Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
kunglao-agent — The reverse-engineering expert agent: plans its own analysis path, derives every fact from raw evidence, and converges under mechanical verification gates — firmware, protocols, web/JS, risk-control, binaries. | Kitploit
أدوات/GitHubGitHub/amd2g2zz/kunglao-agent
Android SecurityStatic AnalysisDynamic Analysis (Sandboxing)Vulnerability AnalysisMobile App PentestingReverse EngineeringWeb SecurityMalware AnalysisBinary AnalysisAI-Assisted ReversingFirmware Analysis
481694منذ 7س 35دتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
GitHubamd2g2zz/kunglao-agent

kunglao-agent

The reverse-engineering expert agent: plans its own analysis path, derives every fact from raw evidence, and converges under mechanical verification gates — firmware, protocols, web/JS, risk-control, binaries.

عرض المستودعالموقع الإلكتروني
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

kunglao-agent

kunglao-agent is an autonomous reverse-engineering system. You hand it a target and the questions you need answered; it works the problem for hours or days on its own — planning its own path, recovering from worker deaths, resuming after crashes — and converges only when every answer is derived from raw evidence and survives mechanical verification gates.

release-check python license PRs welcome

English · Simplified Chinese

It currently ships as a Claude Code plugin — Claude Code is the interface you talk to, not what the product is. The product is the loop: specialist workers analyse (static first), an independent verifier re-derives every fact blind from the raw evidence, and mechanical gates decide when the work is done. The deliverable is a fact base where every claim is byte-anchored, independently verified, and evidence-indexed — trust is enforced by machinery, not convention.

Why kunglao-agent

  • Long-horizon by design. Engagements run unattended across hours and days: a scheduled heartbeat keeps the loop alive, dead workers are reconciled and their claims re-queued, crashes resume from on-disk state, blocked claims self-recover. You read the verdict when it converges — you don't babysit each step. See Long-horizon autonomy.
  • Answers you can trust. No fact is PROVEN until an independent verifier re-derives it blind from the raw artifact; every fact cites a sha256-indexed raw artifact through evidence/_index.json.
  • The full reverse-engineering spectrum. Windows/Linux native binaries, Android APKs, web/JS, protocol analysis, firmware emulation, risk-control countermeasures — one system, not a single-domain tool.
  • Static-first economics. A task that closes statically never touches dynamic tooling; every escalation is declared, gated, and audited.
  • It reuses knowledge instead of re-deriving it. A growing catalog of registered analysis tools (crypto decoders, disassembly pipelines, graph queries) means the system reaches for proven tooling before writing one-off scripts — and every run leaves behind reusable facts, not a chat transcript that evaporates.
  • It recovers instead of dying. Worker deaths, API disconnects, and crashes are first-class events: the loop detects them, snapshots what was already produced, and re-dispatches to continue from where things stopped — not from zero.
  • Your environment, your rules. VMware, ssh, docker, adb, or plain static-only — the system drives whichever execution channel you already have. Nothing is a degraded mode; a task that never needs execution never asks for a VM.

Quick start

kunglao-agent runs inside Claude Code. From a sample on disk to a verdict:

ToolWhyInstall
Claude Codewhere kunglao-agent runsper Anthropic docs
Python 3.10+ (Python 2 is not supported)the plugin carries a pinned env via uv; you do not touch itsystem or uv-managed
uvlocked env resolverpip install uv or astral.sh/uv
Ghidra or IDAone static-analysis suite for decompilationsee Toolchain by target

1. Install the plugin

From any directory, in Claude Code:

/plugin marketplace add amd2g2zz/kunglao-agent
/plugin install kunglao-agent@kunglao-agent

(Alternative: claude --plugin-dir /path/to/kunglao-agent for development.)

2. Init a workspace

/kunglao-agent:init ~/cases/synth-dropper --type windows

kunglao-init scaffolds the workspace, writes CLAUDE.md, probes the toolchain for your --type, and scaffolds .mcp.json. It HARD-rejects when a required tool for your type is missing — the fix guidance is in the error block.

3. State the task and start the analysis

/kunglao-agent:analysis ~/cases/synth-dropper
> Goal: confirm this dropper's persistence mechanism and network endpoints;
>   every conclusion must be reproducible from raw evidence.
> Verification: key findings count only if an independent verifier re-derives
>   them blind and reaches the same answer.
> Constraints: static-first; never execute the sample on the host.

Write the brief so an independent reviewer could judge the result: analysis goal (what you need to know), verification logic (what makes an answer trustworthy — e.g. "the signature must be reproducible from the same inputs"), constraints (e.g. "no execution on the host"). Everything is recorded in task_spec.yaml; from there the loop drives itself. For how the common asks turn into well-formed statements, see How to state the task.

4. Read the deliverable

claim-register.yaml   # every claim terminal, with verifier sign-off
facts/F<NNN>.md       # byte-anchored, reproducible, frontmatter contract
evidence/_index.json  # every fact → raw artifact (sha256 + path)
runs/                 # session audit trail

How to state the task

The loop derives its completion criterion — the oracle — mechanically from the end-state you state. A vague statement yields a vague oracle, and the analysis drifts toward whatever can be proven instead of what you needed. Four phrasings cover most of that drift. For each: what users say, what it usually means, a well-formed statement, and what the oracle anchors on.

"我要纯算" — "just the pure algorithm"

Usually means: offline reproduction of the app's signing/crypto routine — a unidbg harness or a rewrite that runs with no device and no app at run time. Not "analyze the app"; the app is only where the algorithm lives.

> Sample: the v7.2 APK; behavior: the signer producing the `sign`
>   header on api.example.com/v2/* requests.
> Criterion: a standalone reproduction (unidbg or rewrite) replays
>   every captured (input → sign) pair byte-exact — including the
>   withheld pairs — with no device or app at run time.
> Attach: captures/sign-pairs.jsonl — 20 input/output pairs captured
>   from a live session; 10 of them withheld from the analysis.

Oracle anchors on: byte-exact replay on every pair, including the withheld ones — and the reproduction running standalone.

"我要解密" — "I want decryption"

Usually means one of two different targets — say which:

  • (a) decrypt one captured body — a one-off answer about this data: "produce the plaintext of this captured cache file."
  • (b) a decryption capability — algorithm + key recovery, reusable on data you capture tomorrow.

Well-formed (a):

> Sample: the v7.2 APK; behavior: the local config cache
>   files/.cfg/v2.dat is encrypted at rest.
> Criterion: produce the plaintext of the captured v2.dat and validate
>   it against what the app renders (field names and values match the
>   screenshot captured alongside).

Well-formed (b):

> Sample: the v7.2 APK; behavior: request bodies on
>   api.example.com/v2/* are encrypted with a static key.
> Criterion: identify the algorithm and the key, then run a canary
>   round-trip — encrypt a known plaintext with the recovered key and
>   match the ciphertext the device produced, byte for byte.
> Attach: captures/request-bodies.jsonl — ciphertext bodies captured
>   from the device, with the requests that produced them.
تنزيل الأداة