Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Einreichen
ToolsExploitsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
ablation — Reverse-Engineering-Framework mit Disassemblierung, Dekompilierung, Taint-Analyse, Versionsvergleich und semantischer Suche sowie LLM-gesteuerter autonomer Binär- und Firmware-Analyse. | Kitploit
Tools/GitHubGitHub/ablation-tool/ablation
Android-SicherheitStatische AnalyseSchwachstellenanalyseReverse EngineeringMalware-AnalyseKryptographieBinäranalysePapers & ForschungKI-gestütztes Reverse EngineeringFirmware-Analyse
GitHub
3528vor 6h 35mNoch nicht geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen
ablation-tool/ablation

ablation

Reverse-Engineering-Framework mit Disassemblierung, Dekompilierung, Taint-Analyse, Versionsvergleich und semantischer Suche sowie LLM-gesteuerter autonomer Binär- und Firmware-Analyse.

Repository anzeigen
ABLATION

Ablation ist ein Reverse-Engineering-Framework, das exakt dieselben Kernfähigkeiten für Disassemblierung, Dekompilierung und Binäranalyse bietet wie branchenübliche Werkzeuge wie Ghidra, IDA Pro und Binary Ninja.

In Kombination mit Claude Code oder OpenAI Codex verwandelt es sich in ein vollständig autonomes Reverse-Engineering-Werkzeug.


Codex demo

Fähigkeiten

Semantische Suche via BERT: Die semantische Suche findet Ergebnisse basierend auf der Bedeutung statt auf exakten Schlüsselwörtern. BERT liest Text und ermittelt, was er bedeutet. Ähnliche Bedeutungen erhalten ähnliche Bewertungen, sodass Sie nach Konzept statt nach exakten Wörtern suchen können. Durch die Kombination beider Ansätze wird der Hauptengpass des Reverse Engineerings beschleunigt, während die verwundbaren Funktionen gefunden werden.

Extreme Performance: Eine 50 MB große Binärdatei lädt in 35 Sekunden. Ghidra und IDA Pro können Stunden benötigen, weil sie die gesamte Datei in eine Datenbank parsen, bevor Sie irgendetwas tun können. Ablation analysiert nur die Funktionen, an denen Sie aktiv arbeiten, sodass Sie sofort beginnen können.

Versions-Diffing: Unter Verwendung der Jaccard-Methode, um zu messen, wie stark sich das Verhalten einer Funktion zwischen Releases überschneidet, und Dynamic Time Warping, das die „Form" verfolgt, wie eine Funktion über diese Versionen von Firmware oder Software, die ein Anbieter aktualisiert hat, ausgeführt wird, bestätigt Ablation, ob ein Patch tatsächlich die Logik geändert hat oder nur das Packaging, denn eine kosmetische Neukompilierung kann eine ungepatchte Schwachstelle nicht verbergen.

Cross-Binary-Analyse: Analysieren Sie jede gemeinsam genutzte Bibliothek in einem Firmware-Image gleichzeitig und verfolgen Sie Datenflüsse über Binärgrenzen hinweg.

Quellcode-Audit: Prüfen Sie jede große Codebasis schneller als durch lineares Lesen, mit höherer Genauigkeit als reines Pattern Matching. Jede Quelldatei erhält ein 5-Bit-Sicherheitsprofil, das genau bestimmt, wie viel Aufmerksamkeit sie benötigt, sodass nichts übersehen und nichts zweimal gelesen wird.

Windows-Kernel-Treiber- & BYOVD-Analyse: Kartiert die IRP-Dispatch-Tabelle, dekodiert jeden IOCTL-Code und identifiziert, welche Kernel-APIs physischen Speicher und Token-Primitive aus dem User-Mode heraus exponieren. Der BYOVD-Detector fingerprintet signierte Treiber, die diese Fähigkeiten mit sich bringen, denn ein einziger legitimer signierter Treiber genügt, um EDR aus Ring-0 heraus zu blenden.

Android-/APK-Analyse: Liest Android-APKs auf Binärebene ohne Abhängigkeiten. Es kartiert native Code-Einstiegspunkte und die IPC-Oberfläche aus kompiliertem Bytecode, sodass die vollständige Oberfläche ohne Dekompilierung sichtbar ist.

Erlang-/BEAM-Analyse: Erlang kompiliert zu .beam-Dateien, und derselbe Surface-Map-Ansatz, der für ELF verwendet wird, lässt sich direkt anwenden, sodass Atom-Suche, Import-Auditing und Obfuskierungserkennung keine spezielle Behandlung benötigen. Das Durchsuchen eines Release-Verzeichnisses dauert Sekunden.

