Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
ablation — रिवर्स इंजीनियरिंग फ्रेमवर्क जिसमें डिसअसेम्बली, डीकंपाइलेशन, टेंट विश्लेषण, वर्जन डिफिंग और सेमांटिक सर्च, साथ ही LLM-संचालित स्वायत्त बाइनरी और फर्मवेयर विश्लेषण शामिल है। | Kitploit
उपकरण/GitHubGitHub/ablation-tool/ablation
एंड्रॉइड सुरक्षास्थैतिक विश्लेषणभेद्यता विश्लेषणरिवर्स इंजीनियरिंगमालवेयर विश्लेषणक्रिप्टोग्राफीबाइनरी विश्लेषणपेपर और शोधAI-सहायित रिवर्सिंगफर्मवेयर विश्लेषण
GitHubablation-tool/ablation
35286घं 36मि पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

ablation

रिवर्स इंजीनियरिंग फ्रेमवर्क जिसमें डिसअसेम्बली, डीकंपाइलेशन, टेंट विश्लेषण, वर्जन डिफिंग और सेमांटिक सर्च, साथ ही LLM-संचालित स्वायत्त बाइनरी और फर्मवेयर विश्लेषण शामिल है।

रिपॉजिटरी देखें
ABLATION

Ablation एक रिवर्स इंजीनियरिंग फ्रेमवर्क है जो Ghidra, IDA Pro, और Binary Ninja जैसे उद्योग-मानक टूल्स की तरह ही समान कोर डिसअसेम्बली, डीकम्पाइलेशन, और बाइनरी विश्लेषण क्षमताएँ प्रदान करता है।

Claude Code या OpenAI Codex के साथ मिलाकर, यह एक पूरी तरह से स्वायत्त रिवर्स इंजीनियरिंग टूल में बदल जाता है।


Codex demo

क्षमताएँ

BERT के माध्यम से सिमेंटिक सर्च: सिमेंटिक सर्च सटीक कीवर्ड के बजाय अर्थ के आधार पर परिणाम ढूँढता है। BERT टेक्स्ट पढ़ता है और समझता है कि इसका क्या मतलब है। समान अर्थों को समान स्कोर मिलते हैं, इसलिए आप सटीक शब्दों के बजाय अवधारणा के आधार पर खोज सकते हैं। दोनों को मिलाकर, यह रिवर्स इंजीनियरिंग की मुख्य बाधा को तेज़ करता है और साथ ही कमज़ोर फंक्शन्स को ढूँढता है।

अत्यधिक प्रदर्शन: एक 50 MB बाइनरी 35 सेकंड में लोड होती है। Ghidra और IDA Pro को घंटे लग सकते हैं क्योंकि वे कुछ भी करने से पहले पूरी फ़ाइल को डेटाबेस में पार्स करते हैं। Ablation केवल उन फंक्शन्स का विश्लेषण करता है जिन पर आप सक्रिय रूप से काम कर रहे हैं, इसलिए आप तुरंत शुरू कर सकते हैं।

वर्ज़न डिफिंग: Jaccard विधि का उपयोग करके यह मापता है कि रिलीज़ के बीच किसी फंक्शन का व्यवहार कितना ओवरलैप करता है, और Dynamic Time Warping जो ट्रैक करता है कि वेंडर द्वारा अपडेट किए गए फर्मवेयर या सॉफ़्टवेयर के उन वर्ज़न्स में कोई फंक्शन कैसे निष्पादित होता है, Ablation पुष्टि करता है कि किसी पैच ने वास्तव में लॉजिक बदला है या केवल पैकेजिंग, क्योंकि एक कॉस्मेटिक रीकम्पाइल एक अनपैच्ड कमज़ोरी को छिपा नहीं सकता।

क्रॉस-बाइनरी विश्लेषण: एक फर्मवेयर इमेज में प्रत्येक साझा लाइब्रेरी का एक साथ विश्लेषण करें, बाइनरी सीमाओं के पार डेटा फ़्लो को ट्रैक करें।

