Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
ablation — 逆向工程框架,具备反汇编、反编译、污点分析、版本差异比对和语义搜索功能,并支持LLM驱动的自主二进制与固件分析。 | Kitploit
工具/GitHubGitHub/ablation-tool/ablation
Android安全静态分析漏洞分析逆向工程恶意软件分析密码学二进制分析论文与研究AI 辅助逆向固件分析
GitHubablation-tool/ablation

ablation

35286小时25分前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

逆向工程框架,具备反汇编、反编译、污点分析、版本差异比对和语义搜索功能,并支持LLM驱动的自主二进制与固件分析。

查看仓库
ABLATION

Ablation 是一个逆向工程框架,提供与 Ghidra、IDA Pro 和 Binary Ninja 等行业标准工具完全相同的核心反汇编、反编译和二进制分析能力。

结合 Claude Code 或 OpenAI Codex,它可转变为完全自主的逆向工程工具。


Codex demo

功能

基于 BERT 的语义搜索: 语义搜索根据含义而非精确关键词来查找结果。BERT 读取文本并理解其含义。相似的含义会得到相似的评分,因此你可以按概念而非精确词语进行搜索。通过将两者结合,它加速了逆向工程的主要瓶颈,同时发现存在漏洞的函数。

极致性能: 一个 50 MB 的二进制文件在 35 秒内加载完成。Ghidra 和 IDA Pro 可能需要数小时,因为它们会先将整个文件解析到数据库中,之后你才能进行任何操作。Ablation 只分析你正在积极处理的函数,因此你可以立即开始。

版本差异比对: 利用 Jaccard 方法衡量函数行为在不同版本之间的重叠程度,并使用动态时间规整(Dynamic Time Warping)追踪函数在厂商更新的固件或软件各版本中执行的“形态”,Ablation 能够确认补丁是否真正改变了逻辑,还是仅仅改变了打包方式,因为表面性的重新编译无法掩盖未修补的漏洞。

跨二进制分析: 同时分析固件镜像中的每个共享库,追踪跨二进制边界的数据流。

源代码审计: 以比线性阅读更快的速度审计任何大型代码库,且准确率高于单纯的模式匹配。每个源文件都会获得一个 5 位安全画像,精确决定它需要多少关注,因此不会有任何遗漏,也不会有任何内容被重复阅读。

Windows 内核驱动与 BYOVD 分析: 映射 IRP 调度表,解码每个 IOCTL 代码,并识别哪些内核 API 从用户态暴露物理内存和令牌原语。BYOVD 检测器会对携带这些能力的已签名驱动进行指纹识别,因为一个合法的已签名驱动就足以让 EDR 在 ring-0 层面失明。

Android / APK 分析: 在二进制层面读取 Android APK,无需任何依赖。它从编译后的字节码中映射原生代码入口点和 IPC 表面,因此无需反编译即可看到完整的攻击面。

Erlang / BEAM 分析: Erlang 编译为 .beam 文件,用于 ELF 的相同表面映射方法可直接适用,因此原子搜索、导入审计和混淆检测无需特殊处理。扫描一个发布目录只需几秒钟。

解密

  • 熵映射器: 查找二进制文件中的加密、压缩或加壳区段。
  • 密码学审计: 扫描密码学相关实现。
  • XorSolver: 恢复并解密目标区段,从而支持进一步的逆向工程。

实际成果

Ablation 已被用于分析来自 Fortinet、Cisco、Juniper、Axis、Fujitsu、MikroTik、Orka、TencentOS、Enigma2、Skydio 和 Dahua Security System 的生产固件和内核驱动。

在针对 Cisco FMC 和 ISE 进行协调披露之后,Cisco 产品安全事件响应团队(PSIRT)已采用 Ablation 进行内部漏洞分类。Cisco PSIRT 正在积极使用它对 Firepower Threat Defense(FTD)、Cisco Secure Client(AnyConnect)、HyperFlex 和 Catalyst 上正在进行的披露报告进行分类。Cisco Adaptive Security Appliance(ASA)LINA 也已使用 Ablation 进行逆向工程,相关发现目前正通过 CERT/CC VINCE 进行协调分类。


