Skip to main content
Sogen implements the GDB Remote Serial Protocol, allowing you to debug emulated Windows programs using industry-standard debugging tools like GDB, LLDB, IDA Pro, and Visual Studio Code.

Overview

The GDB stub integration provides:
  • Full register access (read/write)
  • Memory inspection and modification
  • Breakpoint support (software and hardware)
  • Single-stepping execution
  • Thread enumeration and switching
  • Library/module information

Enabling GDB Mode

Basic GDB Mode

Start the analyzer in debug mode:
By default, Sogen listens on 127.0.0.1:28960 for GDB connections.

Custom Host and Port

Specify a custom bind address:
Binding to 0.0.0.0 exposes the debugger to your network. Only use this in trusted environments.

GDB Connection Flow

Using GDB

Connecting to Sogen

Basic Debugging Commands

Thread Debugging

Using LLDB

LLDB also supports the GDB remote protocol:

Using IDA Pro

IDA Pro provides excellent integration with GDB remote debugging.

Using Visual Studio Code

VS Code can debug Sogen using the Native Debug extension.

Install Extension

  1. Install the “Native Debug” extension
  2. Create a .vscode/launch.json configuration

Configuration

.vscode/launch.json

Debugging Workflow

GDB Stub Implementation Details

The GDB stub is implemented in /src/gdb-stub/ and provides:

Supported Commands

  • Memory operations: Read (m), Write (M, X)
  • Register operations: Read all (g), Write all (G), Read single (p), Write single (P)
  • Breakpoints: Set (Z), Delete (z) for all types
  • Execution control: Continue (c), Step (s), Continue with signal (S)
  • Thread operations: Query (qfThreadInfo), Switch (H)
  • Information queries: Target description (qXfer:features), Libraries (qXfer:libraries), Executable path (qXfer:exec-file)

Breakpoint Types

Target Architecture

Sogen exposes x86-64 (AMD64) architecture to the debugger with full register set including:
  • General purpose registers (RAX, RBX, RCX, etc.)
  • Segment registers (CS, DS, SS, ES, FS, GS)
  • Control registers
  • Instruction pointer (RIP)
  • Flags register (RFLAGS)

Advanced Debugging Techniques

Conditional Breakpoints

Watchpoints

Scripting

Automate debugging with GDB Python scripts:
debug_script.py
Load the script in GDB:

Troubleshooting

Connection Refused

If the debugger cannot connect:
  1. Check that analyzer is running in debug mode (-d)
  2. Verify the correct host and port
  3. Check firewall settings
  4. Ensure no other service is using the port

Symbols Not Loading

The GDB stub provides basic module information, but doesn’t include full symbol data. To get symbols:
  1. Load the executable in your debugger separately
  2. Use IDA Pro to analyze the binary and debug simultaneously
  3. Generate symbol files from the PE executable

Breakpoints Not Working

If breakpoints aren’t triggering:
  1. Verify the address is within executable code
  2. Check that the module is loaded
  3. Use hardware breakpoints for memory-mapped regions
  4. Ensure the code hasn’t been relocated