
Framework de rétro-ingénierie avec désassemblage, décompilation, analyse de teinte, comparaison de versions et recherche sémantique, plus l'analyse autonome de binaires et de firmwares pilotée par LLM.
Ablation est un framework de reverse engineering qui fournit exactement les mêmes capacités fondamentales de désassemblage, de décompilation et d'analyse binaire que les outils standards du secteur tels que Ghidra, IDA Pro et Binary Ninja.
Combiné à Claude Code ou OpenAI Codex, il se transforme en un outil de reverse engineering entièrement autonome.

Recherche sémantique via BERT : La recherche sémantique trouve des résultats en fonction du sens plutôt que de mots-clés exacts. BERT lit le texte et détermine ce qu'il signifie. Des significations similaires obtiennent des scores similaires, ce qui vous permet de rechercher par concept plutôt que par mots exacts. En combinant les deux, cela accélère le principal goulot d'étranglement du reverse engineering tout en trouvant les fonctions vulnérables.
Performance extrême : Un binaire de 50 Mo se charge en 35 secondes. Ghidra et IDA Pro peuvent prendre des heures car ils analysent l'intégralité du fichier dans une base de données avant que vous puissiez faire quoi que ce soit. Ablation n'analyse que les fonctions sur lesquelles vous travaillez activement, ce qui vous permet de commencer immédiatement.
Diff de versions : En utilisant la méthode de Jaccard pour mesurer le degré de recouvrement du comportement d'une fonction entre les versions et le Dynamic Time Warping qui suit la « forme » de l'exécution d'une fonction à travers ces versions de firmware ou de logiciel qu'un fournisseur a mises à jour, Ablation confirme si un correctif a réellement modifié la logique ou seulement l'empaquetage, car une recompilation cosmétique ne peut pas masquer une vulnérabilité non corrigée.
Analyse inter-binaires : Analysez simultanément chaque bibliothèque partagée d'une image de firmware, en suivant les flux de données à travers les frontières entre binaires.
Audit de code source : Auditez n'importe quelle base de code volumineuse plus rapidement qu'une lecture linéaire, avec une précision supérieure à la simple correspondance de motifs. Chaque fichier source reçoit un profil de sécurité sur 5 bits qui détermine exactement combien d'attention il nécessite, de sorte que rien n'est oublié et que rien n'est lu deux fois.
Analyse des pilotes du noyau Windows et BYOVD : Cartographie la table de dispatch IRP, décode chaque code IOCTL et identifie quelles API du noyau exposent la mémoire physique et les primitives de jeton depuis le mode utilisateur. Le détecteur BYOVD prend l'empreinte des pilotes signés portant ces capacités, car un seul pilote signé légitime suffit à aveugler un EDR depuis le ring-0.
Analyse Android / APK : Lit les APK Android au niveau binaire sans aucune dépendance. Il cartographie les points d'entrée du code natif et la surface IPC à partir du bytecode compilé, de sorte que toute la surface est visible sans décompilation.
Analyse Erlang / BEAM : Erlang se compile en fichiers .beam, et la même approche de cartographie de surface utilisée pour ELF s'applique directement, de sorte que la recherche d'atomes, l'audit des imports et la détection d'obfuscation ne nécessitent aucun traitement particulier. Balayer un répertoire de release prend quelques secondes.
Déchiffrement
Ablation a été utilisé pour analyser des firmwares de production et des pilotes du noyau de Fortinet, Cisco, Juniper, Axis, Fujitsu, MikroTik, Orka, TencentOS, Enigma2, Skydio et Dahua Security System.