本地反编译器


LLM 兼容性

提供商模型
Claude Code/model claude-sonnet-4-6
OpenAI Codex所有已知模型

安装```bash

pip install git+https://github.com/Ablation-Tool/ablation

root@kitploit:~
---

## 环境要求

- Python >= 3.10
- `capstone`、`numpy`、`lief`、`sentence-transformers`、`pyelftools`
- 可选:`anthropic`,用于 LLM 功能

---

## 负责任的使用

Ablation 专为授权的安全研究而构建。请仅针对您拥有或已获得明确书面许可进行测试的系统使用它。未经授权对系统运行本工具,在大多数司法管辖区均违反计算机欺诈相关法律。作者不对任何滥用行为承担责任。

---

## 致谢
本项目在很大程度上受到若干重要文献著作的启发与影响。

**研究论文**

| 标题 | 作者 | 引用 |
|---|---|---|
| [Finding Taint-Style Vulnerabilities in Linux-based Embedded Firmware with SSE-based Alias Analysis](https://arxiv.org/abs/2109.12209) | Cheng, Zheng, Liu, Guan, Liu, Li, Zhu, Ye, Sun | [sse_slicer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/sse_slicer.py) · [arm64_global_tracker.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/arm64_global_tracker.py) |
| [iResolveX: Multi-Layered Indirect Call Resolution via Static Reasoning and Learning-Augmented Refinement](https://arxiv.org/abs/2601.17888) | Monika Santra, Bokai Zhang, Mark Lim, [Vishnu Asutosh Dasu](https://github.com/vdasu), Dongrui Zeng, [Gang Tan](https://github.com/gangtan) | [vtable_resolver.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/vtable_resolver.py) · [interproc_field_writer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/interproc_field_writer.py) · [arm64_global_tracker.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/arm64_global_tracker.py) |
| [Extracting Protocol Format as State Machine via Controlled Static Loop Analysis](https://arxiv.org/abs/2305.13483) | [Qingkai Shi](https://github.com/qingkaishi), Xiangzhe Xu, Xiangyu Zhang | [proto_fsm.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/proto_fsm.py) |
| [NEMETYL: Message Type Identification of Binary Network Protocols using Continuous Segment Similarity](https://arxiv.org/abs/2002.03391) | [Stephan Kleber](https://github.com/vs-uulm), Rens Wouter van der Heijden, [Frank Kargl](https://github.com/fkargl) | [proto_fsm.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/proto_fsm.py) |
| [Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice](https://dl.acm.org/doi/10.1145/2810103.2813707) | [David Adrian](https://github.com/dadrian), Karthikeyan Bhargavan, [Zakir Durumeric](https://github.com/zakird), Pierrick Gaudry, Matthew Green, [J. Alex Halderman](https://github.com/jhalderm), [Nadia Heninger](https://github.com/factorable), Drew Springall, Emmanuel Thomé, [Luke Valenta](https://github.com/lukevalenta) | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |
| [Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM in TLS](https://www.usenix.org/conference/woot16/workshop-program/presentation/bock) | [Hanno Böck](https://github.com/hannob), [Aaron Zauner](https://github.com/azet), Sean Devlin, [Juraj Somorovsky](https://github.com/jurajsomorovsky), [Philipp Jovanovic](https://github.com/Daeinar) | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |
| [Whitening Sentence Representations for Better Semantics and Faster Retrieval](https://arxiv.org/abs/2103.15316) | [Jianlin Su](https://github.com/bojone), [Jiarun Cao](https://github.com/jiaruncao), Weijie Liu, Yangyiwen Ou | [semantic_search.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/semantic_search.py) |
| [Constant Propagation with Conditional Branches](https://dl.acm.org/doi/abs/10.1145/103135.103136) | Mark N. Wegman, F. Kenneth Zadeck | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| [A Simple, Fast Dominance Algorithm](https://www.cs.princeton.edu/techreports/2005/737.pdf) | Cooper, Harvey, Kennedy | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| [libdft: Practical Dynamic Data Flow Tracking for Commodity Systems](https://dl.acm.org/doi/10.1145/2151024.2151042) | [Vasileios P. Kemerlis](https://github.com/vkemerlis), [Georgios Portokalidis](https://github.com/portokalidis), [Kangkook Jee](https://github.com/jikk), Angelos D. Keromytis | [taint_tracker_x86.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_x86.py) · [taint_tracker_arm32.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_arm32.py) |

