the original entry point of packed executables or reading the structured-exception-handler chain and the process environment block. This effectively covers the whole workflow a human would otherwise perform manually inside the x64dbg UI, and makes it accessible to an AI assistant through natural language.

Architecture and installation

According to the vendor, the plugin is written in the Zig programming language, has no external runtime dependencies, and ships as a single binary for both x32 and x64 architectures of x64dbg. Installation consists of copying the contents of the dist/ folder from a release into the x64dbg root directory; on the next launch, x64dbg loads the plugin automatically and starts a local HTTP server, by default on port 9094 for the x64 build and port 9095 for the x32 build. Both Streamable HTTP and SSE are supported as transports, so both newer and legacy MCP clients can connect. Building the plugin from source requires Zig 0.16-dev or later per the README; builds can be produced from Windows, WSL, Linux, or macOS, though only a Windows plugin is shipped, since x64dbg itself only runs on Windows.

Authentication and security notes

Per the documentation, every request to the MCP server requires a Bearer token that is auto-generated on first run; requests without a valid token are rejected with HTTP 401. A configuration dialog in the plugins menu lets you change the bind address, port, and token, with the server automatically restarting after saving. The vendor explicitly notes in the README that communication runs over unencrypted HTTP and that the server should therefore not be exposed to untrusted networks, since it provides full control over the debugged process, including memory access and code execution. A dedicated disclaimer section states that the tool is intended solely for legitimate reverse engineering, malware analysis, security research, and educational purposes, and that proper authorization is always required before analyzing third-party software.

License, maturity, and fit

The repository is MIT licensed and therefore fully open source. Immediately before this entry was created, the GitHub API reported exactly 2,029 stars and 206 forks at current release v1.4 from 2026-09-17; these figures are a point-in-time popularity snapshot, not a security or quality guarantee. The server itself is free and requires no registration or account, only x64dbg as the target software and, for building from source, Zig as the build tool. Because the tool grants full process control over debugged programs, it clearly targets technically proficient users from security research, red teaming, and malware analysis rather than general software development.

Who benefits from the x64dbg-MCP Server?

The server is particularly useful for reverse engineers, malware analysts, and security researchers who already use x64dbg as a standard tool and want an AI assistant to support or automate recurring analysis steps — for example, finding the original entry point of packed samples, systematically scanning memory for patterns, or logging a walk through a control flow. It is less suited to general application development or to users without experience in low-level debugging, since the exposed tools give direct, unfiltered access to process memory and code execution, and misreading the output can quickly lead to incorrect analysis conclusions.

Requirements

x64dbg on Windows (x32 or x64) and an MCP-capable client; building from source additionally requires Zig 0.16-dev or later.

Installation instructions

Copy the contents of the dist/ folder from a release into the x64dbg root directory, launch x64dbg, and store the Bearer token generated on first run as an Authorization header in the MCP client. Only expose the server locally or on trusted networks, since the connection is unencrypted.

Authentication

Bearer token authentication, auto-generated on first run and required on every request; rotatable via the configuration dialog in the plugins menu.

Required access permissions

Full access to the debugged process: reading and writing memory, changing registers, setting breakpoints, executing code, and pausing or terminating processes.

Transmitted or stored data

Tool calls access the memory and state of the locally running x64dbg process directly; results return to the connected MCP client over unencrypted HTTP.

Security risks

An unencrypted HTTP connection, full process control including memory access and code execution, and exposure on untrusted networks can compromise the debugged system. According to the vendor, use only for legitimate reverse engineering with proper authorization.

License and costs

License
MIT
Cost
free

The plugin is MIT licensed and free, with no registration or account required. It requires your own installation of x64dbg.

Alternatives

Not recorded yet.

At a glance

Provider
duty1g
Status
Community
Deployment
Local
Current version
v1.4
GitHub stars
2,029
Last reviewed
21.09.2026

Repository and documentation

Categories

Supported clients