逆向工程框架,具备反汇编、反编译、污点分析、版本差异比对和语义搜索功能,并支持LLM驱动的自主二进制与固件分析。
Ablation 是一个逆向工程框架,提供与 Ghidra、IDA Pro 和 Binary Ninja 等行业标准工具完全相同的核心反汇编、反编译和二进制分析能力。
结合 Claude Code 或 OpenAI Codex,它可转变为完全自主的逆向工程工具。

基于 BERT 的语义搜索: 语义搜索根据含义而非精确关键词来查找结果。BERT 读取文本并理解其含义。相似的含义会得到相似的评分,因此你可以按概念而非精确词语进行搜索。通过将两者结合,它加速了逆向工程的主要瓶颈,同时发现存在漏洞的函数。
极致性能: 一个 50 MB 的二进制文件在 35 秒内加载完成。Ghidra 和 IDA Pro 可能需要数小时,因为它们会先将整个文件解析到数据库中,之后你才能进行任何操作。Ablation 只分析你正在积极处理的函数,因此你可以立即开始。
版本差异比对: 利用 Jaccard 方法衡量函数行为在不同版本之间的重叠程度,并使用动态时间规整(Dynamic Time Warping)追踪函数在厂商更新的固件或软件各版本中执行的“形态”,Ablation 能够确认补丁是否真正改变了逻辑,还是仅仅改变了打包方式,因为表面性的重新编译无法掩盖未修补的漏洞。
跨二进制分析: 同时分析固件镜像中的每个共享库,追踪跨二进制边界的数据流。
源代码审计: 以比线性阅读更快的速度审计任何大型代码库,且准确率高于单纯的模式匹配。每个源文件都会获得一个 5 位安全画像,精确决定它需要多少关注,因此不会有任何遗漏,也不会有任何内容被重复阅读。
Windows 内核驱动与 BYOVD 分析: 映射 IRP 调度表,解码每个 IOCTL 代码,并识别哪些内核 API 从用户态暴露物理内存和令牌原语。BYOVD 检测器会对携带这些能力的已签名驱动进行指纹识别,因为一个合法的已签名驱动就足以让 EDR 在 ring-0 层面失明。
Android / APK 分析: 在二进制层面读取 Android APK,无需任何依赖。它从编译后的字节码中映射原生代码入口点和 IPC 表面,因此无需反编译即可看到完整的攻击面。
Erlang / BEAM 分析: Erlang 编译为 .beam 文件,用于 ELF 的相同表面映射方法可直接适用,因此原子搜索、导入审计和混淆检测无需特殊处理。扫描一个发布目录只需几秒钟。
解密
Ablation 已被用于分析来自 Fortinet、Cisco、Juniper、Axis、Fujitsu、MikroTik、Orka、TencentOS、Enigma2、Skydio 和 Dahua Security System 的生产固件和内核驱动。
在针对 Cisco FMC 和 ISE 进行协调披露之后,Cisco 产品安全事件响应团队(PSIRT)已采用 Ablation 进行内部漏洞分类。Cisco PSIRT 正在积极使用它对 Firepower Threat Defense(FTD)、Cisco Secure Client(AnyConnect)、HyperFlex 和 Catalyst 上正在进行的披露报告进行分类。Cisco Adaptive Security Appliance(ASA)LINA 也已使用 Ablation 进行逆向工程,相关发现目前正通过 CERT/CC VINCE 进行协调分类。
| 提供商 | 模型 |
|---|---|
| Claude Code | /model claude-sonnet-4-6 |
| OpenAI Codex | 所有已知模型 |
pip install git+https://github.com/Ablation-Tool/ablation
---
## 环境要求
- Python >= 3.10
- `capstone`、`numpy`、`lief`、`sentence-transformers`、`pyelftools`
- 可选:`anthropic`,用于 LLM 功能
---
## 负责任的使用
Ablation 专为授权的安全研究而构建。请仅针对您拥有或已获得明确书面许可进行测试的系统使用它。未经授权对系统运行本工具,在大多数司法管辖区均违反计算机欺诈相关法律。作者不对任何滥用行为承担责任。
---
## 致谢
本项目在很大程度上受到若干重要文献著作的启发与影响。
**研究论文**
| 标题 | 作者 | 引用 |
|---|---|---|
| [Finding Taint-Style Vulnerabilities in Linux-based Embedded Firmware with SSE-based Alias Analysis](https://arxiv.org/abs/2109.12209) | Cheng, Zheng, Liu, Guan, Liu, Li, Zhu, Ye, Sun | [sse_slicer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/sse_slicer.py) · [arm64_global_tracker.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/arm64_global_tracker.py) |
| [iResolveX: Multi-Layered Indirect Call Resolution via Static Reasoning and Learning-Augmented Refinement](https://arxiv.org/abs/2601.17888) | Monika Santra, Bokai Zhang, Mark Lim, [Vishnu Asutosh Dasu](https://github.com/vdasu), Dongrui Zeng, [Gang Tan](https://github.com/gangtan) | [vtable_resolver.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/vtable_resolver.py) · [interproc_field_writer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/interproc_field_writer.py) · [arm64_global_tracker.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/arm64_global_tracker.py) |
