Skip to content
55

Welcome to Awesome Fuzzing

A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Development like root cause analysis.

5.9k stars840 forks167 entriesLast push Apr 3, 2024 (2 years ago)License CC0-1.0

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Books

Fuzzing: Brute Force Vulnerability Discovery

by Michael Sutton, Adam Greene, Pedram Amini.

In 2 lists

Fuzzing for Software Security Testing and Quality Assurance

by Ari Takanen, Charles Miller, Jared D Demott and Atte Kettunen.

In 2 lists

Open Source Fuzzing Tools

by by Gadi Evron and Noam Rathaus.

In 2 lists

Gray Hat Python

by Justin Seitz.

The Fuzzing Book

by Andreas Zeller, Rahul Gopinath, Marcel Böhme, Gordon Fraser, and Christian Holler.

In 3 lists

The Shellcoder's Handbook: Discovering and Exploiting Security Holes ( Chapter 15 )

by Chris Anley, Dave Aitel, David Litchfield and others.

In 2 lists

iOS Hacker's Handbook - Chapter 1

Charles Miller, Dino DaiZovi, Dion Blazakis, Ralf-Philip Weinmann, and Stefan Esser.

In 2 lists

IDA Pro - The IDA Pro Book: The Unofficial Guide to the World's Most Popular Disassembler

Courses >Free

NYU Poly ( see videos for more )

Made available freely by Dan Guido.

Samclass.info ( check projects section and chapter 17 )

by Sam.

Modern Binary Exploitation ( RPISEC ) - Chapter 15

by RPISEC.

In 6 listsDetails

Offensive Computer Security - Week 6

by W. Owen Redwood and Prof. Xiuwen Liu.

Courses >Paid

Offensive Security, Cracking The Perimeter ( CTP ) and Advanced Windows Exploitation ( AWE )

Training from BackTrack/Kali developers.

In 2 lists

SANS 660/760 Advanced Exploit Development for Penetration Testers

Exodus Intelligence - Vulnerability development master class

Ada Logics - Applied Source Code Fuzzing

FuzzingLabs Academy (C/C++, Rust, Go fuzzing)

Signal Labs - Vulnerability Research & Fuzzing

Videos >NYU Poly Course videos

NYU Poly ( see videos for more )

Made available freely by Dan Guido.

Fuzzing 101 (Part 2)

by Mike Zusman.

Fuzzing 101 (2009)

by Mike Zusman.

Fuzzing - Software Security Course on Coursera

by University of Maryland.

Videos >Conference talks and tutorials

Attacking Antivirus Software's Kernel Driver

Pocs for Antivirus Software‘s Kernel Vulnerabilities

In 2 lists

Fuzzing the Windows Kernel - OffensiveCon 2020

Youtube Playlist of various fuzzing talks and presentations

Lots of good content in these videos.

Browser bug hunting - Memoirs of a last man standing

by Atte Kettunen

In 2 lists

Coverage-based Greybox Fuzzing as Markov Chain

DerbyCon 2016: Fuzzing basics...or how to break software

Fuzz Theory

by Brandon Falk

Tutorials and Blogs

ARMored CoreSight: Towards Efficient Binary-only Fuzzing

Fuzzing Microsoft's RDP Client using Virtual Channels: Overview & Methodology

Fuzzing Closed Source PDF Viewers

Fuzzing Image Parsing in Windows, Part One: Color Profiles

Fuzzing Image Parsing in Windows, Part Two: Uninitialized Memory

Fuzzing Image Parsing in Windows, Part Three: RAW and HEIF

Fuzzing the Office Ecosystem

Effective File Format Fuzzing

Mateusz “j00ru” Jurczyk @ Black Hat Europe 2016, London

A year of Windows kernel font fuzzing Part-1 the results

Amazing article by Google's Project Zero, describing what it takes to do fuzzing and create fuzzers.

A year of Windows kernel font fuzzing Part-2 the techniques

Amazing article by Google's Project Zero, describing what it takes to do fuzzing and create fuzzers.

Interesting bugs and resources at fuzzing project

by fuzzing-project.org.

Fuzzing workflows; a fuzz job from start to finish

by @BrandonPrry.

A gentle introduction to fuzzing C++ code with AFL and libFuzzer

by Jeff Trull.

A 15 minute introduction to fuzzing

by folks at MWR Security.

