pwndbg: GDB and LLDB Plugin for Exploit Development and Reverse Engineering
Exploit Development and Reverse Engineering with GDB & LLDB Made Easy
At a glance
- What is it?
- pwndbg is an MIT-licensed Python plugin for GDB and LLDB that adds structured context display, memory inspection, disassembly, and exploit-development utilities. It targets reverse engineers, CTF participants, and low-level developers who find vanilla GDB's output insufficient for serious work.
- Who is it for?
- pwndbg is the right tool for anyone doing serious work in GDB or LLDB on Linux binaries, macOS Mach-O files, or QEMU-emulated targets. The GDB path is battle-tested on Ubuntu 22.04 and 24.04; the LLDB path is early-stage and known to have open issues tracked in the GitHub issue tracker.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 2 days ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What pwndbg Solves and Who It Targets
Vanilla GDB and LLDB display minimal information by default. The README describes typing x/30gx $rsp as a tedious way to inspect stack memory and notes that WinDbg users who occasionally need GDB are lost without the familiar UI. Pwndbg fills this gap by loading a Python module that rewrites how GDB presents information: each stop in execution shows a structured context panel with registers, disassembly, stack, and memory sections rather than a blank prompt.
The primary audience is low-level software developers, hardware hackers, reverse engineers, and exploit developers. The README pronounces the name as /paʊnˈdiˌbʌɡ/. It is used widely in CTF (Capture the Flag) competitions where rapid binary analysis and exploit construction are required.
Compared to older GDB enhancement tools, pwndbg is structured as a Python module rather than a monolithic single-file script. The README points out that PEDA is 195 kilobytes as a single file, GEF is 423 kilobytes, and bata24/GEF is 5.24 megabytes. The multi-file architecture of pwndbg is described as easier to extend and maintain.
GDB vs LLDB: Which Backend and Compatibility Requirements
pwndbg supports both GDB and LLDB, but the two backends have different maturity levels and use cases. The GDB path requires Python 3.10 or later and GDB 12.1 or later. The README describes this path as battle-tested on Ubuntu 22.04 and 24.04. The LLDB path requires Python 3.12 or later and LLDB 19 or later, and the README marks it as experimental and early-stage with known issues tracked in the GitHub issue tracker under the LLDB Port label.
The README provides a table of supported use cases. Linux binary debugging and ELF files work with both GDB and LLDB. Mach-O binaries on macOS require LLDB. Linux kernel debugging via qemu-system works with both; Linux user-space emulation via qemu-user requires GDB. Embedded debugging of ARM Cortex M and RISC-V 32-bit targets works with both.
For QEMU, the compatibility requirements are specific: qemu-user needs QEMU 8.1 or later because the vFile API is required for vmmap to work. qemu-system works with QEMU 6.2 or later, which is the version shipped with Ubuntu 22.04.
Installing pwndbg with setup.sh and Docker
The README points to the installation instructions at https://pwndbg.re/stable/setup. The repository includes a setup.sh script that handles dependency installation. Running it requires shell execution permissions:
./setup.shFor development or isolated testing, Docker images are provided for Ubuntu 22.04, Ubuntu 24.04, Debian 12, Arch Linux, Fedora 41, 42, and 43. The docker-compose.yml file in the repository root defines services for each of these distributions. Pre-built images are available from the GitHub Container Registry. The Dockerfile documentation shows how to pull and run an Ubuntu 24.04 container with the current working directory mounted:
docker compose run --rm -v $(pwd):/pwndbg ubuntu24.04The pyproject.toml lists the Python package name as pwndbg at version 2026.09.15. Dependencies include capstone6pwndbg for disassembly, unicorn for emulation, pwntools, pyelftools, pygments for syntax highlighting, psutil, and ropgadget. An IPython dependency enables the ipi command for an interactive Python prompt inside the debugger session.
Commands and Capabilities: Context, ROP, and Decompiler Integration
pwndbg's core addition to GDB and LLDB is the context display: at every breakpoint or step, the terminal shows a panel with registers, code (disassembly), stack contents, and memory sections. This replaces the need to type individual inspection commands after each step.
