Profile
Back to NewsBack
GitHub Trending 12 min
Reader Mode
Ablation-Tool/ablation: Ablation is a fully autonomous reverse engineering tool

Ablation-Tool/ablation: Ablation is a fully autonomous reverse engineering tool

ABLATION

Ablation is a reverse engineering framework that provides the exact same core disassembly, decompilation, and binary analysis capabilities as industry-standard tools like Ghidra, IDA Pro, and Binary Ninja.

Combined with Claude Code or OpenAI Codex, it transforms into a fully autonomous reverse engineering tool.


!demo

Capabilities

Semantic Search via BERT: Searches code by concept instead of exact words. By mapping the actual meaning of the text, it cuts through the heaviest bottleneck of reverse engineering to help you pinpoint vulnerabilities faster.

Extreme Performance: Loads massive binaries in seconds rather than hours. By only analyzing the code you are actively looking at, it skips the heavy upfront processing of traditional tools so you can start reverse engineering immediately.

Version Diffing: Analyzes the actual behavior of updated software to verify vendor patches. It cuts through superficial repackaging to confirm if a vulnerability was genuinely fixed or just hidden.

FORGE: Ablation lets users build their own modules and add-ons. FORGE automatically audits that code before it gets stored, so every local module meets the same standard as the ones that ship with Ablation.

Windows Kernel Driver & BYOVD Analysis: Scans kernel drivers for risky entry points to stop attackers from using vulnerable, signed drivers to bypass your security software.

Android / APK Analysis: Maps out Android app attack surfaces without needing to decompile the code. It automatically scans and ranks internal libraries by security risk, allowing you to immediately target the most vulnerable components.

Erlang / BEAM Analysis: Safely scans Erlang bytecode to instantly highlight dangerous functions and hidden attack surfaces without running the application.

Inter-Binary Taint Analysis: Tracks the propagation of untrusted, user-controlled data across distinct, compiled executable files or binaries within a system (such as multi-binary firmware or cooperating processes) to detect vulnerabilities where data reaches sinks.

DAG Adapter Language: Decodes raw instruction bytes into a named-field bitfield layer before lifting them into a semantic operation graph. Every instruction form gets its own template with its own field positions, so a scanner reading the semantic layer gets the right register for every opcode without per-architecture exception cases. The resulting dataflow graph lets vulnerability detectors check producer-consumer relationships directly rather than walking backwards through raw bytes and guessing at basic block boundaries.

Cryptographic Analysis

Ablation strips away every layer that makes cryptography invisible in a compiled binary. Entropy Mapper locates the encrypted region. Crypto Audit and HashAlgoDiscriminator identify the algorithm. XorSolver, BmpKeyExtractor, and CustomCBCDetector break the encryption or recover the key. ELFVtableReconstructor and VtableDispatchScanner reconstruct what the runtime does with the result.

A binary can hide its crypto from import-table analysis, from symbol tables, and from string search. These eight tools collectively close that gap, so by the end you know the algorithm, the key, and the ciphertext.


Decompilers

| ISA / Runtime | Variants | |---|---| | x86 | x86-32 · x86-64 | | ARM | ARM-32 · ARM-64 | | MIPS | MIPS-32 · nanoMIPS · MIPS-64 | | PowerPC | PPC-32 · PPC-64 | | RISC-V | RISC-V 32 · RISC-V 64 | | ARC | ARC EM/HS | | V850 | V850-32 | | LoongArch | LoongArch64 | | DEX | Dalvik · ART | | ARK | ArkTS | | BEAM | Erlang · Elixir |


Real-World Results

Ablation has been used to analyze production firmware and kernel drivers from Fortinet, Cisco, Juniper, IBM, PlayStation 3, Apple macOS, Microsoft Windows, Axis Communications, HPE, Fujitsu, MikroTik, Orka by MacStadium, Acronis, TencentOS, Huawei, Enigma2, Skydio, Intel, NVIDIA, Dahua Security System, Tuya, and more.

