Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
ctxdebug — MCP-powered reverse engineering platform connecting WinDbg, IDA Pro & x64dbg with 160+ AI-accessible debugging and analysis tools. | Kitploit
Ferramentas/GitHubGitHub/ddudle/ctxdebug
Static AnalysisDynamic Code Analysis (DAST)Reverse EngineeringDebuggersMalware AnalysisBinary AnalysisAI-Assisted Reversing
GitHubddudle/ctxdebug

ctxdebug

MCP-powered reverse engineering platform connecting WinDbg, IDA Pro & x64dbg with 160+ AI-accessible debugging and analysis tools.

Ver Repositório
24427há 5 diasAinda não revisado

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

ctxdebug — MCP servers for WinDbg, IDA Pro, and x64dbg

MCP servers for WinDbg, IDA Pro, and x64dbg
One stdio interface · 160+ tools · Three debuggers, one client.

status python platform mcp license

Quick Start · Architecture · Servers · Workflows · Report an Issue

Website · ctxdebug.xyz  ·  Contact · [email protected]  ·  Status · Public alpha

For authorized reverse engineering, crash analysis, and security research on systems you own or have permission to analyze.


▎ Overview

ctxdebug is an MCP (Model Context Protocol) platform that connects WinDbg, IDA Pro 9.x, and x64dbg to AI coding assistants. Use it for crash dump analysis, static review in IDA, and live debugging in x64dbg — without copying output between windows.

One stdio interface. 160+ tools. Three debuggers, one client.

How it works. Each debugger is exposed as an MCP tool server. You talk to Claude, Kiro, or any MCP-compatible client; the client calls the debuggers. No copy-paste, no manual correlation between tools.

Example. You ask: "analyze this crash dump and find the root cause." ctxdebug opens the dump in WinDbg, runs !analyze -v, takes the faulting address, decompiles the function in IDA Pro, and returns a combined report with pseudocode and the caller chain.


▎ Demo

ctxdebug demo — crash dump analysis with WinDbg and IDA in one request

One prompt → WinDbg opens the dump, analyzes the crash, IDA decompiles the faulting function — combined report in ~1.8s.


▎ Quick Start

Requirements

  • Python 3.11+
  • OS Windows 10 / 11
  • At least one debugger — WinDbg (Windows SDK) · IDA Pro 9.x · x64dbg

Install

root@kitploit:~
git clone https://github.com/DdUdle/ctxdebug.git
cd ctxdebug
pip install -e .

Register servers

Individual servers:

root@kitploit:~
claude mcp add windbg       -- python windbg_mcp.py
claude mcp add ida          -- python ida_mcp.py
claude mcp add x64dbg       -- python -m agent --mcp
claude mcp add mco          -- python mco_orchestrator.py
claude mcp add mco-sessions -- python mco_sessions.py

Or use the unified gateway — one server, every tool:

root@kitploit:~
claude mcp add mco-gateway -- python mco_gateway.py

See mcp_config_example.json for full JSON configuration with environment variables.

Try it

Once a server is registered, ask your AI client:

root@kitploit:~
Open C:\dumps\crash.dmp, run a full crash analysis,
and decompile the function at the fault address.

The orchestrator chains windbg_open_dump → windbg_analyze_crash → mco_pivot_to_ida and returns pseudocode with the caller chain.


▎ Features

CapabilityWhat it does
Live debugger controlRun, pause, step, and inspect a process through x64dbg. Set breakpoints on API groups (memory, network, crypto) instead of one address at a time.
Cross-debugger pivotTake an address from a WinDbg crash dump and open it in IDA Pro for decompilation, callers, and callees in one tool call.
Goal-driven analysisThe x64dbg server includes an optional ReAct agent (agent_analyze) that plans multi-step goals — for example finding an unpacking loop or listing anti-analysis checks — by chaining tool calls. Works with Claude, Groq, local Ollama, or heuristics only.
Persistent notesThe agent stores packer signatures, anti-analysis patterns, and notes from earlier sessions, and can recall them on new targets.
Session recordingTool calls can be logged to SQLite with full-text search (FTS5). Replay a timeline, compare two sessions, or export a Markdown report.
Anti-analysis surveyCombines a static scan (IDA imports/patterns) and a dynamic scan (x64dbg PEB/RDTSC) into one report. Optional lab patches (PEB flags, instruction edits) for samples you are authorized to analyze.

▎ Architecture

System architecture — one MCP connection to three debuggers, an orchestrator, and a session layer

  • Transport — stdio JSON-RPC (MCP 2024-11-05)
  • IDA — HTTP REST on localhost:2022, auto-discovers the endpoint from 6 candidates
  • x64dbg — binary framing over a named pipe (X64A magic + uint32 length + 8-byte padding + JSON)
  • Agent — ReAct loop with pluggable LLM backends (Claude, Groq, OpenRouter, local Ollama, or heuristics only)
  • Sessions — SQLite with FTS5, WAL mode, thread-safe
  • Gateway — starts sub-servers as child processes and proxies tool calls through one stdio connection

▎ Servers

ServerFileWhat it doesTools
windbgwindbg_mcp.pyCrash dumps, heap analysis, shadow stack, kernel debugging70+
idaida_mcp.pyDecompilation, xrefs, type recovery, binary patching32+
x64dbgagent/Dynamic analysis, ReAct agent, memory inspection and patching38+
mcomco_orchestrator.pyCross-debugger compound workflows7
mco-sessionsmco_sessions.pySession recording, FTS search, Markdown export13
mco-gatewaymco_gateway.pyUnified proxy — all servers through one connectionall

▎ Debugger setup

WinDbg

Needs cdb.exe from the Windows SDK. Default path:

root@kitploit:~
C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\cdb.exe

Set WINDBG_MCP_CDB if your path differs. No pre-launch needed — tools open dumps or attach on demand.

