
逆アセンブリ、逆コンパイル、テイント解析、バージョン差分、セマンティック検索を備えたリバースエンジニアリングフレームワーク。さらにLLM駆動の自律的なバイナリおよびファームウェア解析も可能。
Ablationは、Ghidra、IDA Pro、Binary Ninjaといった業界標準ツールとまったく同じコアの逆アセンブル、逆コンパイル、バイナリ解析機能を提供するリバースエンジニアリングフレームワークです。
Claude CodeやOpenAI Codexと組み合わせることで、完全自律型のリバースエンジニアリングツールへと変貌します。

BERTによるセマンティック検索: セマンティック検索は、完全一致するキーワードではなく意味に基づいて結果を検索します。BERTはテキストを読み取り、その意味を理解します。意味が似ていれば類似したスコアが得られるため、完全一致する単語ではなく概念で検索できます。この2つを組み合わせることで、リバースエンジニアリングの主要なボトルネックを加速しつつ、脆弱な関数を発見できます。
圧倒的なパフォーマンス: 50 MBのバイナリが35秒でロードされます。GhidraやIDA Proは、何か操作を行う前にファイル全体をデータベースにパースするため、数時間かかることがあります。Ablationは現在作業中の関数のみを解析するため、すぐに作業を開始できます。
バージョン差分: リリース間で関数の動作がどれだけ重複しているかを測るJaccard法と、ベンダーが更新したファームウェアやソフトウェアの各バージョン間で関数がどのように実行されるかの「形状」を追跡するDynamic Time Warpingを活用し、Ablationはパッチが実際にロジックを変更したのか、それともパッケージングだけを変更したのかを確認します。見た目だけの再コンパイルでは、未パッチの脆弱性を隠すことはできないからです。
クロスバイナリ解析: ファームウェアイメージ内のすべての共有ライブラリを同時に解析し、バイナリ境界を越えたデータフローを追跡します。
ソースコード監査: 大規模なコードベースを線形に読むよりも高速に、単なるパターンマッチングよりも高い精度で監査します。すべてのソースファイルに5ビットのセキュリティプロファイルが付与され、どれだけ注意を払う必要があるかが正確に判定されるため、見落としも重複した読み込みも発生しません。
Windowsカーネルドライバー & BYOVD解析: IRPディスパッチテーブルをマッピングし、すべてのIOCTLコードをデコードし、どのカーネルAPIがユーザーモードから物理メモリとトークンプリミティブを公開しているかを特定します。BYOVD Detectorは、そうした機能を持つ署名済みドライバーをフィンガープリントします。正規の署名済みドライバーが1つあれば、リング0からEDRを無効化するのに十分だからです。
Android / APK解析: 依存関係なしでAndroid APKをバイナリレベルで読み取ります。コンパイル済みバイトコードからネイティブコードのエントリポイントとIPCサーフェスをマッピングするため、逆コンパイルせずにサーフェス全体を可視化できます。
Erlang / BEAM解析: Erlangは.beamファイルにコンパイルされ、ELFに使用されるのと同じサーフェスマップ手法がそのまま適用できるため、アトム検索、インポート監査、難読化検出に特別な処理は不要です。リリースディレクトリのスイープは数秒で完了します。
復号
Ablationは、Fortinet、Cisco、Juniper、Axis、Fujitsu、MikroTik、Orka、TencentOS、Enigma2、Skydio、Dahua Security Systemの本番ファームウェアおよびカーネルドライバーの解析に使用されてきました。
Cisco FMCおよびISEに関する協調的開示に続き、Cisco Product Security Incident Response Team (PSIRT)は内部の脆弱性トリアージにAblationを採用しました。Cisco PSIRTは、Firepower Threat Defense (FTD)、Cisco Secure Client (AnyConnect)、HyperFlex、Catalystにわたる進行中の開示レポートのトリアージに積極的に使用しています。Cisco Adaptive Security Appliance (ASA) LINAもAblationを使用してリバースエンジニアリングされており、その発見は現在CERT/CC VINCEを通じた協調的トリアージの対象となっています。
| Provider | Models |
|---|---|
| Claude Code | /model claude-sonnet-4-6 |
| OpenAI Codex | All known models |
pip install git+https://github.com/Ablation-Tool/ablation
---
## 要件
- Python >= 3.10
- `capstone`、`numpy`、`lief`、`sentence-transformers`、`pyelftools`
- オプション: LLM 機能用の `anthropic`
---
## 責任ある使用
Ablation は、許可されたセキュリティ研究のために構築されています。所有しているシステム、またはテストに対する明示的な書面による許可を得ているシステムに対してのみ使用してください。許可なくシステムに対して実行することは、ほとんどの法域においてコンピュータ詐欺法に違反します。作者は不正使用に対して責任を負いません。
---
## 謝辞
このプロジェクトは、いくつかの重要な文献から多大な情報とインスピレーションを得ています。
**研究論文**
| タイトル | 著者 | 引用 |
|---|---|---|
| [Finding Taint-Style Vulnerabilities in Linux-based Embedded Firmware with SSE-based Alias Analysis](https://arxiv.org/abs/2109.12209) | Cheng, Zheng, Liu, Guan, Liu, Li, Zhu, Ye, Sun | [sse_slicer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/sse_slicer.py) · [arm64_global_tracker.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/arm64_global_tracker.py) |