Following coordinated disclosure on Cisco FMC and ISE, the Cisco Product Security Incident Response Team (PSIRT) has adopted Ablation for internal vulnerability triage. Cisco PSIRT is actively using it to triage ongoing disclosure reports across Firepower Threat Defense (FTD), Cisco Secure Client (AnyConnect), HyperFlex, and Catalyst. Cisco Adaptive Security Appliance (ASA) LINA has also been reverse engineered using Ablation, with findings currently under coordinated triage via CERT/CC VINCE.

| CVE | Product | Title | CVSS | Advisory | |---|---|---|---|---| | CVE-2026-76420 | Secure Firewall Management Center (FMC) | Peer Impersonation | 9.0 Critical | cisco-sa-fmc2-multivulns-HXgcqRG | | CVE-2026-76412 | Secure Firewall Management Center (FMC) | Privilege Escalation to root | 8.5 High | cisco-sa-fmc2-multivulns-HXgcqRG | | CVE-2026-76413 | Secure Firewall Management Center (FMC) | Single Sign-On Token Forgery | 8.5 High | cisco-sa-fmc2-multivulns-HXgcqRG | | CVE-2026-76447 | Identity Services Engine (ISE) | OCSP Responder Authentication Bypass | 5.3 Medium | cisco-sa-ise-multiauth-bypass-sgD2HbL4


Acknowledgments

This project was greatly informed and inspired by several key literary works.

Research Papers

| Title | Authors | |---|---| | Reverse Compilation Techniques · Specifying the Semantics of Machine Instructions · UQBT: Adaptable Binary Translation at Low Cost · Machine-Adaptable Dynamic Binary Translation | Dr. Cristina Cifuentes | | Design of a Retargetable Decompiler for a Static Platform-Independent Malware Analysis | Petr Zemek, Lukáš Ďurfina, Jakub Křoustek, Dušan Kolář, Tomas Hruska, Karel Masařík, Alexander Meduna | | Finding Taint-Style Vulnerabilities in Linux-based Embedded Firmware with SSE-based Alias Analysis | Cheng, Zheng, Liu, Guan, Liu, Li, Zhu, Ye, Sun | | iResolveX: Multi-Layered Indirect Call Resolution via Static Reasoning and Learning-Augmented Refinement | Monika Santra, Bokai Zhang, Mark Lim, Vishnu Asutosh Dasu, Dongrui Zeng, Gang Tan | | Extracting Protocol Format as State Machine via Controlled Static Loop Analysis | Qingkai Shi, Xiangzhe Xu, Xiangyu Zhang | | NEMETYL: Message Type Identification of Binary Network Protocols using Continuous Segment Similarity | Stephan Kleber, Rens Wouter van der Heijden, Frank Kargl | | Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice | David Adrian, Karthikeyan Bhargavan, Zakir Durumeric, Pierrick Gaudry, Matthew Green, J. Alex Halderman, Nadia Heninger, Drew Springall, Emmanuel Thomé, Luke Valenta | | Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM in TLS | Hanno Böck, Aaron Zauner, Sean Devlin, Juraj Somorovsky, Philipp Jovanovic | | Whitening Sentence Representations for Better Semantics and Faster Retrieval | Jianlin Su, Jiarun Cao, Weijie Liu, Yangyiwen Ou | | Constant Propagation with Conditional Branches | Mark N. Wegman, F. Kenneth Zadeck | | A Simple, Fast Dominance Algorithm | Cooper, Harvey, Kennedy | | libdft: Practical Dynamic Data Flow Tracking for Commodity Systems | Vasileios P. Kemerlis, Georgios Portokalidis, Kangkook Jee, Angelos D. Keromytis |