सोर्स कोड ऑडिट: किसी भी बड़े कोडबेस का ऑडिट रैखिक रूप से पढ़ने से तेज़ करें, और अकेले पैटर्न मैचिंग से अधिक सटीकता के साथ। प्रत्येक सोर्स फ़ाइल को 5-बिट सुरक्षा प्रोफ़ाइल मिलती है जो निर्धारित करती है कि उसे कितना ध्यान चाहिए, ताकि कुछ भी छूटे नहीं और कुछ भी दो बार पढ़ा न जाए।

Windows Kernel Driver और BYOVD विश्लेषण: IRP डिस्पैच टेबल को मैप करता है, प्रत्येक IOCTL कोड को डिकोड करता है, और पहचानता है कि कौन से kernel APIs यूज़र मोड से फ़िज़िकल मेमोरी और टोकन प्रिमिटिव्स को उजागर करते हैं। BYOVD Detector उन साइन्ड ड्राइवर्स की फिंगरप्रिंटिंग करता है जो ये क्षमताएँ रखते हैं, क्योंकि एक वैध साइन्ड ड्राइवर ही EDR को ring-0 से अंधा करने के लिए पर्याप्त है।

Android / APK विश्लेषण: बिना किसी निर्भरता के Android APKs को बाइनरी स्तर पर पढ़ता है। यह कम्पाइल्ड बाइटकोड से नेटिव कोड एंट्री पॉइंट्स और IPC सरफेस को मैप करता है, ताकि डीकम्पाइल किए बिना पूरा सरफेस दिखाई दे।

Erlang / BEAM विश्लेषण: Erlang .beam फ़ाइलों में कम्पाइल होता है, और ELF के लिए उपयोग किया जाने वाला वही सरफेस-मैप दृष्टिकोण सीधे लागू होता है, इसलिए एटम सर्च, इम्पोर्ट ऑडिटिंग, और ऑब्फस्केशन डिटेक्शन के लिए किसी विशेष हैंडलिंग की आवश्यकता नहीं है। एक रिलीज़ डायरेक्टरी को स्वीप करने में सेकंड लगते हैं।

डिक्रिप्शन

  • Entropy Mapper: किसी बाइनरी में एन्क्रिप्टेड, कम्प्रेस्ड, या पैक्ड सेक्शन्स को ढूँढता है।
  • Crypto Audit: क्रिप्टोग्राफी के लिए स्कैन करता है।
  • XorSolver: टारगेट सेक्शन को रिकवर करता है, फिर डिक्रिप्ट करता है जिससे आगे रिवर्स इंजीनियरिंग संभव होती है।

वास्तविक दुनिया के परिणाम

Ablation का उपयोग Fortinet, Cisco, Juniper, Axis, Fujitsu, MikroTik, Orka, TencentOS, Enigma2, Skydio, और Dahua Security System के प्रोडक्शन फर्मवेयर और kernel ड्राइवर्स का विश्लेषण करने के लिए किया गया है।

Cisco FMC और ISE पर समन्वित डिस्क्लोज़र के बाद, Cisco Product Security Incident Response Team (PSIRT) ने आंतरिक कमज़ोरी ट्राइएज के लिए Ablation को अपनाया है। Cisco PSIRT इसे Firepower Threat Defense (FTD), Cisco Secure Client (AnyConnect), HyperFlex, और Catalyst में चल रही डिस्क्लोज़र रिपोर्ट्स के ट्राइएज के लिए सक्रिय रूप से उपयोग कर रहा है। Cisco Adaptive Security Appliance (ASA) LINA को भी Ablation का उपयोग करके रिवर्स इंजीनियर किया गया है, और निष्कर्ष वर्तमान में CERT/CC VINCE के माध्यम से समन्वित ट्राइएज के अधीन हैं।


लोकल डीकम्पाइलर्स


LLM संगतता

ProviderModels
Claude Code/model claude-sonnet-4-6
OpenAI CodexAll known models

इंस्टॉल```bash

pip install git+https://github.com/Ablation-Tool/ablation

root@kitploit:~
---

## आवश्यकताएँ

- Python >= 3.10
- `capstone`, `numpy`, `lief`, `sentence-transformers`, `pyelftools`
- वैकल्पिक: LLM सुविधाओं के लिए `anthropic`

