Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ablation — Reverse engineering framework with disassembly, decompilation, taint analysis, version diffing and semantic search, plus LLM-driven autonomous binary and firmware analysis. | Kitploit
Tools/GitHubGitHub/ablation-tool/ablation
Android SecurityStatic AnalysisVulnerability AnalysisReverse EngineeringMalware AnalysisCryptographyBinary AnalysisPapers & ResearchAI-Assisted ReversingFirmware Analysis
GitHub
35286h 36m agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
ablation-tool/ablation

ablation

Reverse engineering framework with disassembly, decompilation, taint analysis, version diffing and semantic search, plus LLM-driven autonomous binary and firmware analysis.

View Repository
ABLATION

Ablation is a reverse engineering framework that provides the exact same core disassembly, decompilation, and binary analysis capabilities as industry-standard tools like Ghidra, IDA Pro, and Binary Ninja.

Combined with Claude Code or OpenAI Codex, it transforms into a fully autonomous reverse engineering tool.


Codex demo

Capabilities

Semantic Search via BERT: Semantic search finds results based on meaning rather than exact keywords. BERT reads text and figures out what it means. Similar meanings get similar scores, so you can search by concept instead of exact words. By combining the two, it speeds up the main bottleneck of reverse engineering while finding the vulnerable functions.

Extreme Performance: A 50 MB binary loads in 35 seconds. Ghidra and IDA Pro can take hours because they parse the entire file into a database before you can do anything. Ablation only analyzes the functions you are actively working on, so you start immediately.

Version Diffing: Utilizing the Jaccard method to measure how much a function's behavior overlaps between releases and Dynamic Time Warping that tracks the "shape" of how a function executes across those versions of firmware or software that a vendor updated, Ablation confirms whether a patch actually changed the logic or just the packaging, because a cosmetic recompile can't hide an unpatched vulnerability.

Cross-Binary Analysis: Analyze every shared library in a firmware image simultaneously, tracking data flows across binary boundaries.

Source Code Audit: Audit any large codebase faster than reading it linearly, with higher accuracy than pattern matching alone. Every source file gets a 5-bit security profile that determines exactly how much attention it needs, so nothing gets missed and nothing gets read twice.

Windows Kernel Driver & BYOVD Analysis: Maps the IRP dispatch table, decodes every IOCTL code, and identifies which kernel APIs expose physical memory and token primitives from user mode. The BYOVD Detector fingerprints signed drivers carrying those capabilities, because one legitimate signed driver is enough to blind EDR from ring-0.

Android / APK Analysis: Reads Android APKs at the binary level with no dependencies. It maps native code entry points and IPC surface from compiled bytecode, so the full surface is visible without decompiling.

Erlang / BEAM Analysis: Erlang compiles to .beam files, and the same surface-map approach used for ELF applies directly, so atom search, import auditing, and obfuscation detection need no special handling. Sweeping a release directory takes seconds.

Decryption

  • Entropy Mapper: Finds encrypted, compressed, or packed sections in a binary.
  • Crypto Audit: Scans for cryptography.
  • XorSolver: Recovers, then decrypts the target section which allows further reverse engineering.

Real-World Results

Ablation has been used to analyze production firmware and kernel drivers from Fortinet, Cisco, Juniper, Axis, Fujitsu, MikroTik, Orka, TencentOS, Enigma2, Skydio, and Dahua Security System.

Following coordinated disclosure on Cisco FMC and ISE, the Cisco Product Security Incident Response Team (PSIRT) has adopted Ablation for internal vulnerability triage. Cisco PSIRT is actively using it to triage ongoing disclosure reports across Firepower Threat Defense (FTD), Cisco Secure Client (AnyConnect), HyperFlex, and Catalyst. Cisco Adaptive Security Appliance (ASA) LINA has also been reverse engineered using Ablation, with findings currently under coordinated triage via CERT/CC VINCE.


Local Decompilers


LLM Compatibility

ProviderModels
Claude Code/model claude-sonnet-4-6
OpenAI CodexAll known models

Install

root@kitploit:~
pip install git+https://github.com/Ablation-Tool/ablation

Requirements

  • Python >= 3.10
  • capstone, numpy, lief, sentence-transformers, pyelftools
  • Optional: anthropic for LLM features

Responsible Use

Ablation is built for authorized security research. Use it only against systems you own or have explicit written permission to test. Running it against systems without authorization violates computer fraud laws in most jurisdictions. The authors are not responsible for misuse.