| [Extracting Protocol Format as State Machine via Controlled Static Loop Analysis](https://arxiv.org/abs/2305.13483) | [Qingkai Shi](https://github.com/qingkaishi), Xiangzhe Xu, Xiangyu Zhang | [proto_fsm.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/proto_fsm.py) |
| [NEMETYL: Message Type Identification of Binary Network Protocols using Continuous Segment Similarity](https://arxiv.org/abs/2002.03391) | [Stephan Kleber](https://github.com/vs-uulm), Rens Wouter van der Heijden, [Frank Kargl](https://github.com/fkargl) | [proto_fsm.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/proto_fsm.py) |
| [Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice](https://dl.acm.org/doi/10.1145/2810103.2813707) | [David Adrian](https://github.com/dadrian), Karthikeyan Bhargavan, [Zakir Durumeric](https://github.com/zakird), Pierrick Gaudry, Matthew Green, [J. Alex Halderman](https://github.com/jhalderm), [Nadia Heninger](https://github.com/factorable), Drew Springall, Emmanuel Thomé, [Luke Valenta](https://github.com/lukevalenta) | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |
| [Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM in TLS](https://www.usenix.org/conference/woot16/workshop-program/presentation/bock) | [Hanno Böck](https://github.com/hannob), [Aaron Zauner](https://github.com/azet), Sean Devlin, [Juraj Somorovsky](https://github.com/jurajsomorovsky), [Philipp Jovanovic](https://github.com/Daeinar) | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |
| [Whitening Sentence Representations for Better Semantics and Faster Retrieval](https://arxiv.org/abs/2103.15316) | [Jianlin Su](https://github.com/bojone), [Jiarun Cao](https://github.com/jiaruncao), Weijie Liu, Yangyiwen Ou | [semantic_search.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/semantic_search.py) |
| [Constant Propagation with Conditional Branches](https://dl.acm.org/doi/abs/10.1145/103135.103136) | Mark N. Wegman, F. Kenneth Zadeck | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| [A Simple, Fast Dominance Algorithm](https://www.cs.princeton.edu/techreports/2005/737.pdf) | Cooper, Harvey, Kennedy | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| [libdft: Practical Dynamic Data Flow Tracking for Commodity Systems](https://dl.acm.org/doi/10.1145/2151024.2151042) | [Vasileios P. Kemerlis](https://github.com/vkemerlis), [Georgios Portokalidis](https://github.com/portokalidis), [Kangkook Jee](https://github.com/jikk), Angelos D. Keromytis | [taint_tracker_x86.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_x86.py) · [taint_tracker_arm32.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_arm32.py) |
**书籍** 由 [www.oreilly.com](https://www.oreilly.com) 提供 | [github.com/oreillymedia](https://github.com/oreillymedia)
| 标题 | 作者 | 引用 |
|---|---|---|
| The Art of Software Security Assessment | [Mark Dowd](https://github.com/mdowd79), John McDonald, [Justin Schuh](https://github.com/jschuh) | [heap_vuln_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/heap_vuln_scanner.py) · [format_string_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/format_string_scanner.py) · [ioctl_attack_surface.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/ioctl_attack_surface.py) |