---

## उत्तरदायी उपयोग

Ablation को अधिकृत सुरक्षा अनुसंधान के लिए बनाया गया है। इसका उपयोग केवल उन सिस्टमों के विरुद्ध करें जिनका आप स्वामी हैं या जिनका परीक्षण करने के लिए आपके पास स्पष्ट लिखित अनुमति है। बिना अनुमति के सिस्टमों के विरुद्ध इसे चलाना अधिकांश क्षेत्राधिकारों में कंप्यूटर धोखाधड़ी कानूनों का उल्लंघन करता है। लेखक दुरुपयोग के लिए उत्तरदायी नहीं हैं।

---

## आभार
यह परियोजना कई प्रमुख साहित्यिक कृतियों से अत्यधिक सूचित और प्रेरित हुई है।

**शोध पत्र**

| शीर्षक | लेखक | उद्धरण |
|---|---|---|
| [Finding Taint-Style Vulnerabilities in Linux-based Embedded Firmware with SSE-based Alias Analysis](https://arxiv.org/abs/2109.12209) | Cheng, Zheng, Liu, Guan, Liu, Li, Zhu, Ye, Sun | [sse_slicer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/sse_slicer.py) · [arm64_global_tracker.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/arm64_global_tracker.py) |
| [iResolveX: Multi-Layered Indirect Call Resolution via Static Reasoning and Learning-Augmented Refinement](https://arxiv.org/abs/2601.17888) | Monika Santra, Bokai Zhang, Mark Lim, [Vishnu Asutosh Dasu](https://github.com/vdasu), Dongrui Zeng, [Gang Tan](https://github.com/gangtan) | [vtable_resolver.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/vtable_resolver.py) · [interproc_field_writer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/interproc_field_writer.py) · [arm64_global_tracker.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/arm64_global_tracker.py) |
| [Extracting Protocol Format as State Machine via Controlled Static Loop Analysis](https://arxiv.org/abs/2305.13483) | [Qingkai Shi](https://github.com/qingkaishi), Xiangzhe Xu, Xiangyu Zhang | [proto_fsm.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/proto_fsm.py) |
| [NEMETYL: Message Type Identification of Binary Network Protocols using Continuous Segment Similarity](https://arxiv.org/abs/2002.03391) | [Stephan Kleber](https://github.com/vs-uulm), Rens Wouter van der Heijden, [Frank Kargl](https://github.com/fkargl) | [proto_fsm.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/proto_fsm.py) |
| [Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice](https://dl.acm.org/doi/10.1145/2810103.2813707) | [David Adrian](https://github.com/dadrian), Karthikeyan Bhargavan, [Zakir Durumeric](https://github.com/zakird), Pierrick Gaudry, Matthew Green, [J. Alex Halderman](https://github.com/jhalderm), [Nadia Heninger](https://github.com/factorable), Drew Springall, Emmanuel Thomé, [Luke Valenta](https://github.com/lukevalenta) | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |
| [Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM in TLS](https://www.usenix.org/conference/woot16/workshop-program/presentation/bock) | [Hanno Böck](https://github.com/hannob), [Aaron Zauner](https://github.com/azet), Sean Devlin, [Juraj Somorovsky](https://github.com/jurajsomorovsky), [Philipp Jovanovic](https://github.com/Daeinar) | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |
| [Whitening Sentence Representations for Better Semantics and Faster Retrieval](https://arxiv.org/abs/2103.15316) | [Jianlin Su](https://github.com/bojone), [Jiarun Cao](https://github.com/jiaruncao), Weijie Liu, Yangyiwen Ou | [semantic_search.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/semantic_search.py) |
| [Constant Propagation with Conditional Branches](https://dl.acm.org/doi/abs/10.1145/103135.103136) | Mark N. Wegman, F. Kenneth Zadeck | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| [A Simple, Fast Dominance Algorithm](https://www.cs.princeton.edu/techreports/2005/737.pdf) | Cooper, Harvey, Kennedy | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| [libdft: Practical Dynamic Data Flow Tracking for Commodity Systems](https://dl.acm.org/doi/10.1145/2151024.2151042) | [Vasileios P. Kemerlis](https://github.com/vkemerlis), [Georgios Portokalidis](https://github.com/portokalidis), [Kangkook Jee](https://github.com/jikk), Angelos D. Keromytis | [taint_tracker_x86.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_x86.py) · [taint_tracker_arm32.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_arm32.py) |