Acknowledgments

This project was greatly informed and inspired by several key literary works.

Research Papers

Books supplied by www.oreilly.com | github.com/oreillymedia

Honorable Mention

Microsoft Excel (Data Analysis ToolPak) When analyzing closed infrastructure or securing black-box systems, this exact process is called timing analysis or telemetry reverse engineering. Without source code, the Data Analysis ToolPak mathematically deconstructs how an application works on the backend by strictly observing its inputs and outputs.


Framework Architecture & Module Orchestration

root@kitploit:~
flowchart TD
    Binary(["<b>Target Binary</b><br/><i>ELF · PE · firmware</i>"])
    Claude(["<b>Claude Code (Orchestrator)</b><br/><i>Central Agent Controller</i>"])

    Binary -->|"load"| BCtx["<b>BinaryContext</b><br/><i>PLT · Strings · Call Graph · XRefs</i>"]
    BCtx -->|"context"| Corpus["<b>Corpus Builder</b><br/><i>Semantic Embedding DB</i>"]
    BCtx -->|"context"| Taint["<b>Taint Engine</b><br/><i>Data Flow / Sinks</i>"]
    BCtx -->|"context"| Diffing["<b>Diffing Engine</b><br/><i>DTW / Version Delta</i>"]
    BCtx -->|"context"| FmtStr["<b>Format String</b><br/><i>Specifier Scanner</i>"]
    BCtx -->|"context"| Heap["<b>Heap Scanner</b><br/><i>Chunk / UAF Audit</i>"]
    BCtx -->|"context"| MultiArch["<b>Multi-Arch Engine</b><br/><i>MIPS · PPC · RISC-V · ARC · V850</i>"]
    BCtx -->|"context"| Driver["<b>Driver Engine</b><br/><i>Kernel IOCTL / BYOVD Audit</i>"]

    Corpus -->|"embeddings"| Semantic["<b>Semantic Search</b><br/><i>BERT Behavioral Fingerprints</i>"]

    Semantic -. "candidates" .-> Claude
    Taint -. "findings" .-> Claude
    Diffing -. "findings" .-> Claude
    FmtStr -. "findings" .-> Claude
    Heap -. "findings" .-> Claude
    MultiArch -. "findings" .-> Claude
    Driver -. "findings" .-> Claude

    Claude -->|"confirmed finding"| Registry["<b>Finding Registry</b><br/><i>Cross-Target Corpus</i>"]
    Registry -->|"seeds future sweeps"| Semantic

    classDef primary fill:#2a1a4a,stroke:#7c3aed,stroke-width:2px,color:#fff
    classDef foundation fill:#0d1117,stroke:#58a6ff,stroke-width:2px,color:#e5e7eb
    classDef engine fill:#171717,stroke:#404040,stroke-width:1px,color:#e5e7eb
    classDef feedback fill:#0d2818,stroke:#238636,stroke-width:2px,color:#e5e7eb

    class Claude,Binary primary
    class BCtx foundation
    class Corpus,Semantic,Taint,Diffing,FmtStr,Heap,MultiArch,Driver engine
    class Registry feedback

Example RE Workflow

End-to-end analysis of stripped binaries from an RPM bundle. Extraction through BinaryContext, string xrefs, and capstone disassembly to confirmed findings.

root@kitploit:~
flowchart TD
    RPM["target-package.rpm<br/>third-party bundle · x86-64"]

    RPM -->|rpm2cpio / cpio| EXTRACT["platform/linux-x86_64/"]