| [iResolveX: Multi-Layered Indirect Call Resolution via Static Reasoning and Learning-Augmented Refinement](https://arxiv.org/abs/2601.17888) | Monika Santra, Bokai Zhang, Mark Lim, [Vishnu Asutosh Dasu](https://github.com/vdasu), Dongrui Zeng, [Gang Tan](https://github.com/gangtan) | [vtable_resolver.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/vtable_resolver.py) · [interproc_field_writer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/interproc_field_writer.py) · [arm64_global_tracker.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/arm64_global_tracker.py) |
| [Extracting Protocol Format as State Machine via Controlled Static Loop Analysis](https://arxiv.org/abs/2305.13483) | [Qingkai Shi](https://github.com/qingkaishi), Xiangzhe Xu, Xiangyu Zhang | [proto_fsm.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/proto_fsm.py) |
| [NEMETYL: Message Type Identification of Binary Network Protocols using Continuous Segment Similarity](https://arxiv.org/abs/2002.03391) | [Stephan Kleber](https://github.com/vs-uulm), Rens Wouter van der Heijden, [Frank Kargl](https://github.com/fkargl) | [proto_fsm.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/proto_fsm.py) |
| [Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice](https://dl.acm.org/doi/10.1145/2810103.2813707) | [David Adrian](https://github.com/dadrian), Karthikeyan Bhargavan, [Zakir Durumeric](https://github.com/zakird), Pierrick Gaudry, Matthew Green, [J. Alex Halderman](https://github.com/jhalderm), [Nadia Heninger](https://github.com/factorable), Drew Springall, Emmanuel Thomé, [Luke Valenta](https://github.com/lukevalenta) | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |
| [Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM in TLS](https://www.usenix.org/conference/woot16/workshop-program/presentation/bock) | [Hanno Böck](https://github.com/hannob), [Aaron Zauner](https://github.com/azet), Sean Devlin, [Juraj Somorovsky](https://github.com/jurajsomorovsky), [Philipp Jovanovic](https://github.com/Daeinar) | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |
| [Whitening Sentence Representations for Better Semantics and Faster Retrieval](https://arxiv.org/abs/2103.15316) | [Jianlin Su](https://github.com/bojone), [Jiarun Cao](https://github.com/jiaruncao), Weijie Liu, Yangyiwen Ou | [semantic_search.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/semantic_search.py) |
| [Constant Propagation with Conditional Branches](https://dl.acm.org/doi/abs/10.1145/103135.103136) | Mark N. Wegman, F. Kenneth Zadeck | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| [A Simple, Fast Dominance Algorithm](https://www.cs.princeton.edu/techreports/2005/737.pdf) | Cooper, Harvey, Kennedy | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| [libdft: Practical Dynamic Data Flow Tracking for Commodity Systems](https://dl.acm.org/doi/10.1145/2151024.2151042) | [Vasileios P. Kemerlis](https://github.com/vkemerlis), [Georgios Portokalidis](https://github.com/portokalidis), [Kangkook Jee](https://github.com/jikk), Angelos D. Keromytis | [taint_tracker_x86.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_x86.py) · [taint_tracker_arm32.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_arm32.py) |
**書籍** [www.oreilly.com](https://www.oreilly.com) 提供 | [github.com/oreillymedia](https://github.com/oreillymedia)
| タイトル | 著者 | 引用 |
|---|---|---|