| Practical Binary Analysis | [Dennis Andriesse](https://github.com/dennisaa) | [taint_tracker_x86.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_x86.py) · [disasm_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/disasm_engine.py) |
| Practical Malware Analysis | Michael Sikorski, Andrew Honig | [pe_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/pe_parser.py) · [shellcode_utils.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/shellcode_utils.py) |
| Practical Reverse Engineering | Bruce Dang, Alexandre Gazet, [Elias Bachaalany](https://github.com/0xeb) | [pe_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/pe_analyzer.py) · [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) |
| Hacking: The Art of Exploitation (2e) | Jon Erickson | [platform_detect.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/platform_detect.py) |
| Learning Linux Binary Analysis | [Ryan O'Neill](https://github.com/elfmaster) | [elf_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/elf_parser.py) · [binary_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/binary_parser.py) |
| Windows Internals Part 1 & 2 | [Pavel Yosifovich](https://github.com/zodiacon), [Mark Russinovich](https://github.com/markrussinovich), David Solomon, [Alex Ionescu](https://github.com/ionescu007), [Andrea Allievi](https://github.com/AaLl86) | [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) · [ioctl_attack_surface.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/ioctl_attack_surface.py) |
| Rootkits: Subverting the Windows Kernel | Greg Hoglund, Jamie Butler | [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) · [yara_generator.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/yara_generator.py) |
| Advanced Compiler Design and Implementation | Steven Muchnick | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| Engineering a Compiler | Keith Cooper, Linda Torczon | [disasm_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/disasm_engine.py) |
| Practical IoT Hacking | [Fotios Chantzis](https://github.com/ithilgore), Ioannis Stais, Paulino Calderon, Evangelos Deirmentzoglou, Beau Woods | [firmware_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/firmware_analyzer.py) |
| Inside the Android OS: Building, Customizing, Managing and Operating Android System Services | G. Blake Meike | [apk_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/apk_parser.py) · [jni_bridge_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/jni_bridge_scanner.py) · [binder_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/binder_scanner.py) |
| Malware Analysis and Detection Engineering | [Abhijit Mohanta](https://github.com/amohanta), Anoop Saldanha | [yara_generator.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/yara_generator.py) |
| Evasive Malware | [Kyle Cucci](https://github.com/d4rksystem) | [process_enum.py](https://github.com/Ablation-Tool/ablation/blob/main/modules/process_enum.py) |
