
A Windows runtime analysis toolkit combining memory scanning, debugging, automation, and AI-friendly APIs.
Cortex v1.0.0 ships as a single portable Windows application: cortex.exe. The x64 and x86 instrumentation runtimes live in the runtime folder and are selected automatically for each target. Nothing else has to be installed (no Qt, no Visual C++ runtime).
Download the archive:
cortex-v1.0.0-windows-portable.zip
Extract the whole archive into a normal, writable folder, for example:
C:\Cortex\
Do not move cortex.exe on its own. Keep the runtime folder next to the executable.
Run:
.\cortex.exe
Help:
.\cortex.exe --help
Version:
.\cortex.exe --version
Persistent MCP server over stdio (targetless; attach from the AI client):
.\cortex.exe mcp
Attach MCP to a PID or a process at startup:
.\cortex.exe mcp --pid 1234
.\cortex.exe mcp --process game.exe
Also expose the low-level primitive tools:
.\cortex.exe mcp --tools all
Other built-in commands:
.\cortex.exe probe --pid 1234
.\cortex.exe diagnose --pid 1234
.\cortex.exe analyze <directory>
.\cortex.exe symbolize [options]
.\cortex.exe inject <target> [dll]
cortex.exe The Cortex application (desktop UI and CLI/MCP modes).
runtime\x64\cortex_core.dll Instrumentation runtime for 64-bit targets.
runtime\x86\cortex_core.dll Instrumentation runtime for 32-bit targets.
runtime\x86\cortex_runtime_helper.exe Private helper used automatically for 32-bit targets.
You never choose between x64 and x86: Cortex reads the target's
architecture and uses the matching runtime, including for
"cortex.exe inject <pid>".
README.md, CHANGELOG.md, LICENSE, docs Documentation, history, license and technical guides.
Use Cortex only on software and systems you own or are authorized to inspect. Anti-cheat bypass, unauthorized access and interference with online services are outside the scope of this project.