À la suite d'une divulgation coordonnée concernant Cisco FMC et ISE, le Cisco Product Security Incident Response Team (PSIRT) a adopté Ablation pour le triage interne des vulnérabilités. Le Cisco PSIRT l'utilise activement pour trier les rapports de divulgation en cours concernant Firepower Threat Defense (FTD), Cisco Secure Client (AnyConnect), HyperFlex et Catalyst. Cisco Adaptive Security Appliance (ASA) LINA a également été reverse-engineered à l'aide d'Ablation, les résultats étant actuellement en cours de triage coordonné via CERT/CC VINCE.
| Fournisseur | Modèles |
|---|---|
| Claude Code | /model claude-sonnet-4-6 |
| OpenAI Codex | Tous les modèles connus |
pip install git+https://github.com/Ablation-Tool/ablation
---
## Prérequis
- Python >= 3.10
- `capstone`, `numpy`, `lief`, `sentence-transformers`, `pyelftools`
- Optionnel : `anthropic` pour les fonctionnalités LLM
---
## Utilisation responsable
Ablation est conçu pour la recherche en sécurité autorisée. Utilisez-le uniquement contre des systèmes que vous possédez ou pour lesquels vous disposez d'une autorisation écrite explicite de test. L'exécuter contre des systèmes sans autorisation enfreint les lois sur la fraude informatique dans la plupart des juridictions. Les auteurs ne sont pas responsables d'une mauvaise utilisation.
---
## Remerciements
Ce projet a été grandement informé et inspiré par plusieurs œuvres littéraires clés.
**Articles de recherche**
| Titre | Auteurs | Citation |
|---|---|---|
| [Finding Taint-Style Vulnerabilities in Linux-based Embedded Firmware with SSE-based Alias Analysis](https://arxiv.org/abs/2109.12209) | Cheng, Zheng, Liu, Guan, Liu, Li, Zhu, Ye, Sun | [sse_slicer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/sse_slicer.py) · [arm64_global_tracker.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/arm64_global_tracker.py) |
| [iResolveX: Multi-Layered Indirect Call Resolution via Static Reasoning and Learning-Augmented Refinement](https://arxiv.org/abs/2601.17888) | Monika Santra, Bokai Zhang, Mark Lim, [Vishnu Asutosh Dasu](https://github.com/vdasu), Dongrui Zeng, [Gang Tan](https://github.com/gangtan) | [vtable_resolver.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/vtable_resolver.py) · [interproc_field_writer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/interproc_field_writer.py) · [arm64_global_tracker.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/arm64_global_tracker.py) |
| [Extracting Protocol Format as State Machine via Controlled Static Loop Analysis](https://arxiv.org/abs/2305.13483) | [Qingkai Shi](https://github.com/qingkaishi), Xiangzhe Xu, Xiangyu Zhang | [proto_fsm.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/proto_fsm.py) |
| [NEMETYL: Message Type Identification of Binary Network Protocols using Continuous Segment Similarity](https://arxiv.org/abs/2002.03391) | [Stephan Kleber](https://github.com/vs-uulm), Rens Wouter van der Heijden, [Frank Kargl](https://github.com/fkargl) | [proto_fsm.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/proto_fsm.py) |
| [Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice](https://dl.acm.org/doi/10.1145/2810103.2813707) | [David Adrian](https://github.com/dadrian), Karthikeyan Bhargavan, [Zakir Durumeric](https://github.com/zakird), Pierrick Gaudry, Matthew Green, [J. Alex Halderman](https://github.com/jhalderm), [Nadia Heninger](https://github.com/factorable), Drew Springall, Emmanuel Thomé, [Luke Valenta](https://github.com/lukevalenta) | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |
| [Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM in TLS](https://www.usenix.org/conference/woot16/workshop-program/presentation/bock) | [Hanno Böck](https://github.com/hannob), [Aaron Zauner](https://github.com/azet), Sean Devlin, [Juraj Somorovsky](https://github.com/jurajsomorovsky), [Philipp Jovanovic](https://github.com/Daeinar) | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |
| [Whitening Sentence Representations for Better Semantics and Faster Retrieval](https://arxiv.org/abs/2103.15316) | [Jianlin Su](https://github.com/bojone), [Jiarun Cao](https://github.com/jiaruncao), Weijie Liu, Yangyiwen Ou | [semantic_search.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/semantic_search.py) |
| [Constant Propagation with Conditional Branches](https://dl.acm.org/doi/abs/10.1145/103135.103136) | Mark N. Wegman, F. Kenneth Zadeck | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| [A Simple, Fast Dominance Algorithm](https://www.cs.princeton.edu/techreports/2005/737.pdf) | Cooper, Harvey, Kennedy | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| [libdft: Practical Dynamic Data Flow Tracking for Commodity Systems](https://dl.acm.org/doi/10.1145/2151024.2151042) | [Vasileios P. Kemerlis](https://github.com/vkemerlis), [Georgios Portokalidis](https://github.com/portokalidis), [Kangkook Jee](https://github.com/jikk), Angelos D. Keromytis | [taint_tracker_x86.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_x86.py) · [taint_tracker_arm32.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_arm32.py) |