| Hacking Cryptography | [Kamran Khan](https://github.com/krkhan), [Bill Cox](https://github.com/waywardgeek) | [tls_enum.py](https://github.com/Ablation-Tool/ablation/blob/main/modules/tls_enum.py) |
| Real-World Cryptography | David Wong | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |
**荣誉提名**
[Microsoft Excel(数据分析工具库)](https://support.microsoft.com/en-us/office/use-the-analysis-toolpak-to-perform-complex-data-analysis-6c67ccf0-f4a9-487c-8dec-bdb5a2cefab6) 在分析封闭基础设施或保护黑盒系统时,这一确切过程被称为时序分析或遥测逆向工程。在没有源代码的情况下,数据分析工具库通过严格观察应用程序的输入与输出,从数学上解构其后端的工作方式。
---
## 框架架构与模块编排```mermaid
flowchart TD
Binary(["<b>Target Binary</b><br/><i>ELF · PE · firmware</i>"])
Claude(["<b>Claude Code (Orchestrator)</b><br/><i>Central Agent Controller</i>"])
Binary -->|"load"| BCtx["<b>BinaryContext</b><br/><i>PLT · Strings · Call Graph · XRefs</i>"]
BCtx -->|"context"| Corpus["<b>Corpus Builder</b><br/><i>Semantic Embedding DB</i>"]
BCtx -->|"context"| Taint["<b>Taint Engine</b><br/><i>Data Flow / Sinks</i>"]
BCtx -->|"context"| Diffing["<b>Diffing Engine</b><br/><i>DTW / Version Delta</i>"]
BCtx -->|"context"| FmtStr["<b>Format String</b><br/><i>Specifier Scanner</i>"]
BCtx -->|"context"| Heap["<b>Heap Scanner</b><br/><i>Chunk / UAF Audit</i>"]
BCtx -->|"context"| MultiArch["<b>Multi-Arch Engine</b><br/><i>MIPS · PPC · RISC-V · ARC · V850</i>"]
BCtx -->|"context"| Driver["<b>Driver Engine</b><br/><i>Kernel IOCTL / BYOVD Audit</i>"]
Corpus -->|"embeddings"| Semantic["<b>Semantic Search</b><br/><i>BERT Behavioral Fingerprints</i>"]
Semantic -. "candidates" .-> Claude
Taint -. "findings" .-> Claude
Diffing -. "findings" .-> Claude
FmtStr -. "findings" .-> Claude
Heap -. "findings" .-> Claude
MultiArch -. "findings" .-> Claude
Driver -. "findings" .-> Claude
Claude -->|"confirmed finding"| Registry["<b>Finding Registry</b><br/><i>Cross-Target Corpus</i>"]
Registry -->|"seeds future sweeps"| Semantic
classDef primary fill:#2a1a4a,stroke:#7c3aed,stroke-width:2px,color:#fff
classDef foundation fill:#0d1117,stroke:#58a6ff,stroke-width:2px,color:#e5e7eb
classDef engine fill:#171717,stroke:#404040,stroke-width:1px,color:#e5e7eb
classDef feedback fill:#0d2818,stroke:#238636,stroke-width:2px,color:#e5e7eb
class Claude,Binary primary
class BCtx foundation
class Corpus,Semantic,Taint,Diffing,FmtStr,Heap,MultiArch,Driver engine
class Registry feedback
对来自 RPM 捆绑包的 stripped 二进制文件进行端到端分析。从提取到 BinaryContext、字符串交叉引用,再到 capstone 反汇编,最终确认发现。```mermaid
flowchart TD
RPM["target-package.rpm
third-party bundle · x86-64"]
RPM -->|rpm2cpio / cpio| EXTRACT["platform/linux-x86_64/"]
EXTRACT --> PI["bin/inference_engine<br/>stripped PIE · x86-64"]
EXTRACT --> CTRL["bin/controller<br/>stripped PIE · x86-64"]
EXTRACT --> LIBS["lib/libcore.so<br/>lib/libruntime.so"]
subgraph TRACK_PI ["inference engine track"]
direction TB
BCI["BinaryContext.load_or_build()<br/>32 func starts · 551 strings · PLT built"]