**पुस्तकें** [www.oreilly.com](https://www.oreilly.com) द्वारा प्रदान की गईं | [github.com/oreillymedia](https://github.com/oreillymedia)

| शीर्षक | लेखक | उद्धरण |
|---|---|---|
| The Art of Software Security Assessment | [Mark Dowd](https://github.com/mdowd79), John McDonald, [Justin Schuh](https://github.com/jschuh) | [heap_vuln_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/heap_vuln_scanner.py) · [format_string_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/format_string_scanner.py) · [ioctl_attack_surface.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/ioctl_attack_surface.py) |
| Practical Binary Analysis | [Dennis Andriesse](https://github.com/dennisaa) | [taint_tracker_x86.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_x86.py) · [disasm_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/disasm_engine.py) |
| Practical Malware Analysis | Michael Sikorski, Andrew Honig | [pe_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/pe_parser.py) · [shellcode_utils.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/shellcode_utils.py) |
| Practical Reverse Engineering | Bruce Dang, Alexandre Gazet, [Elias Bachaalany](https://github.com/0xeb) | [pe_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/pe_analyzer.py) · [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) |
| Hacking: The Art of Exploitation (2e) | Jon Erickson | [platform_detect.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/platform_detect.py) |
| Learning Linux Binary Analysis | [Ryan O'Neill](https://github.com/elfmaster) | [elf_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/elf_parser.py) · [binary_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/binary_parser.py) |
| Windows Internals Part 1 & 2 | [Pavel Yosifovich](https://github.com/zodiacon), [Mark Russinovich](https://github.com/markrussinovich), David Solomon, [Alex Ionescu](https://github.com/ionescu007), [Andrea Allievi](https://github.com/AaLl86) | [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) · [ioctl_attack_surface.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/ioctl_attack_surface.py) |
| Rootkits: Subverting the Windows Kernel | Greg Hoglund, Jamie Butler | [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) · [yara_generator.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/yara_generator.py) |
| Advanced Compiler Design and Implementation | Steven Muchnick | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| Engineering a Compiler | Keith Cooper, Linda Torczon | [disasm_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/disasm_engine.py) |
| Practical IoT Hacking | [Fotios Chantzis](https://github.com/ithilgore), Ioannis Stais, Paulino Calderon, Evangelos Deirmentzoglou, Beau Woods | [firmware_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/firmware_analyzer.py) |
| Inside the Android OS: Building, Customizing, Managing and Operating Android System Services | G. Blake Meike | [apk_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/apk_parser.py) · [jni_bridge_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/jni_bridge_scanner.py) · [binder_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/binder_scanner.py) |
| Malware Analysis and Detection Engineering | [Abhijit Mohanta](https://github.com/amohanta), Anoop Saldanha | [yara_generator.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/yara_generator.py) |
| Evasive Malware | [Kyle Cucci](https://github.com/d4rksystem) | [process_enum.py](https://github.com/Ablation-Tool/ablation/blob/main/modules/process_enum.py) |
| Hacking Cryptography | [Kamran Khan](https://github.com/krkhan), [Bill Cox](https://github.com/waywardgeek) | [tls_enum.py](https://github.com/Ablation-Tool/ablation/blob/main/modules/tls_enum.py) |
| Real-World Cryptography | David Wong | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |

**विशेष उल्लेख**

[Microsoft Excel (Data Analysis ToolPak)](https://support.microsoft.com/en-us/office/use-the-analysis-toolpak-to-perform-complex-data-analysis-6c67ccf0-f4a9-487c-8dec-bdb5a2cefab6) बंद अधोसंरचना का विश्लेषण करते समय या ब्लैक-बॉक्स सिस्टमों को सुरक्षित करते समय, इस सटीक प्रक्रिया को टाइमिंग विश्लेषण या टेलीमेट्री रिवर्स इंजीनियरिंग कहा जाता है। स्रोत कोड के बिना, Data Analysis ToolPak किसी एप्लिकेशन के इनपुट और आउटपुट का सख्ती से अवलोकन करके गणितीय रूप से यह विघटित करता है कि एप्लिकेशन बैकएंड पर कैसे कार्य करता है।

