Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

FeedsContatoPrivacidade© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
kunglao-agent — The reverse-engineering expert agent: plans its own analysis path, derives every fact from raw evidence, and converges under mechanical verification gates — firmware, protocols, web/JS, risk-control, binaries. | Kitploit
Ferramentas/GitHubGitHub/amd2g2zz/kunglao-agent
Android SecurityStatic AnalysisDynamic Analysis (Sandboxing)Vulnerability AnalysisMobile App PentestingReverse EngineeringWeb SecurityMalware AnalysisBinary AnalysisAI-Assisted ReversingFirmware Analysis
481694há 6h 33mRevisado pelo Kitploit

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
GitHubamd2g2zz/kunglao-agent

kunglao-agent

The reverse-engineering expert agent: plans its own analysis path, derives every fact from raw evidence, and converges under mechanical verification gates — firmware, protocols, web/JS, risk-control, binaries.

Ver RepositórioSite
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

kunglao-agent

kunglao-agent is an autonomous reverse-engineering system. You hand it a target and the questions you need answered; it works the problem for hours or days on its own — planning its own path, recovering from worker deaths, resuming after crashes — and converges only when every answer is derived from raw evidence and survives mechanical verification gates.

release-check python license PRs welcome

English · Simplified Chinese

It currently ships as a Claude Code plugin — Claude Code is the interface you talk to, not what the product is. The product is the loop: specialist workers analyse (static first), an independent verifier re-derives every fact blind from the raw evidence, and mechanical gates decide when the work is done. The deliverable is a fact base where every claim is byte-anchored, independently verified, and evidence-indexed — trust is enforced by machinery, not convention.

Why kunglao-agent

  • Long-horizon by design. Engagements run unattended across hours and days: a scheduled heartbeat keeps the loop alive, dead workers are reconciled and their claims re-queued, crashes resume from on-disk state, blocked claims self-recover. You read the verdict when it converges — you don't babysit each step. See Long-horizon autonomy.
  • Answers you can trust. No fact is PROVEN until an independent verifier re-derives it blind from the raw artifact; every fact cites a sha256-indexed raw artifact through evidence/_index.json.
  • The full reverse-engineering spectrum. Windows/Linux native binaries, Android APKs, web/JS, protocol analysis, firmware emulation, risk-control countermeasures — one system, not a single-domain tool.
  • Static-first economics. A task that closes statically never touches dynamic tooling; every escalation is declared, gated, and audited.
  • It reuses knowledge instead of re-deriving it. A growing catalog of registered analysis tools (crypto decoders, disassembly pipelines, graph queries) means the system reaches for proven tooling before writing one-off scripts — and every run leaves behind reusable facts, not a chat transcript that evaporates.
  • It recovers instead of dying. Worker deaths, API disconnects, and crashes are first-class events: the loop detects them, snapshots what was already produced, and re-dispatches to continue from where things stopped — not from zero.
  • Your environment, your rules. VMware, ssh, docker, adb, or plain static-only — the system drives whichever execution channel you already have. Nothing is a degraded mode; a task that never needs execution never asks for a VM.

Quick start

kunglao-agent runs inside Claude Code. From a sample on disk to a verdict:

ToolWhyInstall
Claude Codewhere kunglao-agent runsper Anthropic docs
Python 3.10+ (Python 2 is not supported)the plugin carries a pinned env via uv; you do not touch itsystem or uv-managed
uvlocked env resolverpip install uv or astral.sh/uv
Ghidra or IDAone static-analysis suite for decompilationsee Toolchain by target

1. Install the plugin

From any directory, in Claude Code:

/plugin marketplace add amd2g2zz/kunglao-agent
/plugin install kunglao-agent@kunglao-agent

(Alternative: claude --plugin-dir /path/to/kunglao-agent for development.)

2. Init a workspace

/kunglao-agent:init ~/cases/synth-dropper --type windows

kunglao-init scaffolds the workspace, writes CLAUDE.md, probes the toolchain for your --type, and scaffolds .mcp.json. It HARD-rejects when a required tool for your type is missing — the fix guidance is in the error block.

3. State the task and start the analysis

/kunglao-agent:analysis ~/cases/synth-dropper
> Goal: confirm this dropper's persistence mechanism and network endpoints;
>   every conclusion must be reproducible from raw evidence.
> Verification: key findings count only if an independent verifier re-derives
>   them blind and reaches the same answer.
> Constraints: static-first; never execute the sample on the host.

Write the brief so an independent reviewer could judge the result: analysis goal (what you need to know), verification logic (what makes an answer trustworthy — e.g. "the signature must be reproducible from the same inputs"), constraints (e.g. "no execution on the host"). Everything is recorded in task_spec.yaml; from there the loop drives itself. For how the common asks turn into well-formed statements, see How to state the task.

4. Read the deliverable

claim-register.yaml   # every claim terminal, with verifier sign-off
facts/F<NNN>.md       # byte-anchored, reproducible, frontmatter contract
evidence/_index.json  # every fact → raw artifact (sha256 + path)
runs/                 # session audit trail

How to state the task

The loop derives its completion criterion — the oracle — mechanically from the end-state you state. A vague statement yields a vague oracle, and the analysis drifts toward whatever can be proven instead of what you needed. Four phrasings cover most of that drift. For each: what users say, what it usually means, a well-formed statement, and what the oracle anchors on.

"我要纯算" — "just the pure algorithm"

Usually means: offline reproduction of the app's signing/crypto routine — a unidbg harness or a rewrite that runs with no device and no app at run time. Not "analyze the app"; the app is only where the algorithm lives.

> Sample: the v7.2 APK; behavior: the signer producing the `sign`
>   header on api.example.com/v2/* requests.
> Criterion: a standalone reproduction (unidbg or rewrite) replays
>   every captured (input → sign) pair byte-exact — including the
>   withheld pairs — with no device or app at run time.
> Attach: captures/sign-pairs.jsonl — 20 input/output pairs captured
>   from a live session; 10 of them withheld from the analysis.

Oracle anchors on: byte-exact replay on every pair, including the withheld ones — and the reproduction running standalone.

"我要解密" — "I want decryption"

Usually means one of two different targets — say which:

  • (a) decrypt one captured body — a one-off answer about this data: "produce the plaintext of this captured cache file."
  • (b) a decryption capability — algorithm + key recovery, reusable on data you capture tomorrow.

Well-formed (a):

> Sample: the v7.2 APK; behavior: the local config cache
>   files/.cfg/v2.dat is encrypted at rest.
> Criterion: produce the plaintext of the captured v2.dat and validate
>   it against what the app renders (field names and values match the
>   screenshot captured alongside).

Well-formed (b):

> Sample: the v7.2 APK; behavior: request bodies on
>   api.example.com/v2/* are encrypted with a static key.
> Criterion: identify the algorithm and the key, then run a canary
>   round-trip — encrypt a known plaintext with the recovered key and
>   match the ciphertext the device produced, byte for byte.
> Attach: captures/request-bodies.jsonl — ciphertext bodies captured
>   from the device, with the requests that produced them.
Baixar ferramenta