Books supplied by www.oreilly.com | github.com/oreillymedia

| Title | Authors | |---|---| | The Art of Software Security Assessment | Mark Dowd, John McDonald, Justin Schuh | | Practical Binary Analysis | Dennis Andriesse | | Practical Malware Analysis | Michael Sikorski, Andrew Honig | | Practical Reverse Engineering | Bruce Dang, Alexandre Gazet, Elias Bachaalany | | Hacking: The Art of Exploitation (2e) | Jon Erickson | | Learning Linux Binary Analysis | Ryan O'Neill | | Windows Internals Part 1 & 2 | Pavel Yosifovich, Mark Russinovich, David Solomon, Alex Ionescu, Andrea Allievi | | Rootkits: Subverting the Windows Kernel | Greg Hoglund, Jamie Butler | | Advanced Compiler Design and Implementation | Steven Muchnick | | Engineering a Compiler | Keith Cooper, Linda Torczon | | Practical IoT Hacking | Fotios Chantzis, Ioannis Stais, Paulino Calderon, Evangelos Deirmentzoglou, Beau Woods | | Inside the Android OS: Building, Customizing, Managing and Operating Android System Services | G. Blake Meike | | Malware Analysis and Detection Engineering | Abhijit Mohanta, Anoop Saldanha | | Evasive Malware | Kyle Cucci | | Hacking Cryptography | Kamran Khan, Bill Cox | | Real-World Cryptography | David Wong |

Honorable Mention

Microsoft Excel (Data Analysis ToolPak) When analyzing closed infrastructure or securing black-box systems, this exact process is called timing analysis or telemetry reverse engineering. Without source code, the Data Analysis ToolPak mathematically deconstructs how an application works on the backend by strictly observing its inputs and outputs.


Framework Architecture & Module Orchestration

flowchart TD
    Binary(["<b>Target Binary</b><br/><i>ELF · PE · firmware</i>"])
    Claude(["<b>Claude Code (Orchestrator)</b><br/><i>Central Agent Controller</i>"])

Binary -->|"load"| BCtx["<b>BinaryContext</b><br/><i>PLT · Strings · Call Graph · XRefs</i>"] BCtx -->|"context"| Corpus["<b>Corpus Builder</b><br/><i>Semantic Embedding DB</i>"] BCtx -->|"context"| Taint["<b>Taint Engine</b><br/><i>Data Flow / Sinks</i>"] BCtx -->|"context"| Diffing["<b>Diffing Engine</b><br/><i>DTW / Version Delta</i>"] BCtx -->|"context"| FmtStr["<b>Format String</b><br/><i>Specifier Scanner</i>"] BCtx -->|"context"| Heap["<b>Heap Scanner</b><br/><i>Chunk / UAF Audit</i>"] BCtx -->|"context"| MultiArch["<b>Multi-Arch Engine</b><br/><i>MIPS · PPC · RISC-V · ARC · V850 · LoongArch64</i>"] BCtx -->|"context"| Driver["<b>Driver Engine</b><br/><i>Kernel IOCTL / BYOVD Audit</i>"]

Corpus -->|"embeddings"| Semantic["<b>Semantic Search</b><br/><i>BERT Behavioral Fingerprints</i>"]

Semantic -. "candidates" .-> Claude Taint -. "findings" .-> Claude Diffing -. "findings" .-> Claude FmtStr -. "findings" .-> Claude Heap -. "findings" .-> Claude MultiArch -. "findings" .-> Claude Driver -. "findings" .-> Claude

Claude -->|"confirmed finding"| Registry["<b>Finding Registry</b><br/><i>Cross-Target Corpus</i>"] Registry -->|"seeds future sweeps"| Semantic

classDef primary fill:#2a1a4a,stroke:#7c3aed,stroke-width:2px,color:#fff classDef foundation fill:#0d1117,stroke:#58a6ff,stroke-width:2px,color:#e5e7eb classDef engine fill:#171717,stroke:#404040,stroke-width:1px,color:#e5e7eb classDef feedback fill:#0d2818,stroke:#238636,stroke-width:2px,color:#e5e7eb

class Claude,Binary primary class BCtx foundation class Corpus,Semantic,Taint,Diffing,FmtStr,Heap,MultiArch,Driver engine class Registry feedback


Example RE Workflow

End-to-end analysis of stripped binaries from an RPM bundle. Extraction through BinaryContext, string xrefs, and capstone disassembly to confirmed findings.

flowchart TD
    RPM["target-package.rpm<br/>third-party bundle · x86-64"]

RPM -->|rpm2cpio / cpio| EXTRACT["platform/linux-x86_64/"]