Beyond the context display, pwndbg adds specialized commands. The ropgadget command, powered by the ropgadget 7.6 dependency, searches binary files for ROP (Return Oriented Programming) gadgets. The cymbol command enables working with C type information using the ziglang dependency. The klookup command handles symbol syncing and supports decompiler integration via decomp2dbg. The ai commands (requiring the requests library) add AI-assisted capabilities, though the pyproject.toml marks this group as optional.
A printable CHEATSHEET is available at https://pwndbg.re/dev/CHEATSHEET.pdf listing available commands. The full documentation is at https://pwndbg.re/stable/. The README notes a Discord server at https://discord.gg/x47DssnGwm where the maintainers are regularly available.
Limitations: LLDB Is Early-Stage and Some Commands Are Optional
The LLDB implementation is explicitly described in the README as early-stage and containing bugs or limitations. Known issues are tracked in the GitHub issue tracker. Teams that need LLDB support on macOS for Mach-O debugging should check the LLDB Port label in the issue tracker before committing to pwndbg in a production workflow.
Several pwndbg commands are conditional on optional dependencies. The ropgadget command requires the ropgadget package. The cymbol command requires ziglang, which the pyproject.toml notes is unavailable on loongarch64. The decompiler integration depends on decomp2dbg. The ipi command requires IPython. If any of these optional packages are missing from the Python environment, the corresponding command will not be available without a reinstall.
For embedded RISC-V 32-bit debugging, the Dockerfile and CI configuration show that pwndbg builds test binaries using glibc and musl. The Dockerfile.glibc-test-libs and Dockerfile.musl-test-libs files in the repository indicate that both C library variants are tested, but the test infrastructure is not the same as the production install path.
pwndbg vs GEF: Architecture and Feature Focus
GEF (GDB Enhanced Features) is another GDB enhancement plugin. Unlike pwndbg, GEF is distributed as a single large Python file, which simplifies installation to a single download but makes it harder to extend with new commands or to test individual components. The README notes that GEF's main file is 423 kilobytes.
pwndbg uses a modular Python package layout. The pwndbg/ directory in the repository is a standard Python package with submodules for commands, context display, memory analysis, and other areas. This makes it possible to add a new command in an isolated file without touching the core codebase.
bata24/GEF is a heavily extended fork of GEF with a 5.24-megabyte single file, focused on even more commands for exploit development. It is a separate project from both GEF and pwndbg. pwndbg's documentation acknowledges all three predecessors and frames pwndbg as a cleaner, faster, and more extendable alternative rather than a feature-for-feature replacement. Choosing between them depends on whether the existing workflow has scripts or plugins already tied to one of the other tools.
Editorial conclusion
pwndbg is the right tool for anyone doing serious work in GDB or LLDB on Linux binaries, macOS Mach-O files, or QEMU-emulated targets. The GDB path is battle-tested on Ubuntu 22.04 and 24.04; the LLDB path is early-stage and known to have open issues tracked in the GitHub issue tracker. Before deploying in an automated pipeline, check that Python 3.10 or later (GDB) or Python 3.12 or later (LLDB) is available in the target environment. The current release is 2026.09.15, published on 2026-09-20.
Frequently asked questions
What is pwndbg?
pwndbg is a Python plugin for GDB and LLDB that adds a structured context display, memory inspection, disassembly, and exploit-development commands. The README describes it as focused on features needed by low-level software developers, hardware hackers, reverse engineers, and exploit developers.
How do I install pwndbg?
The README points to installation instructions at https://pwndbg.re/stable/setup. The repository includes a setup.sh script. Docker images for Ubuntu 22.04, Ubuntu 24.04, Debian 12, Arch Linux, and Fedora are available in the GitHub Container Registry via the docker-compose.yml file in the repository root.
What commands does pwndbg add to GDB?
The README points to a CHEATSHEET at https://pwndbg.re/dev/CHEATSHEET.pdf and a Features page at https://pwndbg.re/stable/features/ for the full list. Specific commands include ropgadget for ROP gadget search, cymbol for C type information, klookup for symbol syncing with decompiler integration, and ai commands for AI-assisted analysis.
pwndbg vs peda: which should I use?
The README notes that PEDA is distributed as a single 195-kilobyte Python file and is harder to extend. pwndbg uses a modular Python package layout, which makes it easier to add commands in isolated files and to test individual components. pwndbg also supports LLDB in addition to GDB, while PEDA is GDB-only.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/pwndbg-pwndbg)