IDA Pro와 언어 모델을 MCP를 통해 연결하는 AI 기반 리버스 엔지니어링 어시스턴트.
[!IMPORTANT] 대신 공식 Hex-Rays IDA MCP 서버를 사용하는 것을 권장합니다!
자세한 내용은 발표 블로그 글을 참고하세요.
IDA Pro에서 바이브 리버싱을 가능하게 해주는 간단한 MCP 서버입니다.
https://github.com/user-attachments/assets/6ebeaa92-a9db-43fa-b756-eececce2aca0
영상에 사용된 바이너리와 프롬프트는 mcp-reversing-dataset 저장소에서 확인할 수 있습니다.
idapyswitch를 사용하여 최신 Python 버전으로 전환하세요ida-pro-mcp --config를 실행하여 클라이언트용 JSON 설정을 확인하세요.참고: idalib가 전역적으로 활성화되어 있어야 하며 uv가 설치되어 있어야 합니다:```bash
uv run "C:\Program Files\IDA Professional 9.3\idalib\python\py-activate-idalib.py"
uv run "/Applications/IDA Professional 9.3.app/Contents/MacOS/idalib/python/py-activate-idalib.py"
uv run "/path/to/idapro-9.3/idalib/python/py-activate-idalib.py"
## 설치 (Claude Code)
Claude Code에서 최신 IDA Pro MCP를 설치하려면:```bash
claude plugin marketplace add mrexodia/claude-marketplace
claude plugin uninstall ida-pro-mcp@mrexodia
claude plugin install ida-pro-mcp@mrexodia
Codex에서 최신 IDA Pro MCP를 설치하려면:```bash codex plugin marketplace add mrexodia/codex-marketplace codex plugin remove ida-pro-mcp@mrexodia codex plugin add ida-pro-mcp@mrexodia
## 설치 (Kimi Code)
Kimi Code에서 최신 IDA Pro MCP를 설치하려면 채팅에서 다음 슬래시 명령을 실행하세요:```
/plugins install https://github.com/mrexodia/ida-pro-mcp/tree/main
/reload
이것은 idalib MCP 서버와 idapython 스킬을 설치합니다. 플러그인은
$KIMI_CODE_HOME/plugins/managed/에 복사되므로, uv가 PATH에 있어야 합니다. 설치 후
첫 세션은 서버가 응답하기 전에 uv가 의존성을 해석하기 때문에 더 느립니다.
참고: MCP 플러그인은 더 이상 권장되지 않으며 결국 지원이 중단될 예정입니다. 대신 idalib-mcp를 사용하세요.
IDA GUI에서 MCP 서버를 수동으로 구성하려면:```sh pip uninstall ida-pro-mcp pip install https://github.com/mrexodia/ida-pro-mcp/archive/refs/heads/main.zip
MCP 서버를 구성하고 IDA 플러그인을 설치합니다:```
ida-pro-mcp --install
중요: 설치가 적용되려면 IDA와 MCP 클라이언트를 완전히 재시작해야 합니다. 일부 클라이언트(예: Claude)는 백그라운드에서 실행되므로 트레이 아이콘에서 종료해야 합니다.
LLM은 환각(hallucination)에 취약하므로 프롬프트를 구체적으로 작성해야 합니다. 리버스 엔지니어링의 경우 정수와 바이트 간의 변환이 특히 문제가 됩니다. 아래는 최소한의 예시 프롬프트이며, 다른 프롬프트로 좋은 결과를 얻으셨다면 토론을 시작하거나 이슈를 열어주시기 바랍니다:```md Your task is to analyze a crackme in IDA Pro. You can use the MCP tools to retrieve information. In general use the following strategy:
int_convert MCP tool if needed!이 프롬프트는 단지 첫 번째 실험이었습니다. 출력을 개선할 방법을 찾으셨다면 공유해 주세요!
[@can1357](https://github.com/can1357)의 또 다른 프롬프트:```md
Your task is to create a complete and comprehensive reverse engineering analysis. Reference AGENTS.md to understand the project goals and ensure the analysis serves our purposes.
