Ghostmcp

Created By
mq1n6 months ago
Injectable MCP server for AI-driven reverse engineering inside processes
Overview

What is GhostMCP?

GhostMCP is an injectable Model Context Protocol (MCP) server designed for AI-driven reverse engineering on Windows. It allows users to interact with processes through natural language, enabling complex memory inspection, disassembly, debugging, and code injection tasks.

How to use GhostMCP?

To use GhostMCP, inject it into a target process using the provided ghost-loader, then connect your AI client to the server to start issuing commands and queries about the process.

Key features of GhostMCP?

  • Modular multi-server architecture providing over 250 tools for various tasks.
  • Memory operations including read/write capabilities and pattern scanning.
  • Advanced debugging features with breakpoints and dynamic analysis.
  • Integration with popular reverse engineering tools like Radare2 and Ghidra.
  • AI/LLM support for conversational command execution and analysis.

Use cases of GhostMCP?

  1. Security research for vulnerability analysis and exploit development.
  2. Malware analysis for dynamic behavior observation and unpacking.
  3. Game hacking for value scanning and trainer creation.
  4. Software testing for fault injection and performance analysis.
  5. Educational purposes to learn reverse engineering techniques.

FAQ from GhostMCP?

  • Is GhostMCP safe to use?

Yes, but it is experimental and should be used with caution. Ensure you have permission to analyze the target software.

  • Can I use GhostMCP for online games?

No, using it for online multiplayer cheating is prohibited.

  • What are the system requirements?

GhostMCP is designed for Windows and requires a compatible environment for injection and execution.

Server Config

{
  "mcpServers": {
    "ghost-core": {
      "command": "path/to/ghost-core-mcp.exe",
      "args": [
        "--transport",
        "stdio"
      ]
    },
    "ghost-analysis": {
      "command": "path/to/ghost-analysis-mcp.exe",
      "args": [
        "--port",
        "13341"
      ]
    },
    "ghost-static": {
      "command": "path/to/ghost-static-mcp.exe",
      "args": [
        "--port",
        "13342"
      ]
    },
    "ghost-extended": {
      "command": "path/to/ghost-extended-mcp.exe",
      "args": [
        "--port",
        "13343"
      ]
    }
  }
}
Project Info
Created At
6 months ago
Updated At
6 months ago
Author Name
mq1n
Star
-
Language
-
License
-

Recommend Servers

View All
Bring your real authenticated browser session to AI coding agents. Local-first MCP server + Chrome MV3 extension. No cloud. No telemetry.
@Cubenest

peek records the user's actual logged-in browser (DOM via rrweb, console events, network metadata, optional response bodies via opt-in Deep capture) through a Chrome MV3 extension. The extension ships events through a native-messaging stdio bridge to a local MCP server (peek-mcp), which persists them to a SQLite database at ~/.peek/sessions.db. AI coding agents (Claude Code, Cursor, Cline, Windsurf) read sessions from the database via 10 MCP tools: Tool What it does list_recent_sessions List recently recorded sessions (id, origin, ts, event count). get_session_summary LLM-readable narrative summary of a session. get_session_console_errors Console errors recorded in a session. get_session_network_errors Failed/notable network requests in a session. get_user_action_before_error Last N user actions before a console error. generate_playwright_repro Generate a runnable Playwright test from a session. get_dom_snapshot Reconstruct the DOM at a given timestamp. query_dom_history Timeline of attribute/text changes for a selector. request_authorization Side-panel consent for write actions (Level 3). execute_action Dispatch a UI action (gated by permission level + destructive blocklist). Why local-first matters Every other "browser session for AI" tool ships to a vendor cloud. peek's SQLite + extension live on the user's machine — no remote endpoints, no telemetry. The privacy policy (docs/peek/PRIVACY_POLICY.md) is the source of truth. Install # 1. Add the MCP server to Claude Code claude mcp add peek -- npx -y @peekdev/mcp # 2. Install the Chrome extension from the Chrome Web Store # (link added once the CWS listing is approved)

a day ago
Crevio

2 days ago