Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
ablation — 디스어셈블리, 디컴파일, 테인트 분석, 버전 비교 및 시맨틱 검색을 갖춘 리버스 엔지니어링 프레임워크이며, LLM 기반 자율 바이너리 및 펌웨어 분석 기능을 제공합니다. | Kitploit
도구/GitHubGitHub/ablation-tool/ablation
Android SecurityStatic AnalysisVulnerability AnalysisReverse EngineeringMalware AnalysisCryptographyBinary AnalysisPapers & ResearchAI-Assisted ReversingFirmware Analysis
GitHub
35286시간 35분 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
ablation-tool/ablation

ablation

디스어셈블리, 디컴파일, 테인트 분석, 버전 비교 및 시맨틱 검색을 갖춘 리버스 엔지니어링 프레임워크이며, LLM 기반 자율 바이너리 및 펌웨어 분석 기능을 제공합니다.

저장소 보기
ABLATION

Ablation은 Ghidra, IDA Pro, Binary Ninja와 같은 업계 표준 도구와 정확히 동일한 핵심 디스어셈블리, 디컴파일, 바이너리 분석 기능을 제공하는 리버스 엔지니어링 프레임워크입니다.

Claude Code 또는 OpenAI Codex와 결합하면 완전히 자율적인 리버스 엔지니어링 도구로 변모합니다.


Codex demo

기능

BERT를 통한 시맨틱 검색: 시맨틱 검색은 정확한 키워드가 아닌 의미를 기반으로 결과를 찾습니다. BERT는 텍스트를 읽고 그 의미를 파악합니다. 유사한 의미는 유사한 점수를 받으므로, 정확한 단어 대신 개념으로 검색할 수 있습니다. 이 둘을 결합함으로써 리버스 엔지니어링의 주요 병목 지점을 가속화하는 동시에 취약한 함수를 찾아냅니다.

극한의 성능: 50 MB 바이너리가 35초 만에 로드됩니다. Ghidra와 IDA Pro는 아무것도 하기 전에 전체 파일을 데이터베이스로 파싱하기 때문에 몇 시간이 걸릴 수 있습니다. Ablation은 현재 작업 중인 함수만 분석하므로 즉시 시작할 수 있습니다.

버전 비교: 릴리스 간에 함수의 동작이 얼마나 겹치는지 측정하는 Jaccard 방법과, 벤더가 업데이트한 펌웨어 또는 소프트웨어의 여러 버전에 걸쳐 함수가 실행되는 "형태"를 추적하는 Dynamic Time Warping을 활용하여, Ablation은 패치가 실제로 로직을 변경했는지 아니면 단순히 패키징만 변경했는지 확인합니다. 왜냐하면 겉치레 재컴파일은 패치되지 않은 취약점을 숨길 수 없기 때문입니다.

크로스 바이너리 분석: 펌웨어 이미지 내의 모든 공유 라이브러리를 동시에 분석하고, 바이너리 경계를 넘나드는 데이터 흐름을 추적합니다.

소스 코드 감사: 어떤 대규모 코드베이스든 선형적으로 읽는 것보다 빠르게, 단순한 패턴 매칭보다 높은 정확도로 감사합니다. 모든 소스 파일은 얼마나 많은 주의가 필요한지 정확히 결정하는 5비트 보안 프로필을 부여받으므로, 놓치는 것도 없고 두 번 읽는 것도 없습니다.

Windows 커널 드라이버 및 BYOVD 분석: IRP 디스패치 테이블을 매핑하고, 모든 IOCTL 코드를 디코딩하며, 어떤 커널 API가 사용자 모드에서 물리 메모리와 토큰 프리미티브를 노출하는지 식별합니다. BYOVD Detector는 그러한 기능을 가진 서명된 드라이버를 핑거프린팅합니다. 왜냐하면 정당하게 서명된 드라이버 하나만으로도 ring-0에서 EDR을 무력화하기에 충분하기 때문입니다.

Android / APK 분석: 의존성 없이 바이너리 수준에서 Android APK를 읽습니다. 컴파일된 바이트코드에서 네이티브 코드 진입점과 IPC 표면을 매핑하므로, 디컴파일 없이도 전체 표면을 볼 수 있습니다.

Erlang / BEAM 분석: Erlang은 .beam 파일로 컴파일되며, ELF에 사용되는 것과 동일한 표면 매핑 접근 방식이 그대로 적용되므로, atom 검색, import 감사, 난독화 탐지에 특별한 처리가 필요하지 않습니다. 릴리스 디렉터리를 훑는 데 몇 초밖에 걸리지 않습니다.

