Windbg MCP logo

Windbg MCP

Unclaimed

by memoryforensics1

C# MCP server for kernel & user-mode Windows debugging — DbgEng COM, KDNET, Frida, dbgsrv, TTD, and integrated VM control. 29 tools for LLM agents.

Set up this server

01 / Choose your client

02 / Before you connect

Authentication is not specified. Check the project instructions before connecting.

Install the runtime required by the project and make it available to your client.

Project instructions

Use names from the project instructions, separated by commas. Enter names only, never secret values.

03 / Add the configuration

Source: generated from public install instructions

claude mcp add --transport stdio 'windbg-mcp' -- 'uvx' 'frida-tools'

Run in your terminal after replacing any placeholders.

04 / Check it in your client

Open your client’s MCP settings and confirm the server connects and lists its tools. A copied configuration does not confirm a working connection.

ai-agentclaudecsharpdbgengdebuggerdotnetexploit-developmentfridakernel-debuggingllmmalware-analysismcpmodel-context-protocolreverse-engineeringtime-travel-debuggingttdvmwarevulnerability-researchwindbgwindows

More in AI & ML

Browse the full directory

Unclaimed listing

Is this your MCP server?

This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.

Claim this server

Security profile

Claimed and verified servers get a weekly static scan that shows what the code can reach: external services, environment variables, shell commands, agent configuration folders, plus any dependencies with known advisories. Claim this listing to get one. How the security profile works

29 of 29 tools

Documented tools (29)

From project documentation. A server handshake does not verify each tool’s description or behavior.

get_system_state

Full state overview — VM power, KD, guest ops, UMD. Always allowed.

guest_kill_process

Kill a process by PID

guest_list_processes

List running processes with PIDs

guest_run_command

Execute command in guest OS, capture stdout/stderr

guest_transfer_from_vm

Copy file from guest to host

guest_transfer_to_vm

Copy file from host to guest

kd_break

Halt running target (Ctrl+Break)

kd_connect

Attach to kernel via KDNET. Target breaks on connect.

kd_continue

Resume target execution

kd_disconnect

Detach from kernel. Resumes target so VM keeps running.

kd_execute

Run any WinDbg command (k, r, lm, !process 0 0, !analyze -v, etc.)

kd_step

Step one instruction (into or over)

kd_wait_for_event

Wait for breakpoint/exception with timeout. Always returns.

umd_dbgsrv_connect

Connect to remote dbgsrv in guest

umd_dbgsrv_execute

Attach to PID, run WinDbg commands, detach

umd_dbgsrv_skill

dbgsrv best practices and WinDbg command reference for LLMs

umd_frida

Inject JS, eval expressions, list processes, detach

umd_frida_attach

Attach Frida to a guest process

umd_frida_skill

Frida best practices and API reference for LLMs

umd_ttd

Time Travel Debugging — record, stop, retrieve, list traces

umd_ttd_query

Query TTD traces (not yet implemented)

vm_pause

Freeze entire VM

vm_resume

Unpause a paused VM

vm_screenshot

Capture VM display as PNG

vm_set_target

Switch the active VM target at runtime (VMX path + credentials)

vm_snapshot_list

List available snapshots

vm_snapshot_restore

Restore a named snapshot (debug sessions are cleanly torn down and can reconnect after)

vm_start

Power on the VM

vm_stop

Shut down (graceful or hard)

Tool change history

Compared across complete checks of the same configuration. Tools were listed, not invoked. Input-schema changes are not measured here.

No complete tool checks yet.

FAQ

Questions about Windbg MCP Server

How do I connect Windbg MCP Server to Claude?
Run `claude mcp add windbg-mcp -- uvx frida-tools` in Claude Code, or add the same command and arguments under mcpServers in Cursor's mcp.json or Claude Desktop's claude_desktop_config.json, then restart the client. The blocks above are ready to paste.
Is Windbg MCP Server free?
The listed licence is MIT. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
What can Windbg MCP Server do?
Windbg MCP Server documents 29 tools to the agent, including get_system_state, guest_kill_process, guest_list_processes. The descriptions above come from project documentation. A live handshake does not test individual tool behavior.