EXTRACT --> PI["bin/inference_engine<br/>stripped PIE · x86-64"] EXTRACT --> CTRL["bin/controller<br/>stripped PIE · x86-64"] EXTRACT --> LIBS["lib/libcore.so<br/>lib/libruntime.so"]

subgraph TRACK_PI ["inference engine track"] direction TB BCI["BinaryContext.load_or_build()<br/>32 func starts · 551 strings · PLT built"] BCI --> SS["ctx.strings scan<br/>api_op_read VA 0x51560<br/>api_op_write VA 0x51570<br/>license_key_flag 0x52e08"] SS --> XREF["ctx.string_xrefs()<br/>both ops xref → 0x17499, 0x174af<br/>ctx.func_containing() → init fn 0x10000"] XREF --> DA1["capstone disasm 0x17450<br/>lea rsi → api_op_read · call set::insert<br/>lea rsi → api_op_write · call set::insert<br/>CONFIRMED: exactly 2 blocklist entries"] DA1 --> DA2["capstone disasm 0x16511<br/>cmp qword ptr [r9], 0<br/>je → model loads · ne → handleFatal<br/>empty set = bypass confirmed"] end

subgraph TRACK_LIBS ["library analysis"] direction TB NM["nm -D libcore.so<br/>spawn at 0xfdb20 · ctor at 0xfcfd0"] NM --> DA3["capstone disasm libcore.so:0xfdbc7<br/>cmp entry length == exe_path length<br/>memcmp at 0xfdbdb<br/>proper equality check · no prefix bypass"] LSCAN["re.findall api_op:: in libruntime.so<br/>2481 distinct ops found<br/>2 blocked · 2479 unblocked"] end

subgraph TRACK_CTRL ["controller track"] direction TB BCC["BinaryContext.load_or_build()<br/>18 func starts · PLT · strings"] BCC --> XREF2["ctx.string_xrefs() on 5 path strings<br/>./worker1 · ./worker2<br/>./worker3 · ./worker4<br/>./inference_engine<br/>all xref at 0x9a04-0x9a5e"] XREF2 --> DA4["capstone disasm 0x99e9<br/>call CApp::progDir()<br/>call OsUtils::chdir()<br/>chdir to binary dir before spawn"] DA4 --> DA5["capstone disasm 0x11500<br/>args vector from command pipe tokens<br/>passed raw to spawn() at 0x11699<br/>no validation"] end

PI --> BCI PI --> BCC LIBS --> NM LIBS --> LSCAN

DA2 --> F1 LSCAN --> F1["F1 · HIGH<br/>blocklist covers 2 of 2481 ops<br/>upload malicious model via API<br/>seccomp BPF not decoded — CIA open"]

DA3 --> F2 XREF2 --> F2["F2 · LOW<br/>controller spawn allowlist is sound<br/>but args vector unchecked<br/>requires service user pipe access"]

DA5 --> F2

SS --> F3["F3 · INFO<br/>license gate = JSON field only<br/>no cryptographic verification"]

classDef finding fill:#1a1a2e,stroke:#e94560,stroke-width:2px,color:#fff classDef tool fill:#16213e,stroke:#0f3460,stroke-width:1px,color:#e5e7eb classDef binary fill:#0f3460,stroke:#533483,stroke-width:2px,color:#fff classDef input fill:#533483,stroke:#7c3aed,stroke-width:2px,color:#fff

class F1,F2,F3 finding class BCI,BCC,NM,LSCAN,SS,XREF,XREF2,DA1,DA2,DA3,DA4,DA5 tool class PI,CTRL,LIBS binary class RPM,EXTRACT input

LLM Compatibility

| Provider | Models | |---|---| | Claude Code | /model claude-sonnet-4-6 | | OpenAI Codex | All models |


Install

pip install git+https://github.com/Ablation-Tool/ablation

Requirements

  • Python >= 3.10
  • capstone, numpy, lief, sentence-transformers, pyelftools

Responsible Use

Ablation is built for authorized security research. Use it only against systems you own or have explicit written permission to test. Running it against systems without authorization violates computer fraud laws in most jurisdictions. The authors are not responsible for misuse.

Chat with me