---

## फ्रेमवर्क आर्किटेक्चर और मॉड्यूल ऑर्केस्ट्रेशन```mermaid
flowchart TD
    Binary(["<b>Target Binary</b><br/><i>ELF · PE · firmware</i>"])
    Claude(["<b>Claude Code (Orchestrator)</b><br/><i>Central Agent Controller</i>"])

    Binary -->|"load"| BCtx["<b>BinaryContext</b><br/><i>PLT · Strings · Call Graph · XRefs</i>"]
    BCtx -->|"context"| Corpus["<b>Corpus Builder</b><br/><i>Semantic Embedding DB</i>"]
    BCtx -->|"context"| Taint["<b>Taint Engine</b><br/><i>Data Flow / Sinks</i>"]
    BCtx -->|"context"| Diffing["<b>Diffing Engine</b><br/><i>DTW / Version Delta</i>"]
    BCtx -->|"context"| FmtStr["<b>Format String</b><br/><i>Specifier Scanner</i>"]
    BCtx -->|"context"| Heap["<b>Heap Scanner</b><br/><i>Chunk / UAF Audit</i>"]
    BCtx -->|"context"| MultiArch["<b>Multi-Arch Engine</b><br/><i>MIPS · PPC · RISC-V · ARC · V850</i>"]
    BCtx -->|"context"| Driver["<b>Driver Engine</b><br/><i>Kernel IOCTL / BYOVD Audit</i>"]

    Corpus -->|"embeddings"| Semantic["<b>Semantic Search</b><br/><i>BERT Behavioral Fingerprints</i>"]

    Semantic -. "candidates" .-> Claude
    Taint -. "findings" .-> Claude
    Diffing -. "findings" .-> Claude
    FmtStr -. "findings" .-> Claude
    Heap -. "findings" .-> Claude
    MultiArch -. "findings" .-> Claude
    Driver -. "findings" .-> Claude

    Claude -->|"confirmed finding"| Registry["<b>Finding Registry</b><br/><i>Cross-Target Corpus</i>"]
    Registry -->|"seeds future sweeps"| Semantic

    classDef primary fill:#2a1a4a,stroke:#7c3aed,stroke-width:2px,color:#fff
    classDef foundation fill:#0d1117,stroke:#58a6ff,stroke-width:2px,color:#e5e7eb
    classDef engine fill:#171717,stroke:#404040,stroke-width:1px,color:#e5e7eb
    classDef feedback fill:#0d2818,stroke:#238636,stroke-width:2px,color:#e5e7eb

    class Claude,Binary primary
    class BCtx foundation
    class Corpus,Semantic,Taint,Diffing,FmtStr,Heap,MultiArch,Driver engine
    class Registry feedback

उदाहरण RE वर्कफ़्लो

RPM बंडल से स्ट्रिप्ड बाइनरीज़ का एंड-टू-एंड विश्लेषण। BinaryContext के माध्यम से एक्सट्रैक्शन, स्ट्रिंग xrefs, और पुष्टि किए गए निष्कर्षों तक capstone डिसअसेम्बली।```mermaid flowchart TD RPM["target-package.rpm
third-party bundle · x86-64"]

root@kitploit:~
RPM -->|rpm2cpio / cpio| EXTRACT["platform/linux-x86_64/"]

EXTRACT --> PI["bin/inference_engine<br/>stripped PIE · x86-64"]
EXTRACT --> CTRL["bin/controller<br/>stripped PIE · x86-64"]
EXTRACT --> LIBS["lib/libcore.so<br/>lib/libruntime.so"]