| The Art of Software Security Assessment | [Mark Dowd](https://github.com/mdowd79), John McDonald, [Justin Schuh](https://github.com/jschuh) | [heap_vuln_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/heap_vuln_scanner.py) · [format_string_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/format_string_scanner.py) · [ioctl_attack_surface.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/ioctl_attack_surface.py) |
| Practical Binary Analysis | [Dennis Andriesse](https://github.com/dennisaa) | [taint_tracker_x86.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_x86.py) · [disasm_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/disasm_engine.py) |
| Practical Malware Analysis | Michael Sikorski, Andrew Honig | [pe_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/pe_parser.py) · [shellcode_utils.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/shellcode_utils.py) |
| Practical Reverse Engineering | Bruce Dang, Alexandre Gazet, [Elias Bachaalany](https://github.com/0xeb) | [pe_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/pe_analyzer.py) · [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) |
| Hacking: The Art of Exploitation (2e) | Jon Erickson | [platform_detect.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/platform_detect.py) |
| Learning Linux Binary Analysis | [Ryan O'Neill](https://github.com/elfmaster) | [elf_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/elf_parser.py) · [binary_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/binary_parser.py) |
| Windows Internals Part 1 & 2 | [Pavel Yosifovich](https://github.com/zodiacon), [Mark Russinovich](https://github.com/markrussinovich), David Solomon, [Alex Ionescu](https://github.com/ionescu007), [Andrea Allievi](https://github.com/AaLl86) | [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) · [ioctl_attack_surface.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/ioctl_attack_surface.py) |
| Rootkits: Subverting the Windows Kernel | Greg Hoglund, Jamie Butler | [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) · [yara_generator.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/yara_generator.py) |
| Advanced Compiler Design and Implementation | Steven Muchnick | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| Engineering a Compiler | Keith Cooper, Linda Torczon | [disasm_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/disasm_engine.py) |
| Practical IoT Hacking | [Fotios Chantzis](https://github.com/ithilgore), Ioannis Stais, Paulino Calderon, Evangelos Deirmentzoglou, Beau Woods | [firmware_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/firmware_analyzer.py) |
| Inside the Android OS: Building, Customizing, Managing and Operating Android System Services | G. Blake Meike | [apk_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/apk_parser.py) · [jni_bridge_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/jni_bridge_scanner.py) · [binder_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/binder_scanner.py) |
| Malware Analysis and Detection Engineering | [Abhijit Mohanta](https://github.com/amohanta), Anoop Saldanha | [yara_generator.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/yara_generator.py) |
