svnscha / mcp-windbgView external linksLinks
Model Context Protocol for WinDBG
☆953Dec 26, 2025Updated last month
Alternatives and similar repositories for mcp-windbg
Users that are interested in mcp-windbg are comparing it to the libraries listed below
Sorting:
- WinDbg-ext-MCP bridges your favorite LLM client (like Cursor, Claude, or VS Code) with WinDbg, enabling real-time, AI assisted kernel deb…☆71Sep 10, 2025Updated 5 months ago
- Set of plugins and library for dynamic pdb generation and synchronisation☆37May 3, 2024Updated last year
- Contains all the applications developed for the Second part of the 7th Edition of Windows Internals book☆115Jun 30, 2024Updated last year
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆146Feb 23, 2019Updated 6 years ago
- A fast execution trace symbolizer for Windows that runs on all major platforms and doesn't depend on any Microsoft libraries.☆100Jan 3, 2026Updated last month
- Useful scripts for WinDbg using the debugger data model☆429Mar 27, 2024Updated last year
- Set of scripts for performance investigations on Windows.☆32Dec 17, 2025Updated last month
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆120Sep 8, 2024Updated last year
- Code to make it easier to write an NDIS network driver on Windows☆92Oct 1, 2023Updated 2 years ago
- Native code virtualizer for x64 binaries☆514Dec 20, 2024Updated last year
- Waiting Thread Hijacking - injection by overwriting the return address of a waiting thread☆262Aug 31, 2025Updated 5 months ago
- Sysmon-Like research tool for ETW☆384Nov 15, 2022Updated 3 years ago
- Manage Shadows Copies via the VSS API using C#, C++, Crystal or Python. Working on Windows 11☆81Jan 26, 2026Updated 2 weeks ago
- Static binary instrumentation for windows kernel drivers, to use with winafl☆81Feb 5, 2025Updated last year
- A Windows kernel dump C++ parser library with Python 3 bindings.☆213Oct 5, 2025Updated 4 months ago
- View ETW Provider manifest☆570Nov 1, 2024Updated last year
- Windows Anti-Rootkit Tool☆542Dec 31, 2025Updated last month
- ☆32Jun 1, 2024Updated last year
- Mentally ill EtwTi parser☆66Jan 11, 2026Updated last month
- A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.☆408Jan 11, 2026Updated last month
- binary ninja related code☆37Mar 27, 2025Updated 10 months ago
- Tools and documents for working with Microsoft PDB files, in Rust☆56Jan 30, 2026Updated 2 weeks ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆329May 2, 2024Updated last year
- Document ETW providers☆267Mar 28, 2020Updated 5 years ago
- A little tool to play with the Seclogon service☆328Jul 10, 2022Updated 3 years ago
- Uses Threat-Intelligence ETW events to identify shellcode regions being hidden by fluctuating memory protections☆166May 17, 2023Updated 2 years ago
- A basic implementation of Patch Guard that I implemented, that includes integrity checks and other protection mechanisms I added.☆78Mar 29, 2025Updated 10 months ago
- This is the tool to dump the LSASS process on modern Windows 11☆555Nov 1, 2025Updated 3 months ago
- Sample extensions, scripts, and API uses for WinDbg.☆810Dec 27, 2025Updated last month
- Two new offensive techniques using Windows Fibers: PoisonFiber (The first remote enumeration & Fiber injection capability POC tool) Phan…☆280Sep 18, 2024Updated last year
- Hardcore Debugging☆929Jan 6, 2026Updated last month
- Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999☆239Nov 6, 2019Updated 6 years ago
- Fuzzing Harness and Unpatched Crash Results from Fuzzing Defender MpEngine☆39Jul 29, 2025Updated 6 months ago
- CyberShield 2025 Intro to EDR Evasion Class☆17Jun 3, 2025Updated 8 months ago
- A cmake template for crystal palace☆38Dec 20, 2025Updated last month
- Windows Dependencies☆638Feb 4, 2026Updated last week
- Locate dlls and function addresses without PEB Walk and EAT parsing☆104Nov 7, 2025Updated 3 months ago
- Uses ghidra to find all ETW write metadata for each API in a PE file☆27Jul 26, 2024Updated last year
- A set of LLVM and GCC based plugins that perform code obfuscation.☆138Oct 20, 2025Updated 3 months ago