Overview
The GDB stub integration provides:- Full register access (read/write)
- Memory inspection and modification
- Breakpoint support (software and hardware)
- Single-stepping execution
- Thread enumeration and switching
- Library/module information
Enabling GDB Mode
Basic GDB Mode
Start the analyzer in debug mode:127.0.0.1:28960 for GDB connections.
Custom Host and Port
Specify a custom bind address:GDB Connection Flow
Using GDB
Connecting to Sogen
Basic Debugging Commands
Thread Debugging
Using LLDB
LLDB also supports the GDB remote protocol:Using IDA Pro
IDA Pro provides excellent integration with GDB remote debugging.Using Visual Studio Code
VS Code can debug Sogen using the Native Debug extension.Install Extension
- Install the “Native Debug” extension
- Create a
.vscode/launch.jsonconfiguration
Configuration
.vscode/launch.json
Debugging Workflow
GDB Stub Implementation Details
The GDB stub is implemented in/src/gdb-stub/ and provides:
Supported Commands
- Memory operations: Read (
m), Write (M,X) - Register operations: Read all (
g), Write all (G), Read single (p), Write single (P) - Breakpoints: Set (
Z), Delete (z) for all types - Execution control: Continue (
c), Step (s), Continue with signal (S) - Thread operations: Query (
qfThreadInfo), Switch (H) - Information queries: Target description (
qXfer:features), Libraries (qXfer:libraries), Executable path (qXfer:exec-file)
Breakpoint Types
Target Architecture
Sogen exposes x86-64 (AMD64) architecture to the debugger with full register set including:- General purpose registers (RAX, RBX, RCX, etc.)
- Segment registers (CS, DS, SS, ES, FS, GS)
- Control registers
- Instruction pointer (RIP)
- Flags register (RFLAGS)
Advanced Debugging Techniques
Conditional Breakpoints
Watchpoints
Scripting
Automate debugging with GDB Python scripts:debug_script.py
Troubleshooting
Connection Refused
If the debugger cannot connect:- Check that analyzer is running in debug mode (
-d) - Verify the correct host and port
- Check firewall settings
- Ensure no other service is using the port
Symbols Not Loading
The GDB stub provides basic module information, but doesn’t include full symbol data. To get symbols:- Load the executable in your debugger separately
- Use IDA Pro to analyze the binary and debug simultaneously
- Generate symbol files from the PE executable
Breakpoints Not Working
If breakpoints aren’t triggering:- Verify the address is within executable code
- Check that the module is loaded
- Use hardware breakpoints for memory-mapped regions
- Ensure the code hasn’t been relocated