Entschlüsselung

  • Entropy Mapper: Findet verschlüsselte, komprimierte oder gepackte Abschnitte in einer Binärdatei.
  • Crypto Audit: Sucht nach Kryptographie.
  • XorSolver: Stellt den Zielabschnitt wieder her und entschlüsselt ihn, was weiteres Reverse Engineering ermöglicht.

Ergebnisse aus der Praxis

Ablation wurde zur Analyse von Produktions-Firmware und Kernel-Treibern von Fortinet, Cisco, Juniper, Axis, Fujitsu, MikroTik, Orka, TencentOS, Enigma2, Skydio und Dahua Security System eingesetzt.

Nach der koordinierten Offenlegung zu Cisco FMC und ISE hat das Cisco Product Security Incident Response Team (PSIRT) Ablation für die interne Schwachstellen-Triage übernommen. Cisco PSIRT nutzt es aktiv zur Triage laufender Offenlegungsberichte zu Firepower Threat Defense (FTD), Cisco Secure Client (AnyConnect), HyperFlex und Catalyst. Cisco Adaptive Security Appliance (ASA) LINA wurde ebenfalls mit Ablation reverse-engineered, wobei die Ergebnisse derzeit über CERT/CC VINCE koordiniert triagiert werden.


Lokale Dekompiler


LLM-Kompatibilität

AnbieterModelle
Claude Code/model claude-sonnet-4-6
OpenAI CodexAlle bekannten Modelle

Installation```bash

pip install git+https://github.com/Ablation-Tool/ablation

root@kitploit:~
---

## Voraussetzungen

- Python >= 3.10
- `capstone`, `numpy`, `lief`, `sentence-transformers`, `pyelftools`
- Optional: `anthropic` für LLM-Funktionen

---

## Verantwortungsvolle Nutzung

Ablation wurde für autorisierte Sicherheitsforschung entwickelt. Verwenden Sie es nur gegen Systeme, die Ihnen gehören oder für die Sie eine ausdrückliche schriftliche Genehmigung zum Testen haben. Die Ausführung gegen Systeme ohne Genehmigung verstößt in den meisten Rechtsordnungen gegen Computerbetrugsgesetze. Die Autoren sind nicht für Missbrauch verantwortlich.

---

## Danksagungen
Dieses Projekt wurde maßgeblich durch mehrere wichtige literarische Werke beeinflusst und inspiriert.

**Forschungsarbeiten**

| Titel | Autoren | Zitation |
|---|---|---|
| [Finding Taint-Style Vulnerabilities in Linux-based Embedded Firmware with SSE-based Alias Analysis](https://arxiv.org/abs/2109.12209) | Cheng, Zheng, Liu, Guan, Liu, Li, Zhu, Ye, Sun | [sse_slicer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/sse_slicer.py) · [arm64_global_tracker.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/arm64_global_tracker.py) |
| [iResolveX: Multi-Layered Indirect Call Resolution via Static Reasoning and Learning-Augmented Refinement](https://arxiv.org/abs/2601.17888) | Monika Santra, Bokai Zhang, Mark Lim, [Vishnu Asutosh Dasu](https://github.com/vdasu), Dongrui Zeng, [Gang Tan](https://github.com/gangtan) | [vtable_resolver.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/vtable_resolver.py) · [interproc_field_writer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/interproc_field_writer.py) · [arm64_global_tracker.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/arm64_global_tracker.py) |
| [Extracting Protocol Format as State Machine via Controlled Static Loop Analysis](https://arxiv.org/abs/2305.13483) | [Qingkai Shi](https://github.com/qingkaishi), Xiangzhe Xu, Xiangyu Zhang | [proto_fsm.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/proto_fsm.py) |
| [NEMETYL: Message Type Identification of Binary Network Protocols using Continuous Segment Similarity](https://arxiv.org/abs/2002.03391) | [Stephan Kleber](https://github.com/vs-uulm), Rens Wouter van der Heijden, [Frank Kargl](https://github.com/fkargl) | [proto_fsm.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/proto_fsm.py) |
| [Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice](https://dl.acm.org/doi/10.1145/2810103.2813707) | [David Adrian](https://github.com/dadrian), Karthikeyan Bhargavan, [Zakir Durumeric](https://github.com/zakird), Pierrick Gaudry, Matthew Green, [J. Alex Halderman](https://github.com/jhalderm), [Nadia Heninger](https://github.com/factorable), Drew Springall, Emmanuel Thomé, [Luke Valenta](https://github.com/lukevalenta) | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |
| [Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM in TLS](https://www.usenix.org/conference/woot16/workshop-program/presentation/bock) | [Hanno Böck](https://github.com/hannob), [Aaron Zauner](https://github.com/azet), Sean Devlin, [Juraj Somorovsky](https://github.com/jurajsomorovsky), [Philipp Jovanovic](https://github.com/Daeinar) | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |
| [Whitening Sentence Representations for Better Semantics and Faster Retrieval](https://arxiv.org/abs/2103.15316) | [Jianlin Su](https://github.com/bojone), [Jiarun Cao](https://github.com/jiaruncao), Weijie Liu, Yangyiwen Ou | [semantic_search.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/semantic_search.py) |
| [Constant Propagation with Conditional Branches](https://dl.acm.org/doi/abs/10.1145/103135.103136) | Mark N. Wegman, F. Kenneth Zadeck | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| [A Simple, Fast Dominance Algorithm](https://www.cs.princeton.edu/techreports/2005/737.pdf) | Cooper, Harvey, Kennedy | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| [libdft: Practical Dynamic Data Flow Tracking for Commodity Systems](https://dl.acm.org/doi/10.1145/2151024.2151042) | [Vasileios P. Kemerlis](https://github.com/vkemerlis), [Georgios Portokalidis](https://github.com/portokalidis), [Kangkook Jee](https://github.com/jikk), Angelos D. Keromytis | [taint_tracker_x86.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_x86.py) · [taint_tracker_arm32.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_arm32.py) |