Use the following systematic methodology:
1. **Decompilation Analysis**
- Thoroughly inspect the decompiler output
- Add detailed comments documenting your findings
- Focus on understanding the actual functionality and purpose of each component (do not rely on old, incorrect comments)
2. **Improve Readability in the Database**
- Rename variables to sensible, descriptive names
- Correct variable and argument types where necessary (especially pointers and array types)
- Update function names to be descriptive of their actual purpose
3. **Deep Dive When Needed**
- If more details are necessary, examine the disassembly and add comments with findings
- Document any low-level behaviors that aren't clear from the decompilation alone
- Use sub-agents to perform detailed analysis
4. **Important Constraints**
- NEVER convert number bases yourself - use the int_convert MCP tool if needed
- Use MCP tools to retrieve information as necessary
- Derive all conclusions from actual analysis, not assumptions
5. **Documentation**
- Produce comprehensive RE/*.md files with your findings
- Document the steps taken and methodology used
- When asked by the user, ensure accuracy over previous analysis file
- Organize findings in a way that serves the project goals outlined in AGENTS.md or CLAUDE.md
프롬프트 작성에 대해 논의하고 실제 악성코드 분석을 보여주는 라이브 스트림:
대규모 언어 모델(LLM)은 강력한 도구이지만, 때때로 복잡한 수학 계산에 어려움을 겪거나 "환각"(사실을 지어내는 것)을 일으킬 수 있습니다. LLM에게 int_convert MCP 도구를 사용하라고 반드시 알려주고, 특정 작업에는 math-mcp도 필요할 수 있습니다.
또 한 가지 명심해야 할 점은 LLM이 난독화된 코드에서는 성능이 좋지 않다는 것입니다. LLM을 사용해 문제를 해결하기 전에, 바이너리를 둘러보고 다음 항목들을 (자동으로) 제거하는 데 시간을 투자하세요:
Lumina나 FLIRT 같은 도구를 사용해 모든 오픈 소스 라이브러리 코드와 C++ STL을 해석하는 것도 시도해야 하며, 이는 정확도를 더욱 향상시킬 것입니다.
다음과 같이 SSE 서버를 실행하여 사용자 인터페이스에 연결할 수 있습니다:```sh uv run ida-pro-mcp --transport http://127.0.0.1:8744/sse
[`idalib`](https://docs.hex-rays.com/core/idalib/getting-started)를 설치한 후에는 헤드리스 MCP 서버도 실행할 수 있습니다. 초기 바이너리와 함께 시작할 수 있습니다:```sh
uv run idalib-mcp --host 127.0.0.1 --port 8745 path/to/executable
바이너리 없이 시작한 뒤 나중에 idb_open(...)으로 임의의 파일을 열 수도 있습니다:```sh
uv run idalib-mcp --host 127.0.0.1 --port 8745
stdio 기반 클라이언트의 경우 다음을 사용하세요:```sh
uv run idalib-mcp --stdio
데이터베이스 워커는 영구적입니다. 각 워커는 자신을 생성한 슈퍼바이저보다 오래 살아남는 분리된 프로세스로 실행됩니다. 새로운 슈퍼바이저(stdio 또는 HTTP를 통해)가 이 호스트의 워커 아래에서 이미 열려 있는 바이너리에 대해 idb_open을 호출하면, 슈퍼바이저는 해당 워커를 투명하게 채택합니다. 활성화해야 할 별도의 "공유" 모드는 없습니다. 워커는 유휴 간격 동안 요청이 들어오지 않으면 스스로 종료됩니다.
참고: idalib 기능은 Willi Ballenthin이 기여했습니다.
idalib-mcp는 열린 각 데이터베이스를 자체 idalib 워커 프로세스에 유지하는 슈퍼바이저입니다. 워커는 호스트 로컬 검색 디렉터리에 자신을 등록하고 자신을 생성한 슈퍼바이저보다 오래 살아남습니다. 동일한 경로를 원하는 후속 슈퍼바이저는 실행 중인 워커를 채택합니다. 워커는 유휴 TTL(기본 1시간) 동안 요청이 들어오지 않으면 스스로 종료됩니다. idb_close를 호출하여 워커를 즉시 해제할 수 있습니다(--max-workers를 향한 슬롯 확보). 채택된 GUI/워커 인스턴스는 종료되지 않고 분리됩니다.
idb_open은 mode 매개변수를 통해 백엔드를 선택합니다: