Fuzzing: Brute Force Vulnerability Discovery
by Michael Sutton, Adam Greene, Pedram Amini.
A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Development like root cause analysis.
This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.
by Michael Sutton, Adam Greene, Pedram Amini.
by Ari Takanen, Charles Miller, Jared D Demott and Atte Kettunen.
by by Gadi Evron and Noam Rathaus.
by Justin Seitz.
by Andreas Zeller, Rahul Gopinath, Marcel Böhme, Gordon Fraser, and Christian Holler.
by Chris Anley, Dave Aitel, David Litchfield and others.
Charles Miller, Dino DaiZovi, Dion Blazakis, Ralf-Philip Weinmann, and Stefan Esser.
Made available freely by Dan Guido.
by W. Owen Redwood and Prof. Xiuwen Liu.
Training from BackTrack/Kali developers.
Made available freely by Dan Guido.
by Mike Zusman.
by Mike Zusman.
by University of Maryland.
Pocs for Antivirus Software‘s Kernel Vulnerabilities
Lots of good content in these videos.
by Atte Kettunen
by Brandon Falk
Mateusz “j00ru” Jurczyk @ Black Hat Europe 2016, London
Amazing article by Google's Project Zero, describing what it takes to do fuzzing and create fuzzers.
Amazing article by Google's Project Zero, describing what it takes to do fuzzing and create fuzzers.
by fuzzing-project.org.
by @BrandonPrry.
by folks at MWR Security.
by fuzzing.info
by Corelan Team.
by Corelan Team.
by Open Security Research
by Emily Ratliff.
by Harold Rodriguez(@superkojiman).
by Jason Kratzer of corelan team
by Jason Kratzer of corelan team.
by Frédéric Guihéry, Georges Bossert.
by @toasted_flakes
by Jonathan Foote
Tutorials, examples, discussions, research proposals, and other resources related to fuzzing (archived)
Repository for materials of "Modern fuzzing of C/C++ Projects" workshop.
by samclass.info
by Samclass.info
Getting Started with Z3: A Guide
by @fady_othman
Cloud fuzzing framework which makes it possible to easily run automated fuzz-testing in cloud environments.
ClusterFuzzer, scalable open source fuzzing infrastructure. It is used by Google for fuzzing Chrome Browser.
Fuzzit, Continuous fuzzing as a service platform. Free for open source. used by various open-source projects (systemd, radare2) and close-source projects. To join oss program drop a line at [email protected]
Binary, coverage-guided fuzzer for Windows, macOS, Linux and Android
Basic file format fuzzing tool by Microsoft. (No longer available on Microsoft website).
Basic Fuzzing Framework for file formats.
American Fuzzy Lop Fuzzer by Michal Zalewski aka lcamtuf
A Python interface to AFL, allowing for easy injection of testcases and other functionality.
A modified version of AFL that supports fuzzing for applications whose source code not available.
Directed Greybox Fuzzing with AFL, to fuzz targeted locations of a program.
Framework which helps to create custom dumb and smart fuzzers.
A fork of peach 2.7 by Mozilla Security.
mutational file-based fuzz testing tool for windows applications.
mutation based file fuzzer that uses PyDBG to monitor for signals of interest.
A general-purpose, easy-to-use fuzzer with interesting analysis options. Supports feedback-driven fuzzing based on code coverage. Supports GNU/Linux, FreeBSD, Mac OSX and Android.
A transparent application input fuzzer. It works by intercepting file operations and changing random bits in the program's input.
A general purpose fuzzer and test case generator.
A binary format analysis and fuzzing tool
Fuzzing tool for file formats based on ANTLR v4 grammars (lots of grammars already available from the ANTLR project).
Sloth 🦥 is a coverage guided fuzzing framework for fuzzing Android Native libraries that makes use of libFuzzer and QEMU user-mode emulation.
Binary code-coverage fuzzer for macOS, based on libFuzzer and LLVM.
Framework which helps to create custom dumb and smart fuzzers.
A fuzzer development and fuzz testing framework consisting of multiple extensible components by Pedram Amini.
A fork and successor of Sulley framework.