**Livres** fournis par [www.oreilly.com](https://www.oreilly.com) | [github.com/oreillymedia](https://github.com/oreillymedia)
| Titre | Auteurs | Citation |
|---|---|---|
| The Art of Software Security Assessment | [Mark Dowd](https://github.com/mdowd79), John McDonald, [Justin Schuh](https://github.com/jschuh) | [heap_vuln_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/heap_vuln_scanner.py) · [format_string_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/format_string_scanner.py) · [ioctl_attack_surface.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/ioctl_attack_surface.py) |
| Practical Binary Analysis | [Dennis Andriesse](https://github.com/dennisaa) | [taint_tracker_x86.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_x86.py) · [disasm_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/disasm_engine.py) |
| Practical Malware Analysis | Michael Sikorski, Andrew Honig | [pe_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/pe_parser.py) · [shellcode_utils.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/shellcode_utils.py) |
| Practical Reverse Engineering | Bruce Dang, Alexandre Gazet, [Elias Bachaalany](https://github.com/0xeb) | [pe_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/pe_analyzer.py) · [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) |
| Hacking: The Art of Exploitation (2e) | Jon Erickson | [platform_detect.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/platform_detect.py) |
| Learning Linux Binary Analysis | [Ryan O'Neill](https://github.com/elfmaster) | [elf_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/elf_parser.py) · [binary_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/binary_parser.py) |
| Windows Internals Part 1 & 2 | [Pavel Yosifovich](https://github.com/zodiacon), [Mark Russinovich](https://github.com/markrussinovich), David Solomon, [Alex Ionescu](https://github.com/ionescu007), [Andrea Allievi](https://github.com/AaLl86) | [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) · [ioctl_attack_surface.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/ioctl_attack_surface.py) |
| Rootkits: Subverting the Windows Kernel | Greg Hoglund, Jamie Butler | [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) · [yara_generator.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/yara_generator.py) |
| Advanced Compiler Design and Implementation | Steven Muchnick | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| Engineering a Compiler | Keith Cooper, Linda Torczon | [disasm_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/disasm_engine.py) |
| Practical IoT Hacking | [Fotios Chantzis](https://github.com/ithilgore), Ioannis Stais, Paulino Calderon, Evangelos Deirmentzoglou, Beau Woods | [firmware_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/firmware_analyzer.py) |
| Inside the Android OS: Building, Customizing, Managing and Operating Android System Services | G. Blake Meike | [apk_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/apk_parser.py) · [jni_bridge_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/jni_bridge_scanner.py) · [binder_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/binder_scanner.py) |
| Malware Analysis and Detection Engineering | [Abhijit Mohanta](https://github.com/amohanta), Anoop Saldanha | [yara_generator.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/yara_generator.py) |
| Evasive Malware | [Kyle Cucci](https://github.com/d4rksystem) | [process_enum.py](https://github.com/Ablation-Tool/ablation/blob/main/modules/process_enum.py) |
| Hacking Cryptography | [Kamran Khan](https://github.com/krkhan), [Bill Cox](https://github.com/waywardgeek) | [tls_enum.py](https://github.com/Ablation-Tool/ablation/blob/main/modules/tls_enum.py) |
| Real-World Cryptography | David Wong | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |
**Mention honorable**
[Microsoft Excel (Data Analysis ToolPak)](https://support.microsoft.com/en-us/office/use-the-analysis-toolpak-to-perform-complex-data-analysis-6c67ccf0-f4a9-487c-8dec-bdb5a2cefab6) Lors de l'analyse d'une infrastructure fermée ou de la sécurisation de systèmes en boîte noire, ce processus exact est appelé analyse temporelle ou rétro-ingénierie de télémétrie. Sans code source, le Data Analysis ToolPak déconstruit mathématiquement le fonctionnement d'une application côté backend en observant strictement ses entrées et sorties.