**书籍** 由 [www.oreilly.com](https://www.oreilly.com) 提供 | [github.com/oreillymedia](https://github.com/oreillymedia)

| 标题 | 作者 | 引用 |
|---|---|---|
| The Art of Software Security Assessment | [Mark Dowd](https://github.com/mdowd79), John McDonald, [Justin Schuh](https://github.com/jschuh) | [heap_vuln_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/heap_vuln_scanner.py) · [format_string_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/format_string_scanner.py) · [ioctl_attack_surface.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/ioctl_attack_surface.py) |
| Practical Binary Analysis | [Dennis Andriesse](https://github.com/dennisaa) | [taint_tracker_x86.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/taint_tracker_x86.py) · [disasm_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/disasm_engine.py) |
| Practical Malware Analysis | Michael Sikorski, Andrew Honig | [pe_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/pe_parser.py) · [shellcode_utils.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/shellcode_utils.py) |
| Practical Reverse Engineering | Bruce Dang, Alexandre Gazet, [Elias Bachaalany](https://github.com/0xeb) | [pe_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/pe_analyzer.py) · [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) |
| Hacking: The Art of Exploitation (2e) | Jon Erickson | [platform_detect.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/platform_detect.py) |
| Learning Linux Binary Analysis | [Ryan O'Neill](https://github.com/elfmaster) | [elf_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/elf_parser.py) · [binary_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/binary_parser.py) |
| Windows Internals Part 1 & 2 | [Pavel Yosifovich](https://github.com/zodiacon), [Mark Russinovich](https://github.com/markrussinovich), David Solomon, [Alex Ionescu](https://github.com/ionescu007), [Andrea Allievi](https://github.com/AaLl86) | [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) · [ioctl_attack_surface.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/ioctl_attack_surface.py) |
| Rootkits: Subverting the Windows Kernel | Greg Hoglund, Jamie Butler | [kernel_driver_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/kernel_driver_analyzer.py) · [yara_generator.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/yara_generator.py) |
| Advanced Compiler Design and Implementation | Steven Muchnick | [dataflow_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/dataflow_engine.py) |
| Engineering a Compiler | Keith Cooper, Linda Torczon | [disasm_engine.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/disasm_engine.py) |
| Practical IoT Hacking | [Fotios Chantzis](https://github.com/ithilgore), Ioannis Stais, Paulino Calderon, Evangelos Deirmentzoglou, Beau Woods | [firmware_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/firmware_analyzer.py) |
| Inside the Android OS: Building, Customizing, Managing and Operating Android System Services | G. Blake Meike | [apk_parser.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/apk_parser.py) · [jni_bridge_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/jni_bridge_scanner.py) · [binder_scanner.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/analyzers/binder_scanner.py) |
| Malware Analysis and Detection Engineering | [Abhijit Mohanta](https://github.com/amohanta), Anoop Saldanha | [yara_generator.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/yara_generator.py) |
| Evasive Malware | [Kyle Cucci](https://github.com/d4rksystem) | [process_enum.py](https://github.com/Ablation-Tool/ablation/blob/main/modules/process_enum.py) |
| Hacking Cryptography | [Kamran Khan](https://github.com/krkhan), [Bill Cox](https://github.com/waywardgeek) | [tls_enum.py](https://github.com/Ablation-Tool/ablation/blob/main/modules/tls_enum.py) |
| Real-World Cryptography | David Wong | [tls_analyzer.py](https://github.com/Ablation-Tool/ablation/blob/main/ablation/core/tls_analyzer.py) |