    EXTRACT --> PI["bin/inference_engine<br/>stripped PIE · x86-64"]
    EXTRACT --> CTRL["bin/controller<br/>stripped PIE · x86-64"]
    EXTRACT --> LIBS["lib/libcore.so<br/>lib/libruntime.so"]

    subgraph TRACK_PI ["inference engine track"]
        direction TB
        BCI["BinaryContext.load_or_build()<br/>32 func starts · 551 strings · PLT built"]
        BCI --> SS["ctx.strings scan<br/>api_op_read VA 0x51560<br/>api_op_write VA 0x51570<br/>license_key_flag 0x52e08"]
        SS --> XREF["ctx.string_xrefs()<br/>both ops xref → 0x17499, 0x174af<br/>ctx.func_containing() → init fn 0x10000"]
        XREF --> DA1["capstone disasm 0x17450<br/>lea rsi → api_op_read · call set::insert<br/>lea rsi → api_op_write · call set::insert<br/>CONFIRMED: exactly 2 blocklist entries"]
        DA1 --> DA2["capstone disasm 0x16511<br/>cmp qword ptr [r9], 0<br/>je → model loads · ne → handleFatal<br/>empty set = bypass confirmed"]
    end

    subgraph TRACK_LIBS ["library analysis"]
        direction TB
        NM["nm -D libcore.so<br/>spawn at 0xfdb20 · ctor at 0xfcfd0"]
        NM --> DA3["capstone disasm libcore.so:0xfdbc7<br/>cmp entry length == exe_path length<br/>memcmp at 0xfdbdb<br/>proper equality check · no prefix bypass"]
        LSCAN["re.findall api_op:: in libruntime.so<br/>2481 distinct ops found<br/>2 blocked · 2479 unblocked"]
    end

    subgraph TRACK_CTRL ["controller track"]
        direction TB
        BCC["BinaryContext.load_or_build()<br/>18 func starts · PLT · strings"]
        BCC --> XREF2["ctx.string_xrefs() on 5 path strings<br/>./worker1 · ./worker2<br/>./worker3 · ./worker4<br/>./inference_engine<br/>all xref at 0x9a04-0x9a5e"]
        XREF2 --> DA4["capstone disasm 0x99e9<br/>call CApp::progDir()<br/>call OsUtils::chdir()<br/>chdir to binary dir before spawn"]
        DA4 --> DA5["capstone disasm 0x11500<br/>args vector from command pipe tokens<br/>passed raw to spawn() at 0x11699<br/>no validation"]
    end

    PI --> BCI
    PI --> BCC
    LIBS --> NM
    LIBS --> LSCAN

    DA2 --> F1
    LSCAN --> F1["F1 · HIGH<br/>blocklist covers 2 of 2481 ops<br/>upload malicious model via API<br/>seccomp BPF not decoded — CIA open"]

    DA3 --> F2
    XREF2 --> F2["F2 · LOW<br/>controller spawn allowlist is sound<br/>but args vector unchecked<br/>requires service user pipe access"]

    DA5 --> F2

    SS --> F3["F3 · INFO<br/>license gate = JSON field only<br/>no cryptographic verification"]

    classDef finding fill:#1a1a2e,stroke:#e94560,stroke-width:2px,color:#fff
    classDef tool fill:#16213e,stroke:#0f3460,stroke-width:1px,color:#e5e7eb
    classDef binary fill:#0f3460,stroke:#533483,stroke-width:2px,color:#fff
    classDef input fill:#533483,stroke:#7c3aed,stroke-width:2px,color:#fff