---
## Architecture du framework et orchestration des modules```mermaid
flowchart TD
Binary(["<b>Target Binary</b><br/><i>ELF · PE · firmware</i>"])
Claude(["<b>Claude Code (Orchestrator)</b><br/><i>Central Agent Controller</i>"])
Binary -->|"load"| BCtx["<b>BinaryContext</b><br/><i>PLT · Strings · Call Graph · XRefs</i>"]
BCtx -->|"context"| Corpus["<b>Corpus Builder</b><br/><i>Semantic Embedding DB</i>"]
BCtx -->|"context"| Taint["<b>Taint Engine</b><br/><i>Data Flow / Sinks</i>"]
BCtx -->|"context"| Diffing["<b>Diffing Engine</b><br/><i>DTW / Version Delta</i>"]
BCtx -->|"context"| FmtStr["<b>Format String</b><br/><i>Specifier Scanner</i>"]
BCtx -->|"context"| Heap["<b>Heap Scanner</b><br/><i>Chunk / UAF Audit</i>"]
BCtx -->|"context"| MultiArch["<b>Multi-Arch Engine</b><br/><i>MIPS · PPC · RISC-V · ARC · V850</i>"]
BCtx -->|"context"| Driver["<b>Driver Engine</b><br/><i>Kernel IOCTL / BYOVD Audit</i>"]
Corpus -->|"embeddings"| Semantic["<b>Semantic Search</b><br/><i>BERT Behavioral Fingerprints</i>"]
Semantic -. "candidates" .-> Claude
Taint -. "findings" .-> Claude
Diffing -. "findings" .-> Claude
FmtStr -. "findings" .-> Claude
Heap -. "findings" .-> Claude
MultiArch -. "findings" .-> Claude
Driver -. "findings" .-> Claude
Claude -->|"confirmed finding"| Registry["<b>Finding Registry</b><br/><i>Cross-Target Corpus</i>"]
Registry -->|"seeds future sweeps"| Semantic
classDef primary fill:#2a1a4a,stroke:#7c3aed,stroke-width:2px,color:#fff
classDef foundation fill:#0d1117,stroke:#58a6ff,stroke-width:2px,color:#e5e7eb
classDef engine fill:#171717,stroke:#404040,stroke-width:1px,color:#e5e7eb
classDef feedback fill:#0d2818,stroke:#238636,stroke-width:2px,color:#e5e7eb
class Claude,Binary primary
class BCtx foundation
class Corpus,Semantic,Taint,Diffing,FmtStr,Heap,MultiArch,Driver engine
class Registry feedback
Analyse de bout en bout de binaires strippés à partir d'un bundle RPM. Extraction via BinaryContext, xrefs de chaînes et désassemblage capstone jusqu'à la confirmation des résultats.```mermaid
flowchart TD
RPM["target-package.rpm
third-party bundle · x86-64"]
RPM -->|rpm2cpio / cpio| EXTRACT["platform/linux-x86_64/"]
EXTRACT --> PI["bin/inference_engine<br/>stripped PIE · x86-64"]
EXTRACT --> CTRL["bin/controller<br/>stripped PIE · x86-64"]
EXTRACT --> LIBS["lib/libcore.so<br/>lib/libruntime.so"]
subgraph TRACK_PI ["inference engine track"]
direction TB
BCI["BinaryContext.load_or_build()<br/>32 func starts · 551 strings · PLT built"]
BCI --> SS["ctx.strings scan<br/>api_op_read VA 0x51560<br/>api_op_write VA 0x51570<br/>license_key_flag 0x52e08"]
SS --> XREF["ctx.string_xrefs()<br/>both ops xref → 0x17499, 0x174af<br/>ctx.func_containing() → init fn 0x10000"]
XREF --> DA1["capstone disasm 0x17450<br/>lea rsi → api_op_read · call set::insert<br/>lea rsi → api_op_write · call set::insert<br/>CONFIRMED: exactly 2 blocklist entries"]