**荣誉提名**

[Microsoft Excel(数据分析工具库)](https://support.microsoft.com/en-us/office/use-the-analysis-toolpak-to-perform-complex-data-analysis-6c67ccf0-f4a9-487c-8dec-bdb5a2cefab6) 在分析封闭基础设施或保护黑盒系统时,这一确切过程被称为时序分析或遥测逆向工程。在没有源代码的情况下,数据分析工具库通过严格观察应用程序的输入与输出,从数学上解构其后端的工作方式。

---

## 框架架构与模块编排```mermaid
flowchart TD
    Binary(["<b>Target Binary</b><br/><i>ELF · PE · firmware</i>"])
    Claude(["<b>Claude Code (Orchestrator)</b><br/><i>Central Agent Controller</i>"])

    Binary -->|"load"| BCtx["<b>BinaryContext</b><br/><i>PLT · Strings · Call Graph · XRefs</i>"]
    BCtx -->|"context"| Corpus["<b>Corpus Builder</b><br/><i>Semantic Embedding DB</i>"]
    BCtx -->|"context"| Taint["<b>Taint Engine</b><br/><i>Data Flow / Sinks</i>"]
    BCtx -->|"context"| Diffing["<b>Diffing Engine</b><br/><i>DTW / Version Delta</i>"]
    BCtx -->|"context"| FmtStr["<b>Format String</b><br/><i>Specifier Scanner</i>"]
    BCtx -->|"context"| Heap["<b>Heap Scanner</b><br/><i>Chunk / UAF Audit</i>"]
    BCtx -->|"context"| MultiArch["<b>Multi-Arch Engine</b><br/><i>MIPS · PPC · RISC-V · ARC · V850</i>"]
    BCtx -->|"context"| Driver["<b>Driver Engine</b><br/><i>Kernel IOCTL / BYOVD Audit</i>"]

    Corpus -->|"embeddings"| Semantic["<b>Semantic Search</b><br/><i>BERT Behavioral Fingerprints</i>"]

    Semantic -. "candidates" .-> Claude
    Taint -. "findings" .-> Claude
    Diffing -. "findings" .-> Claude
    FmtStr -. "findings" .-> Claude
    Heap -. "findings" .-> Claude
    MultiArch -. "findings" .-> Claude
    Driver -. "findings" .-> Claude

    Claude -->|"confirmed finding"| Registry["<b>Finding Registry</b><br/><i>Cross-Target Corpus</i>"]
    Registry -->|"seeds future sweeps"| Semantic

    classDef primary fill:#2a1a4a,stroke:#7c3aed,stroke-width:2px,color:#fff
    classDef foundation fill:#0d1117,stroke:#58a6ff,stroke-width:2px,color:#e5e7eb
    classDef engine fill:#171717,stroke:#404040,stroke-width:1px,color:#e5e7eb
    classDef feedback fill:#0d2818,stroke:#238636,stroke-width:2px,color:#e5e7eb

    class Claude,Binary primary
    class BCtx foundation
    class Corpus,Semantic,Taint,Diffing,FmtStr,Heap,MultiArch,Driver engine
    class Registry feedback

逆向工程工作流示例

对来自 RPM 捆绑包的 stripped 二进制文件进行端到端分析。从提取到 BinaryContext、字符串交叉引用,再到 capstone 反汇编,最终确认发现。```mermaid flowchart TD RPM["target-package.rpm
third-party bundle · x86-64"]

root@kitploit:~
RPM -->|rpm2cpio / cpio| EXTRACT["platform/linux-x86_64/"]

EXTRACT --> PI["bin/inference_engine<br/>stripped PIE · x86-64"]
EXTRACT --> CTRL["bin/controller<br/>stripped PIE · x86-64"]
EXTRACT --> LIBS["lib/libcore.so<br/>lib/libruntime.so"]