    class F1,F2,F3 finding
    class BCI,BCC,NM,LSCAN,SS,XREF,XREF2,DA1,DA2,DA3,DA4,DA5 tool
    class PI,CTRL,LIBS binary
    class RPM,EXTRACT input
Download Tool
CVEProductTitleCVSSAdvisory
CVE-2026-76420Secure Firewall Management Center (FMC)Peer Impersonation9.0 Criticalcisco-sa-fmc2-multivulns-HXgcqRG
CVE-2026-76412Secure Firewall Management Center (FMC)Privilege Escalation to root8.5 Highcisco-sa-fmc2-multivulns-HXgcqRG
CVE-2026-76413Secure Firewall Management Center (FMC)Single Sign-On Token Forgery8.5 Highcisco-sa-fmc2-multivulns-HXgcqRG
CVE-2026-76447Identity Services Engine (ISE)OCSP Responder Authentication Bypass5.3 Mediumcisco-sa-ise-multiauth-bypass-sgD2HbL4
ArchitectureVariants
x86x86-32 · x86-64
ARMARM-32 · ARM-64
MIPSMIPS-32 · nanoMIPS · MIPS-64
PowerPCPPC-32 · PPC-64
RISC-VRISC-V 32 · RISC-V 64
EmbeddedARC EM/HS · V850-32
TitleAuthorsCitation
Finding Taint-Style Vulnerabilities in Linux-based Embedded Firmware with SSE-based Alias AnalysisCheng, Zheng, Liu, Guan, Liu, Li, Zhu, Ye, Sunsse_slicer.py · arm64_global_tracker.py
iResolveX: Multi-Layered Indirect Call Resolution via Static Reasoning and Learning-Augmented RefinementMonika Santra, Bokai Zhang, Mark Lim, Vishnu Asutosh Dasu, Dongrui Zeng, Gang Tanvtable_resolver.py · interproc_field_writer.py · arm64_global_tracker.py
Extracting Protocol Format as State Machine via Controlled Static Loop AnalysisQingkai Shi, Xiangzhe Xu, Xiangyu Zhangproto_fsm.py
NEMETYL: Message Type Identification of Binary Network Protocols using Continuous Segment SimilarityStephan Kleber, Rens Wouter van der Heijden, Frank Karglproto_fsm.py
Imperfect Forward Secrecy: How Diffie-Hellman Fails in PracticeDavid Adrian, Karthikeyan Bhargavan, Zakir Durumeric, Pierrick Gaudry, Matthew Green, J. Alex Halderman, Nadia Heninger, Drew Springall, Emmanuel Thomé, Luke Valentatls_analyzer.py
Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM in TLSHanno Böck, Aaron Zauner, Sean Devlin, Juraj Somorovsky, Philipp Jovanovictls_analyzer.py
Whitening Sentence Representations for Better Semantics and Faster RetrievalJianlin Su, Jiarun Cao, Weijie Liu, Yangyiwen Ousemantic_search.py
Constant Propagation with Conditional BranchesMark N. Wegman, F. Kenneth Zadeckdataflow_engine.py
A Simple, Fast Dominance AlgorithmCooper, Harvey, Kennedydataflow_engine.py
libdft: Practical Dynamic Data Flow Tracking for Commodity SystemsVasileios P. Kemerlis, Georgios Portokalidis, Kangkook Jee, Angelos D. Keromytistaint_tracker_x86.py · taint_tracker_arm32.py
TitleAuthorsCitation
The Art of Software Security AssessmentMark Dowd, John McDonald, Justin Schuhheap_vuln_scanner.py · format_string_scanner.py · ioctl_attack_surface.py
Practical Binary AnalysisDennis Andriessetaint_tracker_x86.py · disasm_engine.py
Practical Malware AnalysisMichael Sikorski, Andrew Honigpe_parser.py · shellcode_utils.py
Practical Reverse EngineeringBruce Dang, Alexandre Gazet, Elias Bachaalanype_analyzer.py · kernel_driver_analyzer.py
Hacking: The Art of Exploitation (2e)Jon Ericksonplatform_detect.py
Learning Linux Binary AnalysisRyan O'Neillelf_parser.py · binary_parser.py
Windows Internals Part 1 & 2Pavel Yosifovich, Mark Russinovich, David Solomon, Alex Ionescu, Andrea Allievikernel_driver_analyzer.py · ioctl_attack_surface.py
Rootkits: Subverting the Windows KernelGreg Hoglund, Jamie Butlerkernel_driver_analyzer.py · yara_generator.py
Advanced Compiler Design and ImplementationSteven Muchnickdataflow_engine.py
Engineering a CompilerKeith Cooper, Linda Torczondisasm_engine.py
Practical IoT HackingFotios Chantzis, Ioannis Stais, Paulino Calderon, Evangelos Deirmentzoglou, Beau Woodsfirmware_analyzer.py
Inside the Android OS: Building, Customizing, Managing and Operating Android System ServicesG. Blake Meikeapk_parser.py · jni_bridge_scanner.py · binder_scanner.py
Malware Analysis and Detection EngineeringAbhijit Mohanta, Anoop Saldanhayara_generator.py
Evasive MalwareKyle Cucciprocess_enum.py
Hacking CryptographyKamran Khan, Bill Coxtls_enum.py
Real-World CryptographyDavid Wongtls_analyzer.py