복호화

  • Entropy Mapper: 바이너리에서 암호화, 압축 또는 패킹된 섹션을 찾습니다.
  • Crypto Audit: 암호화를 스캔합니다.
  • XorSolver: 대상 섹션을 복구한 다음 복호화하여 추가 리버스 엔지니어링을 가능하게 합니다.

실제 결과

Ablation은 Fortinet, Cisco, Juniper, Axis, Fujitsu, MikroTik, Orka, TencentOS, Enigma2, Skydio, Dahua Security System의 프로덕션 펌웨어와 커널 드라이버를 분석하는 데 사용되었습니다.

Cisco FMC와 ISE에 대한 조율된 공개 이후, Cisco 제품 보안 사고 대응팀(PSIRT)은 내부 취약점 분류에 Ablation을 도입했습니다. Cisco PSIRT는 Firepower Threat Defense(FTD), Cisco Secure Client(AnyConnect), HyperFlex, Catalyst 전반에 걸친 진행 중인 공개 보고서를 분류하는 데 이를 적극적으로 사용하고 있습니다. Cisco Adaptive Security Appliance(ASA) LINA 또한 Ablation을 사용하여 리버스 엔지니어링되었으며, 발견 사항은 현재 CERT/CC VINCE를 통해 조율된 분류가 진행 중입니다.


로컬 디컴파일러


LLM 호환성

제공자모델
Claude Code/model claude-sonnet-4-6
OpenAI CodexAll known models

설치```bash

pip install git+https://github.com/Ablation-Tool/ablation

root@kitploit:~
---

## 요구 사항

- Python >= 3.10
- `capstone`, `numpy`, `lief`, `sentence-transformers`, `pyelftools`
- 선택 사항: LLM 기능을 위한 `anthropic`

---

## 책임 있는 사용

Ablation은 승인된 보안 연구를 위해 제작되었습니다. 본인이 소유하거나 테스트에 대한 명시적인 서면 허가를 받은 시스템에만 사용하십시오. 승인 없이 시스템에 대해 실행하는 것은 대부분의 관할권에서 컴퓨터 사기법을 위반합니다. 저자는 오용에 대해 책임지지 않습니다.

---

## 감사의 글
이 프로젝트는 여러 핵심 문헌 작품에서 큰 정보와 영감을 받았습니다.

**연구 논문**

| 제목 | 저자 | 인용 |
|---|---|---|
| [Finding Taint-Style Vulnerabilities in Linux-based Embedded Firmware with SSE-based Alias Analysis](https://arxiv.org/abs/2109.12209) | Cheng, Zheng, Liu, Guan, Liu, Li, Zhu, Ye, Sun | [sse_slicer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/sse_slicer.py) · [arm64_global_tracker.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/arm64_global_tracker.py) |
| [iResolveX: Multi-Layered Indirect Call Resolution via Static Reasoning and Learning-Augmented Refinement](https://arxiv.org/abs/2601.17888) | Monika Santra, Bokai Zhang, Mark Lim, [Vishnu Asutosh Dasu](https://github.com/vdasu), Dongrui Zeng, [Gang Tan](https://github.com/gangtan) | [vtable_resolver.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/vtable_resolver.py) · [interproc_field_writer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/interproc_field_writer.py) · [arm64_global_tracker.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/arm64_global_tracker.py) |
| [Extracting Protocol Format as State Machine via Controlled Static Loop Analysis](https://arxiv.org/abs/2305.13483) | [Qingkai Shi](https://github.com/qingkaishi), Xiangzhe Xu, Xiangyu Zhang | [proto_fsm.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/proto_fsm.py) |
| [NEMETYL: Message Type Identification of Binary Network Protocols using Continuous Segment Similarity](https://arxiv.org/abs/2002.03391) | [Stephan Kleber](https://github.com/vs-uulm), Rens Wouter van der Heijden, [Frank Kargl](https://github.com/fkargl) | [proto_fsm.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/proto_fsm.py) |
| [Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice](https://dl.acm.org/doi/10.1145/2810103.2813707) | [David Adrian](https://github.com/dadrian), Karthikeyan Bhargavan, [Zakir Durumeric](https://github.com/zakird), Pierrick Gaudry, Matthew Green, [J. Alex Halderman](https://github.com/jhalderm), [Nadia Heninger](https://github.com/factorable), Drew Springall, Emmanuel Thomé, [Luke Valenta](https://github.com/lukevalenta) | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |
| [Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM in TLS](https://www.usenix.org/conference/woot16/workshop-program/presentation/bock) | [Hanno Böck](https://github.com/hannob), [Aaron Zauner](https://github.com/azet), Sean Devlin, [Juraj Somorovsky](https://github.com/jurajsomorovsky), [Philipp Jovanovic](https://github.com/Daeinar) | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |
| [Whitening Sentence Representations for Better Semantics and Faster Retrieval](https://arxiv.org/abs/2103.15316) | [Jianlin Su](https://github.com/bojone), [Jiarun Cao](https://github.com/jiaruncao), Weijie Liu, Yangyiwen Ou | [semantic_search.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/semantic_search.py) |
| [Constant Propagation with Conditional Branches](https://dl.acm.org/doi/abs/10.1145/103135.103136) | Mark N. Wegman, F. Kenneth Zadeck | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| [A Simple, Fast Dominance Algorithm](https://www.cs.princeton.edu/techreports/2005/737.pdf) | Cooper, Harvey, Kennedy | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| [libdft: Practical Dynamic Data Flow Tracking for Commodity Systems](https://dl.acm.org/doi/10.1145/2151024.2151042) | [Vasileios P. Kemerlis](https://github.com/vkemerlis), [Georgios Portokalidis](https://github.com/portokalidis), [Kangkook Jee](https://github.com/jikk), Angelos D. Keromytis | [taint_tracker_x86.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_x86.py) · [taint_tracker_arm32.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_arm32.py) |

**도서** 제공: [www.oreilly.com](https://www.oreilly.com) | [github.com/oreillymedia](https://github.com/oreillymedia)

| 제목 | 저자 | 인용 |
|---|---|---|
| The Art of Software Security Assessment | [Mark Dowd](https://github.com/mdowd79), John McDonald, [Justin Schuh](https://github.com/jschuh) | [heap_vuln_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/heap_vuln_scanner.py) · [format_string_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/format_string_scanner.py) · [ioctl_attack_surface.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/ioctl_attack_surface.py) |
| Practical Binary Analysis | [Dennis Andriesse](https://github.com/dennisaa) | [taint_tracker_x86.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_x86.py) · [disasm_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/disasm_engine.py) |
| Practical Malware Analysis | Michael Sikorski, Andrew Honig | [pe_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/pe_parser.py) · [shellcode_utils.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/shellcode_utils.py) |
| Practical Reverse Engineering | Bruce Dang, Alexandre Gazet, [Elias Bachaalany](https://github.com/0xeb) | [pe_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/pe_analyzer.py) · [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) |
| Hacking: The Art of Exploitation (2e) | Jon Erickson | [platform_detect.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/platform_detect.py) |
| Learning Linux Binary Analysis | [Ryan O'Neill](https://github.com/elfmaster) | [elf_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/elf_parser.py) · [binary_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/binary_parser.py) |
| Windows Internals Part 1 & 2 | [Pavel Yosifovich](https://github.com/zodiacon), [Mark Russinovich](https://github.com/markrussinovich), David Solomon, [Alex Ionescu](https://github.com/ionescu007), [Andrea Allievi](https://github.com/AaLl86) | [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) · [ioctl_attack_surface.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/ioctl_attack_surface.py) |
| Rootkits: Subverting the Windows Kernel | Greg Hoglund, Jamie Butler | [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) · [yara_generator.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/yara_generator.py) |
| Advanced Compiler Design and Implementation | Steven Muchnick | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| Engineering a Compiler | Keith Cooper, Linda Torczon | [disasm_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/disasm_engine.py) |
| Practical IoT Hacking | [Fotios Chantzis](https://github.com/ithilgore), Ioannis Stais, Paulino Calderon, Evangelos Deirmentzoglou, Beau Woods | [firmware_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/firmware_analyzer.py) |
| Inside the Android OS: Building, Customizing, Managing and Operating Android System Services | G. Blake Meike | [apk_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/apk_parser.py) · [jni_bridge_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/jni_bridge_scanner.py) · [binder_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/binder_scanner.py) |
| Malware Analysis and Detection Engineering | [Abhijit Mohanta](https://github.com/amohanta), Anoop Saldanha | [yara_generator.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/yara_generator.py) |
| Evasive Malware | [Kyle Cucci](https://github.com/d4rksystem) | [process_enum.py](https://github.com/Ablation-Tool/ablation/blob/main/modules/process_enum.py) |
| Hacking Cryptography | [Kamran Khan](https://github.com/krkhan), [Bill Cox](https://github.com/waywardgeek) | [tls_enum.py](https://github.com/Ablation-Tool/ablation/blob/main/modules/tls_enum.py) |
| Real-World Cryptography | David Wong | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |

**특별 언급**

[Microsoft Excel (Data Analysis ToolPak)](https://support.microsoft.com/en-us/office/use-the-analysis-toolpak-to-perform-complex-data-analysis-6c67ccf0-f4a9-487c-8dec-bdb5a2cefab6) 폐쇄된 인프라를 분석하거나 블랙박스 시스템을 보호할 때, 이 정확한 프로세스를 타이밍 분석 또는 텔레메트리 리버스 엔지니어링이라고 합니다. 소스 코드 없이 Data Analysis ToolPak은 애플리케이션의 입력과 출력을 엄격하게 관찰하여 백엔드에서 애플리케이션이 작동하는 방식을 수학적으로 분해합니다.

---

## 프레임워크 아키텍처 및 모듈 오케스트레이션```mermaid
flowchart TD
    Binary(["<b>Target Binary</b><br/><i>ELF · PE · firmware</i>"])
    Claude(["<b>Claude Code (Orchestrator)</b><br/><i>Central Agent Controller</i>"])

    Binary -->|"load"| BCtx["<b>BinaryContext</b><br/><i>PLT · Strings · Call Graph · XRefs</i>"]
    BCtx -->|"context"| Corpus["<b>Corpus Builder</b><br/><i>Semantic Embedding DB</i>"]
    BCtx -->|"context"| Taint["<b>Taint Engine</b><br/><i>Data Flow / Sinks</i>"]
    BCtx -->|"context"| Diffing["<b>Diffing Engine</b><br/><i>DTW / Version Delta</i>"]
    BCtx -->|"context"| FmtStr["<b>Format String</b><br/><i>Specifier Scanner</i>"]
    BCtx -->|"context"| Heap["<b>Heap Scanner</b><br/><i>Chunk / UAF Audit</i>"]
    BCtx -->|"context"| MultiArch["<b>Multi-Arch Engine</b><br/><i>MIPS · PPC · RISC-V · ARC · V850</i>"]
    BCtx -->|"context"| Driver["<b>Driver Engine</b><br/><i>Kernel IOCTL / BYOVD Audit</i>"]

    Corpus -->|"embeddings"| Semantic["<b>Semantic Search</b><br/><i>BERT Behavioral Fingerprints</i>"]

    Semantic -. "candidates" .-> Claude
    Taint -. "findings" .-> Claude
    Diffing -. "findings" .-> Claude
    FmtStr -. "findings" .-> Claude
    Heap -. "findings" .-> Claude
    MultiArch -. "findings" .-> Claude
    Driver -. "findings" .-> Claude

    Claude -->|"confirmed finding"| Registry["<b>Finding Registry</b><br/><i>Cross-Target Corpus</i>"]
    Registry -->|"seeds future sweeps"| Semantic

    classDef primary fill:#2a1a4a,stroke:#7c3aed,stroke-width:2px,color:#fff
    classDef foundation fill:#0d1117,stroke:#58a6ff,stroke-width:2px,color:#e5e7eb
    classDef engine fill:#171717,stroke:#404040,stroke-width:1px,color:#e5e7eb
    classDef feedback fill:#0d2818,stroke:#238636,stroke-width:2px,color:#e5e7eb

    class Claude,Binary primary
    class BCtx foundation
    class Corpus,Semantic,Taint,Diffing,FmtStr,Heap,MultiArch,Driver engine
    class Registry feedback

RE 워크플로 예시

RPM 번들에서 추출한 스트립된 바이너리의 엔드투엔드 분석. 추출부터 BinaryContext, 문자열 교차 참조, capstone 디스어셈블리를 거쳐 확인된 발견 사항까지.```mermaid flowchart TD RPM["target-package.rpm
third-party bundle · x86-64"]

root@kitploit:~
RPM -->|rpm2cpio / cpio| EXTRACT["platform/linux-x86_64/"]