A fuzzer development framework like sulley, a predecessor of sulley.
A framework which contains some fuzzing capabilities via Auxiliary modules.
A distributed fuzzing testing suite with web administration, supports fuzzing using network protocols.
A dumb protocol-unaware packet fuzzer/replayer.
A simple network fuzzer supporting TCP, UDP and multithreading.
The Mutiny Fuzzing Framework is a network fuzzer that operates by replaying PCAPs through a mutational fuzzer.
A fuzzing framework for network servers.
An unofficial american fuzzy lop capable of network fuzzing.
A Greybox Fuzzer for Network Protocols (an extention of AFL).
Protocol Learning, Simulation and Stateful Fuzzer.
An input based, browser fuzzing framework. Fuzzinator - Fuzzinator Random Testing Framework Grizzly - A cross-platform browser fuzzing framework
An evolutionary knowledge-based fuzzer
A tool written in Haskell designed for testing un-expected inputs of common file formats on third-party software, taking advantage of off-the-shelf, well known fuzzers.
A grammar-based fuzzer that lets one define complex grammars to model text and binary data formats
Cross Platform Kernel Fuzzer Framework.
A general-purpose, easy-to-use fuzzer with interesting analysis options.
Yet Another general purpose fuzzer.
In-process, coverage-guided, evolutionary fuzzing engine for targets written in C/C++.
An advanced cross platform fuzzing framework designed to find vulnerabilities in C/C++ code.
Easy-to-use, coverage-guided JVM fuzzing framework.
Automated Large-Scale Fuzzing Framework
A coverage-guided, in-process fuzzer for the Java Virtual Machine based on libFuzzer.
A command line tool for executing coverage-guided fuzz tests in multiple languages and targets.
WebGL Fuzzer
A fuzzer tool written in TypeScript and designed to run un-expected inputs against JavaScript code.
Platform for Architecture-Neutral Dynamic Analysis.
Tool to perform advanced logging of memory references performed by operating systems’ kernels
A software security framework containing tools for vulnerability, discovery, and triage.
A theorem prover from Microsoft Research.
An international initiative aimed at facilitating research and development in Satisfiability Modulo Theories (SMT)
A set of four instructional videos introducing KLEE, starting with how to get started with KLEE and ending with a demo that finds memory corruption bugs in real code.
The preferred debugger by exploit writers.
Immunity Debugger by Immunity Sec.
Awesome tools that makes life easy for exploit developers.
An open-source x64/x32 debugger for windows.
Front end for gdb.
The favorite linux debugger.
Framework for reverse-engineering and analyzing binaries.
The best disassembler
Binary analysis IDE, annotates control flow graphs and call graphs of disassembled code.
Capstone is a lightweight multi-platform, multi-architecture disassembly framework.
Intercepts library calls
Intercepts system calls
(search and pick the exploits, which have respective apps available for download, reproduce the exploit by using fuzzer of your choice)
Vulnerable C program for testing fuzzers.
A vulnerable server for testing fuzzers.
PDF Reader in JavaScript.
Set of tests for fuzzing engines. Includes different well-known bugs such as Heartbleed, c-ares $100K bug and others.
A corpus, including various file formats for fuzzing multiple targets in the fuzzing literature.
VoltAgent/awesome-openclaw-skills
The awesome collection of OpenClaw skills. 5,400+ skills filtered and categorized from the official OpenClaw Skills Registry.🦞
awesome-dsh-plugin/awesome-dsh-plugin
A curated list of plugins for DeepSeek Harness (dsh) · DeepSeek Harness 插件精选列表
Kristories/awesome-guidelines
Programming style, best practices, and coding conventions.
sindresorhus/awesome
😎 Awesome lists about all kinds of interesting topics [NOTE: Pull requests are temporarily disabled until I have a chance to catch up with the existing ones]
ai-boost/awesome-prompts
Curated list of chatgpt prompts from the top-rated GPTs in the GPTs Store. Prompt Engineering, prompt attack & prompt protect. Advanced Prompt Engineering papers.
matiassingers/awesome-readme
A curated list of awesome READMEs