**Bücher** bereitgestellt von [www.oreilly.com](https://www.oreilly.com) | [github.com/oreillymedia](https://github.com/oreillymedia)

| Titel | Autoren | Zitation |
|---|---|---|
| The Art of Software Security Assessment | [Mark Dowd](https://github.com/mdowd79), John McDonald, [Justin Schuh](https://github.com/jschuh) | [heap_vuln_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/heap_vuln_scanner.py) · [format_string_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/format_string_scanner.py) · [ioctl_attack_surface.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/ioctl_attack_surface.py) |
| Practical Binary Analysis | [Dennis Andriesse](https://github.com/dennisaa) | [taint_tracker_x86.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_x86.py) · [disasm_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/disasm_engine.py) |
| Practical Malware Analysis | Michael Sikorski, Andrew Honig | [pe_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/pe_parser.py) · [shellcode_utils.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/shellcode_utils.py) |
| Practical Reverse Engineering | Bruce Dang, Alexandre Gazet, [Elias Bachaalany](https://github.com/0xeb) | [pe_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/pe_analyzer.py) · [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) |
| Hacking: The Art of Exploitation (2e) | Jon Erickson | [platform_detect.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/platform_detect.py) |
| Learning Linux Binary Analysis | [Ryan O'Neill](https://github.com/elfmaster) | [elf_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/elf_parser.py) · [binary_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/binary_parser.py) |
| Windows Internals Part 1 & 2 | [Pavel Yosifovich](https://github.com/zodiacon), [Mark Russinovich](https://github.com/markrussinovich), David Solomon, [Alex Ionescu](https://github.com/ionescu007), [Andrea Allievi](https://github.com/AaLl86) | [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) · [ioctl_attack_surface.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/ioctl_attack_surface.py) |
| Rootkits: Subverting the Windows Kernel | Greg Hoglund, Jamie Butler | [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) · [yara_generator.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/yara_generator.py) |
| Advanced Compiler Design and Implementation | Steven Muchnick | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| Engineering a Compiler | Keith Cooper, Linda Torczon | [disasm_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/disasm_engine.py) |
| Practical IoT Hacking | [Fotios Chantzis](https://github.com/ithilgore), Ioannis Stais, Paulino Calderon, Evangelos Deirmentzoglou, Beau Woods | [firmware_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/firmware_analyzer.py) |
| Inside the Android OS: Building, Customizing, Managing and Operating Android System Services | G. Blake Meike | [apk_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/apk_parser.py) · [jni_bridge_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/jni_bridge_scanner.py) · [binder_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/binder_scanner.py) |
| Malware Analysis and Detection Engineering | [Abhijit Mohanta](https://github.com/amohanta), Anoop Saldanha | [yara_generator.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/yara_generator.py) |
| Evasive Malware | [Kyle Cucci](https://github.com/d4rksystem) | [process_enum.py](https://github.com/Ablation-Tool/ablation/blob/main/modules/process_enum.py) |
| Hacking Cryptography | [Kamran Khan](https://github.com/krkhan), [Bill Cox](https://github.com/waywardgeek) | [tls_enum.py](https://github.com/Ablation-Tool/ablation/blob/main/modules/tls_enum.py) |
| Real-World Cryptography | David Wong | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |

**Lobende Erwähnung**

[Microsoft Excel (Data Analysis ToolPak)](https://support.microsoft.com/en-us/office/use-the-analysis-toolpak-to-perform-complex-data-analysis-6c67ccf0-f4a9-487c-8dec-bdb5a2cefab6) Bei der Analyse geschlossener Infrastrukturen oder der Absicherung von Black-Box-Systemen wird genau dieser Prozess als Timing-Analyse oder Telemetrie-Reverse-Engineering bezeichnet. Ohne Quellcode zerlegt das Data Analysis ToolPak mathematisch, wie eine Anwendung im Backend funktioniert, indem es streng ihre Ein- und Ausgaben beobachtet.

---

## Framework-Architektur & Modul-Orchestrierung```mermaid
flowchart TD
    Binary(["<b>Target Binary</b><br/><i>ELF · PE · firmware</i>"])
    Claude(["<b>Claude Code (Orchestrator)</b><br/><i>Central Agent Controller</i>"])

    Binary -->|"load"| BCtx["<b>BinaryContext</b><br/><i>PLT · Strings · Call Graph · XRefs</i>"]
    BCtx -->|"context"| Corpus["<b>Corpus Builder</b><br/><i>Semantic Embedding DB</i>"]
    BCtx -->|"context"| Taint["<b>Taint Engine</b><br/><i>Data Flow / Sinks</i>"]
    BCtx -->|"context"| Diffing["<b>Diffing Engine</b><br/><i>DTW / Version Delta</i>"]
    BCtx -->|"context"| FmtStr["<b>Format String</b><br/><i>Specifier Scanner</i>"]
    BCtx -->|"context"| Heap["<b>Heap Scanner</b><br/><i>Chunk / UAF Audit</i>"]
    BCtx -->|"context"| MultiArch["<b>Multi-Arch Engine</b><br/><i>MIPS · PPC · RISC-V · ARC · V850</i>"]
    BCtx -->|"context"| Driver["<b>Driver Engine</b><br/><i>Kernel IOCTL / BYOVD Audit</i>"]

    Corpus -->|"embeddings"| Semantic["<b>Semantic Search</b><br/><i>BERT Behavioral Fingerprints</i>"]

    Semantic -. "candidates" .-> Claude
    Taint -. "findings" .-> Claude
    Diffing -. "findings" .-> Claude
    FmtStr -. "findings" .-> Claude
    Heap -. "findings" .-> Claude
    MultiArch -. "findings" .-> Claude
    Driver -. "findings" .-> Claude

    Claude -->|"confirmed finding"| Registry["<b>Finding Registry</b><br/><i>Cross-Target Corpus</i>"]
    Registry -->|"seeds future sweeps"| Semantic

    classDef primary fill:#2a1a4a,stroke:#7c3aed,stroke-width:2px,color:#fff
    classDef foundation fill:#0d1117,stroke:#58a6ff,stroke-width:2px,color:#e5e7eb
    classDef engine fill:#171717,stroke:#404040,stroke-width:1px,color:#e5e7eb
    classDef feedback fill:#0d2818,stroke:#238636,stroke-width:2px,color:#e5e7eb

    class Claude,Binary primary
    class BCtx foundation
    class Corpus,Semantic,Taint,Diffing,FmtStr,Heap,MultiArch,Driver engine
    class Registry feedback

Beispiel-RE-Workflow

End-to-End-Analyse von gestrippten Binaries aus einem RPM-Bundle. Extraktion über BinaryContext, String-Xrefs und Capstone-Disassembly bis hin zu bestätigten Findings.```mermaid flowchart TD RPM["target-package.rpm
third-party bundle · x86-64"]

root@kitploit:~
RPM -->|rpm2cpio / cpio| EXTRACT["platform/linux-x86_64/"]