| Evasive Malware | [Kyle Cucci](https://github.com/d4rksystem) | [process_enum.py](https://github.com/Ablation-Tool/ablation/blob/main/modules/process_enum.py) |
| Hacking Cryptography | [Kamran Khan](https://github.com/krkhan), [Bill Cox](https://github.com/waywardgeek) | [tls_enum.py](https://github.com/Ablation-Tool/ablation/blob/main/modules/tls_enum.py) |
| Real-World Cryptography | David Wong | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |
**次点**
[Microsoft Excel (Data Analysis ToolPak)](https://support.microsoft.com/en-us/office/use-the-analysis-toolpak-to-perform-complex-data-analysis-6c67ccf0-f4a9-487c-8dec-bdb5a2cefab6) 閉じたインフラストラクチャを分析したり、ブラックボックスシステムを保護したりする場合、この正確なプロセスはタイミング分析またはテレメトリリバースエンジニアリングと呼ばれます。ソースコードがなくても、Data Analysis ToolPak は、アプリケーションの入力と出力を厳密に観察することで、バックエンドでの動作を数学的に分解します。
---
## フレームワークアーキテクチャとモジュールオーケストレーション```mermaid
flowchart TD
Binary(["<b>Target Binary</b><br/><i>ELF · PE · firmware</i>"])
Claude(["<b>Claude Code (Orchestrator)</b><br/><i>Central Agent Controller</i>"])
Binary -->|"load"| BCtx["<b>BinaryContext</b><br/><i>PLT · Strings · Call Graph · XRefs</i>"]
BCtx -->|"context"| Corpus["<b>Corpus Builder</b><br/><i>Semantic Embedding DB</i>"]
BCtx -->|"context"| Taint["<b>Taint Engine</b><br/><i>Data Flow / Sinks</i>"]
BCtx -->|"context"| Diffing["<b>Diffing Engine</b><br/><i>DTW / Version Delta</i>"]
BCtx -->|"context"| FmtStr["<b>Format String</b><br/><i>Specifier Scanner</i>"]
BCtx -->|"context"| Heap["<b>Heap Scanner</b><br/><i>Chunk / UAF Audit</i>"]
BCtx -->|"context"| MultiArch["<b>Multi-Arch Engine</b><br/><i>MIPS · PPC · RISC-V · ARC · V850</i>"]
BCtx -->|"context"| Driver["<b>Driver Engine</b><br/><i>Kernel IOCTL / BYOVD Audit</i>"]
Corpus -->|"embeddings"| Semantic["<b>Semantic Search</b><br/><i>BERT Behavioral Fingerprints</i>"]
Semantic -. "candidates" .-> Claude
Taint -. "findings" .-> Claude
Diffing -. "findings" .-> Claude
FmtStr -. "findings" .-> Claude
Heap -. "findings" .-> Claude
MultiArch -. "findings" .-> Claude
Driver -. "findings" .-> Claude
Claude -->|"confirmed finding"| Registry["<b>Finding Registry</b><br/><i>Cross-Target Corpus</i>"]
Registry -->|"seeds future sweeps"| Semantic
classDef primary fill:#2a1a4a,stroke:#7c3aed,stroke-width:2px,color:#fff
classDef foundation fill:#0d1117,stroke:#58a6ff,stroke-width:2px,color:#e5e7eb
classDef engine fill:#171717,stroke:#404040,stroke-width:1px,color:#e5e7eb
classDef feedback fill:#0d2818,stroke:#238636,stroke-width:2px,color:#e5e7eb
class Claude,Binary primary
class BCtx foundation
class Corpus,Semantic,Taint,Diffing,FmtStr,Heap,MultiArch,Driver engine
class Registry feedback
RPMバンドルからのストリップ済みバイナリのエンドツーエンド分析。抽出からBinaryContext、文字列xref、capstone逆アセンブリを経て確認された発見に至るまで。```mermaid
flowchart TD
RPM["target-package.rpm
third-party bundle · x86-64"]
RPM -->|rpm2cpio / cpio| EXTRACT["platform/linux-x86_64/"]
EXTRACT --> PI["bin/inference_engine<br/>stripped PIE · x86-64"]
EXTRACT --> CTRL["bin/controller<br/>stripped PIE · x86-64"]
EXTRACT --> LIBS["lib/libcore.so<br/>lib/libruntime.so"]
subgraph TRACK_PI ["inference engine track"]
direction TB
BCI["BinaryContext.load_or_build()<br/>32 func starts · 551 strings · PLT built"]
