vibe coders, script kiddies, unemployed rappers, tiktok dancers, and amphetamine dabblers.
a reverse engineering tool for the unwashed.
https://t.co/Qq3T5lgPoU
@JustLingonberry@MatthewBerman im working on some documentation shit right now. and reverse engineering some other stuff, so its continuously adding more modules and analyzers and improving on the tool
A new open-source project brings Metal support for NVIDIA GeForce RTX graphics cards to macOS 15 on Intel Macs and OpenCore systems.
It supports Metal 3 features including ray tracing, along with OpenGL, OpenCL and Core ML. It builds on NVIDIA's open GPU kernel modules and the Mesa NVK Vulkan driver.
It does not support Apple Silicon Macs or CUDA. The developer has only tested an RTX 5060 and warns it may not work on every system.
Repo: https://t.co/tfkUqNbvZW
Ablation is a reverse engineering framework.
It carries no dependency on legacy tools like Ghidra, IDA Pro, Binary Ninja, or any MCP server.
Combined with any coding agent, it runs as an autonomous reverse engineering tool.
Ablation also does this.
Layer 1: Fortinet firmware has two encryption layers and most tools only get through the first
Standard tools like binwalk, file, and 7z can detect the outer gzip wrapper on a .out file but fail at what is inside. The inner binary is XOR-encrypted with a 64-byte repeating key. Binwalk has no automated XOR key recovery, so it calls the inner data "data." Ablation's XorSolver exploits a property that generic tools don't know about: NAND flash memory erases to 0xFF, so the plaintext is roughly 80 to 86 percent null bytes. That byte-frequency bias creates an Index of Coincidence spike at shift=64 that is 192 to 244 times above random baseline, which is unambiguous key-length signal from a 4KB sample. FortiOSHardwareExtractor wraps this into a single call that goes from raw .out to decrypted NAND image.
Hardware appliances have a second layer on top of that. The inner gzip partitions are RC4-encrypted. The FAC_400E work today confirmed that the gzip FLG reserved bits, values like 0xdd and 0x9b, are Fortinet's RC4-in-progress markers and not corrupt data. FirmwareContainerKeyExtractor scans the decrypted outer image for PKCS#1 v1.5 blocks that carry the RC4 key and decrypts each partition with it. Generic tools see the gzip magic bytes, report invalid compression, and stop because they have no concept of a per-partition secondary cipher.
---
Layer 2: The known-key corpus makes "already seen this" instant
Fortinet ships the same private key files unchanged across entire product families for years. Ablation's FortiGateCertKeyScanner maintains a KNOWN_KEY_FAMILIES table, now at 6 entries
including the FortiAP MIPS key added this session. For any new Fortinet firmwar an immediate verdict: known CRITICAL, known HIGH, or an unknown MD5 that isitself a finding candidate.
Without the table, you extract a key, compute an MD5, and have no context. With it, you know that 1158fa1e is the same 512-bit RSA key shared across FortiGate, FortiFirewall, FortiWiFi,
and FortiExtender, and you know what attack paths that opens. FortiBuildTrackCly reading the M-build vs F-build suffix in the filename and predicting how manykeys the image should contain before you touch it. An unexpected count is flagged as anomalous.
---
Layer 3: Semantic sweep across the binary, not pattern matching
Most vulnerability scanners are static string matchers that grep for system( and strcpy, or they are dynamic fuzzers. Ablation's semantic sweep is different. It lifts functions to an
intermediate representation, traces taint from user-controlled inputs to dangers candidates by a composite score built from opcode density, xref depth,argument structure, and known-bad patterns. A 885-function binary returns a ranked shortlist in 35 seconds.
This matters for Fortinet because many sink calls are PLT-wrapped and not directly visible as call system@plt in the obvious pattern. SinkArgClassifier resolves PLT stubs to identify thtrue sink. ARM32 and ARM64 have different PLT calling conventions, so the same t works on x86-64 fails silently on ARM without architecture-aware resolvers.Ablation has those resolvers because the FortiExtender 40D ARM32 analysis in session 8 surfaced the gap and it became a module fix the same day. CppVtableReconstructorAnalyzer resolves virtual dispatch chains that would otherwise appear as opaque register-indirectbler.
Ghidra and IDA give you an annotated disassembly of 885 functions with no prior 5 to 10 confirmed taint paths worth manual time. Session 10's FortiWebFWB-FABRIC-1, a pre-auth SQL injection and path traversal through an unsanitized Bearer token, came from this ranking. The semantic sweep put the handler in the top candidates and a manual capstone trace confirmed it.
Ablation does this as well:
Go Binary Reverse Engineering
Recovers function names and string literals from stripped and obfuscated Go binaries. Most tools fail on Go because stripped Go binaries lack traditional symbols, and obfuscated Go deliberately scrambles the names and constants that remain. Ablation reads the Go runtime metadata table to recover function boundaries, and separately handles the garble obfuscator, which is designed specifically to defeat this. The result is a named, navigable binary instead of an opaque address space.
go_garble_re.py recovers names from garbled Go binaries — Go code obfuscated with garble, which scrambles symbol names, string literals, and control flow. go_pclntab.py reconstructs function boundaries from Go's pclntab table in stripped binaries. Combined with go_string_resolver.py, this handles modern Go malware and Go-based firmware that every other tool gives up on.
vibe coders, script kiddies, unemployed rappers, tiktok dancers, and amphetamine dabblers.
a reverse engineering tool for the unwashed.
https://t.co/Qq3T5lgPoU
Confirmed findings from one target automatically seed semantic searches on future targets. Every CVE you confirm becomes a behavioral fingerprint that Ablation uses to find the same class of bug in the next binary it sees. No other RE tool does this. Ghidra/IDA are session-scoped — they forget everything when you close the project. This is architectural.
proto_fsm.py extracts protocol finite state machines from binary code.
This is research-level — it's what you'd need to fuzz a proprietary protocol or map authentication bypass windows. It's cited in the acknowledgments (the NEMETYL paper) but isn't described as a capability.
hisi_rv32_ext.py handles 6 custom opcode spaces plus 2 16-bit extensions for the HiSilicon WS63/Hi3863/BS21 SoC. This isn't "ISA coverage" in the generic sense — it's knowledge of what a specific chip vendor added on top of RISC-V that breaks every other decoder. The WS63 target produced 13 confirmed firmware findings. There's no other tool that handles this.
spu_disassembler.py is the only open-source Cell BE SPU disassembler that isn't tied to an ancient IDA plugin.
The PS3 security research (GoldenEye target in the active RE list) is only possible because of this.