subgraph TRACK_PI ["inference engine track"]
    direction TB
    BCI["BinaryContext.load_or_build()<br/>32 func starts · 551 strings · PLT built"]
    BCI --> SS["ctx.strings scan<br/>api_op_read VA 0x51560<br/>api_op_write VA 0x51570<br/>license_key_flag 0x52e08"]
    SS --> XREF["ctx.string_xrefs()<br/>both ops xref → 0x17499, 0x174af<br/>ctx.func_containing() → init fn 0x10000"]
    XREF --> DA1["capstone disasm 0x17450<br/>lea rsi → api_op_read · call set::insert<br/>lea rsi → api_op_write · call set::insert<br/>CONFIRMED: exactly 2 blocklist entries"]
    DA1 --> DA2["capstone disasm 0x16511<br/>cmp qword ptr [r9], 0<br/>je → model loads · ne → handleFatal<br/>empty set = bypass confirmed"]
end

subgraph TRACK_LIBS ["library analysis"]
    direction TB
    NM["nm -D libcore.so<br/>spawn at 0xfdb20 · ctor at 0xfcfd0"]
    NM --> DA3["capstone disasm libcore.so:0xfdbc7<br/>cmp entry length == exe_path length<br/>memcmp at 0xfdbdb<br/>proper equality check · no prefix bypass"]
    LSCAN["re.findall api_op:: in libruntime.so<br/>2481 distinct ops found<br/>2 blocked · 2479 unblocked"]
end

subgraph TRACK_CTRL ["controller track"]
    direction TB
    BCC["BinaryContext.load_or_build()<br/>18 func starts · PLT · strings"]
    BCC --> XREF2["ctx.string_xrefs() on 5 path strings<br/>./worker1 · ./worker2<br/>./worker3 · ./worker4<br/>./inference_engine<br/>all xref at 0x9a04-0x9a5e"]
    XREF2 --> DA4["capstone disasm 0x99e9<br/>call CApp::progDir()<br/>call OsUtils::chdir()<br/>chdir to binary dir before spawn"]
    DA4 --> DA5["capstone disasm 0x11500<br/>args vector from command pipe tokens<br/>passed raw to spawn() at 0x11699<br/>no validation"]
end

PI --> BCI
PI --> BCC
LIBS --> NM
LIBS --> LSCAN

DA2 --> F1
LSCAN --> F1["F1 · HIGH<br/>blocklist covers 2 of 2481 ops<br/>upload malicious model via API<br/>seccomp BPF not decoded — CIA open"]

DA3 --> F2
XREF2 --> F2["F2 · LOW<br/>controller spawn allowlist is sound<br/>but args vector unchecked<br/>requires service user pipe access"]

DA5 --> F2

SS --> F3["F3 · INFO<br/>license gate = JSON field only<br/>no cryptographic verification"]

classDef finding fill:#1a1a2e,stroke:#e94560,stroke-width:2px,color:#fff
classDef tool fill:#16213e,stroke:#0f3460,stroke-width:1px,color:#e5e7eb
classDef binary fill:#0f3460,stroke:#533483,stroke-width:2px,color:#fff
classDef input fill:#533483,stroke:#7c3aed,stroke-width:2px,color:#fff

class F1,F2,F3 finding
class BCI,BCC,NM,LSCAN,SS,XREF,XREF2,DA1,DA2,DA3,DA4,DA5 tool
class PI,CTRL,LIBS binary
class RPM,EXTRACT input
root@kitploit:~
下载工具
CVE产品标题CVSS公告
CVE-2026-76420Secure Firewall Management Center (FMC)对等方身份冒充9.0 Criticalcisco-sa-fmc2-multivulns-HXgcqRG
CVE-2026-76412Secure Firewall Management Center (FMC)提权至 root8.5 Highcisco-sa-fmc2-multivulns-HXgcqRG
CVE-2026-76413Secure Firewall Management Center (FMC)单点登录令牌伪造8.5 Highcisco-sa-fmc2-multivulns-HXgcqRG
CVE-2026-76447Identity Services Engine (ISE)OCSP 响应器身份验证绕过5.3 Mediumcisco-sa-ise-multiauth-bypass-sgD2HbL4
架构变体
x86x86-32 · x86-64
ARMARM-32 · ARM-64
MIPSMIPS-32 · nanoMIPS · MIPS-64
PowerPCPPC-32 · PPC-64
RISC-VRISC-V 32 · RISC-V 64
EmbeddedARC EM/HS · V850-32