EXTRACT --> PI["bin/inference_engine<br/>stripped PIE · x86-64"]
EXTRACT --> CTRL["bin/controller<br/>stripped PIE · x86-64"]
EXTRACT --> LIBS["lib/libcore.so<br/>lib/libruntime.so"]

subgraph TRACK_PI ["inference engine track"]
    direction TB
    BCI["BinaryContext.load_or_build()<br/>32 func starts · 551 strings · PLT built"]
    BCI --> SS["ctx.strings scan<br/>api_op_read VA 0x51560<br/>api_op_write VA 0x51570<br/>license_key_flag 0x52e08"]
    SS --> XREF["ctx.string_xrefs()<br/>both ops xref → 0x17499, 0x174af<br/>ctx.func_containing() → init fn 0x10000"]
    XREF --> DA1["capstone disasm 0x17450<br/>lea rsi → api_op_read · call set::insert<br/>lea rsi → api_op_write · call set::insert<br/>CONFIRMED: exactly 2 blocklist entries"]
    DA1 --> DA2["capstone disasm 0x16511<br/>cmp qword ptr [r9], 0<br/>je → model loads · ne → handleFatal<br/>empty set = bypass confirmed"]
end

subgraph TRACK_LIBS ["library analysis"]
    direction TB
    NM["nm -D libcore.so<br/>spawn at 0xfdb20 · ctor at 0xfcfd0"]
    NM --> DA3["capstone disasm libcore.so:0xfdbc7<br/>cmp entry length == exe_path length<br/>memcmp at 0xfdbdb<br/>proper equality check · no prefix bypass"]
    LSCAN["re.findall api_op:: in libruntime.so<br/>2481 distinct ops found<br/>2 blocked · 2479 unblocked"]
end

subgraph TRACK_CTRL ["controller track"]
    direction TB
    BCC["BinaryContext.load_or_build()<br/>18 func starts · PLT · strings"]
    BCC --> XREF2["ctx.string_xrefs() on 5 path strings<br/>./worker1 · ./worker2<br/>./worker3 · ./worker4<br/>./inference_engine<br/>all xref at 0x9a04-0x9a5e"]
    XREF2 --> DA4["capstone disasm 0x99e9<br/>call CApp::progDir()<br/>call OsUtils::chdir()<br/>chdir to binary dir before spawn"]
    DA4 --> DA5["capstone disasm 0x11500<br/>args vector from command pipe tokens<br/>passed raw to spawn() at 0x11699<br/>no validation"]
end

PI --> BCI
PI --> BCC
LIBS --> NM
LIBS --> LSCAN

DA2 --> F1
LSCAN --> F1["F1 · HIGH<br/>blocklist covers 2 of 2481 ops<br/>upload malicious model via API<br/>seccomp BPF not decoded — CIA open"]

DA3 --> F2
XREF2 --> F2["F2 · LOW<br/>controller spawn allowlist is sound<br/>but args vector unchecked<br/>requires service user pipe access"]

DA5 --> F2

SS --> F3["F3 · INFO<br/>license gate = JSON field only<br/>no cryptographic verification"]

classDef finding fill:#1a1a2e,stroke:#e94560,stroke-width:2px,color:#fff
classDef tool fill:#16213e,stroke:#0f3460,stroke-width:1px,color:#e5e7eb
classDef binary fill:#0f3460,stroke:#533483,stroke-width:2px,color:#fff
classDef input fill:#533483,stroke:#7c3aed,stroke-width:2px,color:#fff

class F1,F2,F3 finding
class BCI,BCC,NM,LSCAN,SS,XREF,XREF2,DA1,DA2,DA3,DA4,DA5 tool
class PI,CTRL,LIBS binary
class RPM,EXTRACT input
root@kitploit:~
도구 다운로드
CVE제품제목CVSS권고
CVE-2026-76420Secure Firewall Management Center (FMC)Peer Impersonation9.0 Criticalcisco-sa-fmc2-multivulns-HXgcqRG
CVE-2026-76412Secure Firewall Management Center (FMC)Privilege Escalation to root8.5 Highcisco-sa-fmc2-multivulns-HXgcqRG
CVE-2026-76413Secure Firewall Management Center (FMC)Single Sign-On Token Forgery8.5 Highcisco-sa-fmc2-multivulns-HXgcqRG
CVE-2026-76447Identity Services Engine (ISE)OCSP Responder Authentication Bypass5.3 Mediumcisco-sa-ise-multiauth-bypass-sgD2HbL4
아키텍처변형
x86x86-32 · x86-64
ARMARM-32 · ARM-64
MIPSMIPS-32 · nanoMIPS · MIPS-64
PowerPCPPC-32 · PPC-64
RISC-VRISC-V 32 · RISC-V 64
EmbeddedARC EM/HS · V850-32