EXTRACT --> PI["bin/inference_engine<br/>stripped PIE · x86-64"]
EXTRACT --> CTRL["bin/controller<br/>stripped PIE · x86-64"]
EXTRACT --> LIBS["lib/libcore.so<br/>lib/libruntime.so"]

subgraph TRACK_PI ["inference engine track"]
    direction TB
    BCI["BinaryContext.load_or_build()<br/>32 func starts · 551 strings · PLT built"]
    BCI --> SS["ctx.strings scan<br/>api_op_read VA 0x51560<br/>api_op_write VA 0x51570<br/>license_key_flag 0x52e08"]
    SS --> XREF["ctx.string_xrefs()<br/>both ops xref → 0x17499, 0x174af<br/>ctx.func_containing() → init fn 0x10000"]
    XREF --> DA1["capstone disasm 0x17450<br/>lea rsi → api_op_read · call set::insert<br/>lea rsi → api_op_write · call set::insert<br/>CONFIRMED: exactly 2 blocklist entries"]
    DA1 --> DA2["capstone disasm 0x16511<br/>cmp qword ptr [r9], 0<br/>je → model loads · ne → handleFatal<br/>empty set = bypass confirmed"]
end

subgraph TRACK_LIBS ["library analysis"]
    direction TB
    NM["nm -D libcore.so<br/>spawn at 0xfdb20 · ctor at 0xfcfd0"]
    NM --> DA3["capstone disasm libcore.so:0xfdbc7<br/>cmp entry length == exe_path length<br/>memcmp at 0xfdbdb<br/>proper equality check · no prefix bypass"]
    LSCAN["re.findall api_op:: in libruntime.so<br/>2481 distinct ops found<br/>2 blocked · 2479 unblocked"]
end

subgraph TRACK_CTRL ["controller track"]
    direction TB
    BCC["BinaryContext.load_or_build()<br/>18 func starts · PLT · strings"]
    BCC --> XREF2["ctx.string_xrefs() on 5 path strings<br/>./worker1 · ./worker2<br/>./worker3 · ./worker4<br/>./inference_engine<br/>all xref at 0x9a04-0x9a5e"]
    XREF2 --> DA4["capstone disasm 0x99e9<br/>call CApp::progDir()<br/>call OsUtils::chdir()<br/>chdir to binary dir before spawn"]
    DA4 --> DA5["capstone disasm 0x11500<br/>args vector from command pipe tokens<br/>passed raw to spawn() at 0x11699<br/>no validation"]
end

PI --> BCI
PI --> BCC
LIBS --> NM
LIBS --> LSCAN

DA2 --> F1
LSCAN --> F1["F1 · HIGH<br/>blocklist covers 2 of 2481 ops<br/>upload malicious model via API<br/>seccomp BPF not decoded — CIA open"]

DA3 --> F2
XREF2 --> F2["F2 · LOW<br/>controller spawn allowlist is sound<br/>but args vector unchecked<br/>requires service user pipe access"]

DA5 --> F2

SS --> F3["F3 · INFO<br/>license gate = JSON field only<br/>no cryptographic verification"]

classDef finding fill:#1a1a2e,stroke:#e94560,stroke-width:2px,color:#fff
classDef tool fill:#16213e,stroke:#0f3460,stroke-width:1px,color:#e5e7eb
classDef binary fill:#0f3460,stroke:#533483,stroke-width:2px,color:#fff
classDef input fill:#533483,stroke:#7c3aed,stroke-width:2px,color:#fff

class F1,F2,F3 finding
class BCI,BCC,NM,LSCAN,SS,XREF,XREF2,DA1,DA2,DA3,DA4,DA5 tool
class PI,CTRL,LIBS binary
class RPM,EXTRACT input
root@kitploit:~
Tool herunterladen
CVEProduktTitelCVSSAdvisory
CVE-2026-76420Secure Firewall Management Center (FMC)Peer Impersonation9.0 Criticalcisco-sa-fmc2-multivulns-HXgcqRG
CVE-2026-76412Secure Firewall Management Center (FMC)Privilege Escalation to root8.5 Highcisco-sa-fmc2-multivulns-HXgcqRG
CVE-2026-76413Secure Firewall Management Center (FMC)Single Sign-On Token Forgery8.5 Highcisco-sa-fmc2-multivulns-HXgcqRG
CVE-2026-76447Identity Services Engine (ISE)OCSP Responder Authentication Bypass5.3 Mediumcisco-sa-ise-multiauth-bypass-sgD2HbL4
ArchitekturVarianten
x86x86-32 · x86-64
ARMARM-32 · ARM-64
MIPSMIPS-32 · nanoMIPS · MIPS-64
PowerPCPPC-32 · PPC-64
RISC-VRISC-V 32 · RISC-V 64
EmbeddedARC EM/HS · V850-32