BCI --> SS["ctx.strings scan<br/>api_op_read VA 0x51560<br/>api_op_write VA 0x51570<br/>license_key_flag 0x52e08"]
SS --> XREF["ctx.string_xrefs()<br/>both ops xref → 0x17499, 0x174af<br/>ctx.func_containing() → init fn 0x10000"]
XREF --> DA1["capstone disasm 0x17450<br/>lea rsi → api_op_read · call set::insert<br/>lea rsi → api_op_write · call set::insert<br/>CONFIRMED: exactly 2 blocklist entries"]
DA1 --> DA2["capstone disasm 0x16511<br/>cmp qword ptr [r9], 0<br/>je → model loads · ne → handleFatal<br/>empty set = bypass confirmed"]
end
subgraph TRACK_LIBS ["library analysis"]
direction TB
NM["nm -D libcore.so<br/>spawn at 0xfdb20 · ctor at 0xfcfd0"]
NM --> DA3["capstone disasm libcore.so:0xfdbc7<br/>cmp entry length == exe_path length<br/>memcmp at 0xfdbdb<br/>proper equality check · no prefix bypass"]
LSCAN["re.findall api_op:: in libruntime.so<br/>2481 distinct ops found<br/>2 blocked · 2479 unblocked"]
end
subgraph TRACK_CTRL ["controller track"]
direction TB
BCC["BinaryContext.load_or_build()<br/>18 func starts · PLT · strings"]
BCC --> XREF2["ctx.string_xrefs() on 5 path strings<br/>./worker1 · ./worker2<br/>./worker3 · ./worker4<br/>./inference_engine<br/>all xref at 0x9a04-0x9a5e"]
XREF2 --> DA4["capstone disasm 0x99e9<br/>call CApp::progDir()<br/>call OsUtils::chdir()<br/>chdir to binary dir before spawn"]
DA4 --> DA5["capstone disasm 0x11500<br/>args vector from command pipe tokens<br/>passed raw to spawn() at 0x11699<br/>no validation"]
end
PI --> BCI
PI --> BCC
LIBS --> NM
LIBS --> LSCAN
DA2 --> F1
LSCAN --> F1["F1 · HIGH<br/>blocklist covers 2 of 2481 ops<br/>upload malicious model via API<br/>seccomp BPF not decoded — CIA open"]
DA3 --> F2
XREF2 --> F2["F2 · LOW<br/>controller spawn allowlist is sound<br/>but args vector unchecked<br/>requires service user pipe access"]
DA5 --> F2
SS --> F3["F3 · INFO<br/>license gate = JSON field only<br/>no cryptographic verification"]
classDef finding fill:#1a1a2e,stroke:#e94560,stroke-width:2px,color:#fff
classDef tool fill:#16213e,stroke:#0f3460,stroke-width:1px,color:#e5e7eb
classDef binary fill:#0f3460,stroke:#533483,stroke-width:2px,color:#fff
classDef input fill:#533483,stroke:#7c3aed,stroke-width:2px,color:#fff
class F1,F2,F3 finding
class BCI,BCC,NM,LSCAN,SS,XREF,XREF2,DA1,DA2,DA3,DA4,DA5 tool
class PI,CTRL,LIBS binary
class RPM,EXTRACT input
| CVE | Product | Title | CVSS | Advisory |
|---|
| CVE-2026-76420 | Secure Firewall Management Center (FMC) | Peer Impersonation | 9.0 Critical | cisco-sa-fmc2-multivulns-HXgcqRG |
| CVE-2026-76412 | Secure Firewall Management Center (FMC) | Privilege Escalation to root | 8.5 High | cisco-sa-fmc2-multivulns-HXgcqRG |
| CVE-2026-76413 | Secure Firewall Management Center (FMC) | Single Sign-On Token Forgery | 8.5 High | cisco-sa-fmc2-multivulns-HXgcqRG |
| CVE-2026-76447 | Identity Services Engine (ISE) | OCSP Responder Authentication Bypass | 5.3 Medium | cisco-sa-ise-multiauth-bypass-sgD2HbL4 |
| Architecture | Variants |
|---|
| x86 | x86-32 · x86-64 |
| ARM | ARM-32 · ARM-64 |
| MIPS | MIPS-32 · nanoMIPS · MIPS-64 |
| PowerPC | PPC-32 · PPC-64 |
| RISC-V | RISC-V 32 · RISC-V 64 |
| Embedded | ARC EM/HS · V850-32 |