subgraph TRACK_PI ["inference engine track"]
    direction TB
    BCI["BinaryContext.load_or_build()<br/>32 func starts · 551 strings · PLT built"]
    BCI --> SS["ctx.strings scan<br/>api_op_read VA 0x51560<br/>api_op_write VA 0x51570<br/>license_key_flag 0x52e08"]
    SS --> XREF["ctx.string_xrefs()<br/>both ops xref → 0x17499, 0x174af<br/>ctx.func_containing() → init fn 0x10000"]
    XREF --> DA1["capstone disasm 0x17450<br/>lea rsi → api_op_read · call set::insert<br/>lea rsi → api_op_write · call set::insert<br/>CONFIRMED: exactly 2 blocklist entries"]
    DA1 --> DA2["capstone disasm 0x16511<br/>cmp qword ptr [r9], 0<br/>je → model loads · ne → handleFatal<br/>empty set = bypass confirmed"]
end

subgraph TRACK_LIBS ["library analysis"]
    direction TB
    NM["nm -D libcore.so<br/>spawn at 0xfdb20 · ctor at 0xfcfd0"]
    NM --> DA3["capstone disasm libcore.so:0xfdbc7<br/>cmp entry length == exe_path length<br/>memcmp at 0xfdbdb<br/>proper equality check · no prefix bypass"]
    LSCAN["re.findall api_op:: in libruntime.so<br/>2481 distinct ops found<br/>2 blocked · 2479 unblocked"]
end

subgraph TRACK_CTRL ["controller track"]
    direction TB
    BCC["BinaryContext.load_or_build()<br/>18 func starts · PLT · strings"]
    BCC --> XREF2["ctx.string_xrefs() on 5 path strings<br/>./worker1 · ./worker2<br/>./worker3 · ./worker4<br/>./inference_engine<br/>all xref at 0x9a04-0x9a5e"]
    XREF2 --> DA4["capstone disasm 0x99e9<br/>call CApp::progDir()<br/>call OsUtils::chdir()<br/>chdir to binary dir before spawn"]
    DA4 --> DA5["capstone disasm 0x11500<br/>args vector from command pipe tokens<br/>passed raw to spawn() at 0x11699<br/>no validation"]
end

PI --> BCI
PI --> BCC
LIBS --> NM
LIBS --> LSCAN

DA2 --> F1
LSCAN --> F1["F1 · HIGH<br/>blocklist covers 2 of 2481 ops<br/>upload malicious model via API<br/>seccomp BPF not decoded — CIA open"]

DA3 --> F2
XREF2 --> F2["F2 · LOW<br/>controller spawn allowlist is sound<br/>but args vector unchecked<br/>requires service user pipe access"]

DA5 --> F2

SS --> F3["F3 · INFO<br/>license gate = JSON field only<br/>no cryptographic verification"]

classDef finding fill:#1a1a2e,stroke:#e94560,stroke-width:2px,color:#fff
classDef tool fill:#16213e,stroke:#0f3460,stroke-width:1px,color:#e5e7eb
classDef binary fill:#0f3460,stroke:#533483,stroke-width:2px,color:#fff
classDef input fill:#533483,stroke:#7c3aed,stroke-width:2px,color:#fff

class F1,F2,F3 finding
class BCI,BCC,NM,LSCAN,SS,XREF,XREF2,DA1,DA2,DA3,DA4,DA5 tool
class PI,CTRL,LIBS binary
class RPM,EXTRACT input
root@kitploit:~
टूल डाउनलोड करें
CVEProductTitleCVSSAdvisory
CVE-2026-76420Secure Firewall Management Center (FMC)Peer Impersonation9.0 Criticalcisco-sa-fmc2-multivulns-HXgcqRG
CVE-2026-76412Secure Firewall Management Center (FMC)Privilege Escalation to root8.5 Highcisco-sa-fmc2-multivulns-HXgcqRG
CVE-2026-76413Secure Firewall Management Center (FMC)Single Sign-On Token Forgery8.5 Highcisco-sa-fmc2-multivulns-HXgcqRG
CVE-2026-76447Identity Services Engine (ISE)OCSP Responder Authentication Bypass5.3 Mediumcisco-sa-ise-multiauth-bypass-sgD2HbL4
ArchitectureVariants
x86x86-32 · x86-64
ARMARM-32 · ARM-64
MIPSMIPS-32 · nanoMIPS · MIPS-64
PowerPCPPC-32 · PPC-64
RISC-VRISC-V 32 · RISC-V 64
EmbeddedARC EM/HS · V850-32