DA1 --> DA2["capstone disasm 0x16511<br/>cmp qword ptr [r9], 0<br/>je → model loads · ne → handleFatal<br/>empty set = bypass confirmed"]
end
subgraph TRACK_LIBS ["library analysis"]
direction TB
NM["nm -D libcore.so<br/>spawn at 0xfdb20 · ctor at 0xfcfd0"]
NM --> DA3["capstone disasm libcore.so:0xfdbc7<br/>cmp entry length == exe_path length<br/>memcmp at 0xfdbdb<br/>proper equality check · no prefix bypass"]
LSCAN["re.findall api_op:: in libruntime.so<br/>2481 distinct ops found<br/>2 blocked · 2479 unblocked"]
end
subgraph TRACK_CTRL ["controller track"]
direction TB
BCC["BinaryContext.load_or_build()<br/>18 func starts · PLT · strings"]
BCC --> XREF2["ctx.string_xrefs() on 5 path strings<br/>./worker1 · ./worker2<br/>./worker3 · ./worker4<br/>./inference_engine<br/>all xref at 0x9a04-0x9a5e"]
XREF2 --> DA4["capstone disasm 0x99e9<br/>call CApp::progDir()<br/>call OsUtils::chdir()<br/>chdir to binary dir before spawn"]
DA4 --> DA5["capstone disasm 0x11500<br/>args vector from command pipe tokens<br/>passed raw to spawn() at 0x11699<br/>no validation"]
end
PI --> BCI
PI --> BCC
LIBS --> NM
LIBS --> LSCAN
DA2 --> F1
LSCAN --> F1["F1 · HIGH<br/>blocklist covers 2 of 2481 ops<br/>upload malicious model via API<br/>seccomp BPF not decoded — CIA open"]
DA3 --> F2
XREF2 --> F2["F2 · LOW<br/>controller spawn allowlist is sound<br/>but args vector unchecked<br/>requires service user pipe access"]
DA5 --> F2
SS --> F3["F3 · INFO<br/>license gate = JSON field only<br/>no cryptographic verification"]
classDef finding fill:#1a1a2e,stroke:#e94560,stroke-width:2px,color:#fff
classDef tool fill:#16213e,stroke:#0f3460,stroke-width:1px,color:#e5e7eb
classDef binary fill:#0f3460,stroke:#533483,stroke-width:2px,color:#fff
classDef input fill:#533483,stroke:#7c3aed,stroke-width:2px,color:#fff
class F1,F2,F3 finding
class BCI,BCC,NM,LSCAN,SS,XREF,XREF2,DA1,DA2,DA3,DA4,DA5 tool
class PI,CTRL,LIBS binary
class RPM,EXTRACT input
| CVE | Produit | Titre | CVSS | Avis |
|---|
| CVE-2026-76420 | Secure Firewall Management Center (FMC) | Usurpation de pair | 9.0 Critique | cisco-sa-fmc2-multivulns-HXgcqRG |
| CVE-2026-76412 | Secure Firewall Management Center (FMC) | Élévation de privilèges vers root | 8.5 Élevée | cisco-sa-fmc2-multivulns-HXgcqRG |
| CVE-2026-76413 | Secure Firewall Management Center (FMC) | Falsification de jeton Single Sign-On | 8.5 Élevée | cisco-sa-fmc2-multivulns-HXgcqRG |
| CVE-2026-76447 | Identity Services Engine (ISE) | Contournement d'authentification du répondeur OCSP | 5.3 Moyenne | cisco-sa-ise-multiauth-bypass-sgD2HbL4 |
| Architecture | Variantes |
|---|
| x86 | x86-32 · x86-64 |
| ARM | ARM-32 · ARM-64 |
| MIPS | MIPS-32 · nanoMIPS · MIPS-64 |
| PowerPC | PPC-32 · PPC-64 |
| RISC-V | RISC-V 32 · RISC-V 64 |
| Embarqué | ARC EM/HS · V850-32 |