IDA Pro 9.x
  1. Open IDA Pro 9.x with a binary loaded.

  2. In the Python console, run:

    root@kitploit:~
    exec(open(r'path\to\ctxdebug\ida_server_plugin.py').read())
    
  3. HTTP server starts on port 2022.

x64dbg
  1. Build the C++ plugin:

    root@kitploit:~
    cd agent\plugins
    build_plugin.bat
    
  2. Copy mco_agent.dp64 to x64dbg's plugin directory.

  3. Restart x64dbg — the plugin exposes named pipe \\.\pipe\x64dbg_ai_agent.


▎ Key Workflows

Crash dump → source (one command)

root@kitploit:~
mco_crash_to_source(dump_path="C:\\dumps\\crash.dmp")

Opens the dump, runs !analyze -v, extracts the faulting address, decompiles the crashing function in IDA, and returns pseudocode with callers.

Anti-analysis report

root@kitploit:~
mco_bossix_report()
bossix_hide()            # PEB flag adjustments (lab)
bossix_patch(address)    # NOP / flip JCC at a check (lab)

For authorized lab analysis of samples that implement anti-debug checks.

Pivot an address to pseudocode

root@kitploit:~
mco_pivot_to_ida(address="0x7FF712340000")

Goal-driven analysis

root@kitploit:~
agent_analyze(goal="Find the unpacking loop and identify the OEP")

The agent plans a sequence of tool calls, executes them, and reports findings — with or without an LLM backend.

Session recording

root@kitploit:~
session_start(name="crash dump review")
# ... do your work ...
session_end(notes="null deref in CRenderObject::Destroy")
session_export_markdown(session_id=1)

▎ x64dbg Server Modes

ModeCommand
Tool-only (default)python -m agent --mcp
Claude reasoningpython -m agent --mcp --llm claude --api-key sk-...
Local Ollamapython -m agent --mcp --llm local --llm-model deepseek-r1
Groq (free tier)python -m agent --mcp --llm groq
OpenRouterpython -m agent --mcp --llm openrouter
Interactive CLIpython -m agent --cli

▎ Environment Variables

VariableServerPurpose
WINDBG_MCP_CDBwindbgPath to cdb.exe
IDA_MCP_HOSTidaIDA HTTP host (default: localhost)
IDA_MCP_PORTidaIDA HTTP port (default: 2022)
IDA_MCP_TOKENidaBearer token for the IDA HTTP server — required to bind it off loopback
IDA_SERVER_HOSTidaBind address of the in-IDA HTTP server (default: 127.0.0.1)
X64DBG_PATHx64dbgPath to x64dbg.exe
X64DBG_PIPEx64dbgNamed pipe path
ANTHROPIC_API_KEYx64dbgOnly needed with --llm claude
GROQ_API_KEYx64dbgOnly needed with --llm groq
MCO_SESSIONS_DBsessionsSQLite database path
MCO_SERVERSgatewayComma-separated subset of servers to enable

▎ Project Structure

root@kitploit:~
ctxdebug/
├── windbg_mcp.py           # WinDbg MCP server
├── ida_mcp.py              # IDA Pro MCP server
├── ida_server_plugin.py    # IDA Python plugin (starts HTTP server)
├── mco_orchestrator.py     # Cross-debugger meta-tools
├── mco_sessions.py         # Session recording (SQLite + FTS5)
├── mco_gateway.py          # Unified gateway proxy
├── agent/
│   ├── __main__.py         # x64dbg MCP entry point + LLM backend selection
│   ├── core.py             # ReAct agent (Observe → Think → Act)
│   ├── memory.py           # Persistent memory store (~/.x64ai/)
│   ├── bridge.py           # Named-pipe IPC to x64dbg plugin
│   ├── mcp_server.py       # Tool definitions (38+)
│   ├── skills/             # Modular skill implementations
│   └── plugins/
│       ├── x64dbg_plugin.cpp
│       └── build_plugin.bat
├── mcp_config_example.json # Ready-to-use MCP client config
└── pyproject.toml

▎ Development

root@kitploit:~
git clone https://github.com/DdUdle/ctxdebug.git
cd ctxdebug
pip install -e ".[dev]"
pytest

▎ Contributing

Contributions are welcome. Please open an issue before starting large changes so the approach can be discussed first.


▎ License

MIT — see LICENSE.

WinDbg · IDA Pro · x64dbg — one MCP client.

Baixar ferramenta