BCI --> SS["ctx.strings scan<br/>api_op_read VA 0x51560<br/>api_op_write VA 0x51570<br/>license_key_flag 0x52e08"]
SS --> XREF["ctx.string_xrefs()<br/>both ops xref → 0x17499, 0x174af<br/>ctx.func_containing() → init fn 0x10000"]
XREF --> DA1["capstone disasm 0x17450<br/>lea rsi → api_op_read · call set::insert<br/>lea rsi → api_op_write · call set::insert<br/>CONFIRMED: exactly 2 blocklist entries"]
DA1 --> DA2["capstone disasm 0x16511<br/>cmp qword ptr [r9], 0<br/>je → model loads · ne → handleFatal<br/>empty set = bypass confirmed"]
end
subgraph TRACK_LIBS ["library analysis"]
direction TB
NM["nm -D libcore.so<br/>spawn at 0xfdb20 · ctor at 0xfcfd0"]
NM --> DA3["capstone disasm libcore.so:0xfdbc7<br/>cmp entry length == exe_path length<br/>memcmp at 0xfdbdb<br/>proper equality check · no prefix bypass"]
LSCAN["re.findall api_op:: in libruntime.so<br/>2481 distinct ops found<br/>2 blocked · 2479 unblocked"]
end
subgraph TRACK_CTRL ["controller track"]
direction TB
BCC["BinaryContext.load_or_build()<br/>18 func starts · PLT · strings"]
BCC --> XREF2["ctx.string_xrefs() on 5 path strings<br/>./worker1 · ./worker2<br/>./worker3 · ./worker4<br/>./inference_engine<br/>all xref at 0x9a04-0x9a5e"]
XREF2 --> DA4["capstone disasm 0x99e9<br/>call CApp::progDir()<br/>call OsUtils::chdir()<br/>chdir to binary dir before spawn"]
DA4 --> DA5["capstone disasm 0x11500<br/>args vector from command pipe tokens<br/>passed raw to spawn() at 0x11699<br/>no validation"]
end
PI --> BCI
PI --> BCC
LIBS --> NM
LIBS --> LSCAN
DA2 --> F1
LSCAN --> F1["F1 · HIGH<br/>blocklist covers 2 of 2481 ops<br/>upload malicious model via API<br/>seccomp BPF not decoded — CIA open"]
DA3 --> F2
XREF2 --> F2["F2 · LOW<br/>controller spawn allowlist is sound<br/>but args vector unchecked<br/>requires service user pipe access"]
DA5 --> F2
SS --> F3["F3 · INFO<br/>license gate = JSON field only<br/>no cryptographic verification"]
classDef finding fill:#1a1a2e,stroke:#e94560,stroke-width:2px,color:#fff
classDef tool fill:#16213e,stroke:#0f3460,stroke-width:1px,color:#e5e7eb
classDef binary fill:#0f3460,stroke:#533483,stroke-width:2px,color:#fff
classDef input fill:#533483,stroke:#7c3aed,stroke-width:2px,color:#fff
class F1,F2,F3 finding
class BCI,BCC,NM,LSCAN,SS,XREF,XREF2,DA1,DA2,DA3,DA4,DA5 tool
class PI,CTRL,LIBS binary
class RPM,EXTRACT input
| CVE | 产品 | 标题 | CVSS | 公告 |
|---|
| CVE-2026-76420 | Secure Firewall Management Center (FMC) | 对等方身份冒充 | 9.0 Critical | cisco-sa-fmc2-multivulns-HXgcqRG |
| CVE-2026-76412 | Secure Firewall Management Center (FMC) | 提权至 root | 8.5 High | cisco-sa-fmc2-multivulns-HXgcqRG |
| CVE-2026-76413 | Secure Firewall Management Center (FMC) | 单点登录令牌伪造 | 8.5 High | cisco-sa-fmc2-multivulns-HXgcqRG |
| CVE-2026-76447 | Identity Services Engine (ISE) | OCSP 响应器身份验证绕过 | 5.3 Medium | cisco-sa-ise-multiauth-bypass-sgD2HbL4 |
| 架构 | 变体 |
|---|
| x86 | x86-32 · x86-64 |
| ARM | ARM-32 · ARM-64 |
| MIPS | MIPS-32 · nanoMIPS · MIPS-64 |
| PowerPC | PPC-32 · PPC-64 |
| RISC-V | RISC-V 32 · RISC-V 64 |
| Embedded | ARC EM/HS · V850-32 |