Fuzzing Blogs and Books

by fuzzing.info

Root Cause Analysis of the Crash during Fuzzing

by Corelan Team.

Root cause analysis of integer flow

by Corelan Team.

In 2 lists

Creating custom peach fuzzer publishers

by Open Security Research

7 Things to Consider Before Fuzzing a Large Open Source Project

by Emily Ratliff.

From fuzzing to 0-day

by Harold Rodriguez(@superkojiman).

Peach Fuzzer Introductionh

Fuzzing with Peach Part 1

by Jason Kratzer of corelan team

Fuzzing with Peach Part 2

by Jason Kratzer of corelan team.

Auto generation of Peach pit files/fuzzers

by Frédéric Guihéry, Georges Bossert.

Creating a fuzzing harness for FoxitReader 9.7 ConvertToPDF Function

50 CVEs in 50 Days: Fuzzing Adobe Reader

Fuzzing sockets, part 1: FTP servers

Fuzzing software: common challenges and potential solutions (Part 1)

Fuzzing software: advanced tricks (Part 2)

Fuzzing capstone using AFL persistent mode

by @toasted_flakes

RAM disks and saving your SSD from AFL Fuzzing

Bug Hunting with American Fuzzy Lop

Advanced usage of American Fuzzy Lop with real world examples

Segfaulting Python with afl-fuzz

Fuzzing With AFL-Fuzz, a Practical Example ( AFL vs Binutils )

The Importance of Fuzzing...Emulators?

How Heartbleed could've been found

Filesystem Fuzzing with American Fuzzy lop

Fuzzing Perl/XS modules with AFL

How to fuzz a server with American Fuzzy Lop

by Jonathan Foote

Fuzzing with AFL Workshop - a set of challenges on real vulnerabilities

Fuzzing 101 - PHDays

libFuzzer Tutorial

Tutorials, examples, discussions, research proposals, and other resources related to fuzzing (archived)

In 2 lists

Hunting for bugs in VirtualBox (First Take)

libFuzzer Workshop: "Modern fuzzing of C/C++ Projects"

Repository for materials of "Modern fuzzing of C/C++ Projects" workshop.

In 3 lists

Fuzzing ImageIO

Double-Free RCE in VLC. A honggfuzz how-to

Fuzzing with Spike to find overflows

Fuzzing with Spike

by samclass.info

Fuzzing with FOE

by Samclass.info

Z3 - A guide

Getting Started with Z3: A Guide

Building A Feedback Fuzzer

by @fady_othman

Tools >Cloud Fuzzers

Cloudfuzzer

Cloud fuzzing framework which makes it possible to easily run automated fuzz-testing in cloud environments.

ClusterFuzzer

ClusterFuzzer, scalable open source fuzzing infrastructure. It is used by Google for fuzzing Chrome Browser.

Fuzzit

Fuzzit, Continuous fuzzing as a service platform. Free for open source. used by various open-source projects (systemd, radare2) and close-source projects. To join oss program drop a line at oss@fuzzit.dev

Tools >File Format Fuzzers

Jackalope

Binary, coverage-guided fuzzer for Windows, macOS, Linux and Android

In 2 lists

Rehepapp

pe-afl combines static binary instrumentation on PE binary and WinAFL

MiniFuzz - Wayback Machine link

Basic file format fuzzing tool by Microsoft. (No longer available on Microsoft website).

BFF from CERT

Basic Fuzzing Framework for file formats.

AFL Fuzzer (Linux only)

American Fuzzy Lop Fuzzer by Michal Zalewski aka lcamtuf

Win AFL

A fork of AFL for fuzzing Windows binaries

In 4 listsDetails

Shellphish Fuzzer

A Python interface to AFL, allowing for easy injection of testcases and other functionality.

TriforceAFL

A modified version of AFL that supports fuzzing for applications whose source code not available.

AFLGo

Directed Greybox Fuzzing with AFL, to fuzz targeted locations of a program.

In 2 lists

Peach Fuzzer

Framework which helps to create custom dumb and smart fuzzers.

MozPeach

A fork of peach 2.7 by Mozilla Security.

Failure Observation Engine (FOE)

mutational file-based fuzz testing tool for windows applications.

rmadair

mutation based file fuzzer that uses PyDBG to monitor for signals of interest.

honggfuzz

A general-purpose, easy-to-use fuzzer with interesting analysis options. Supports feedback-driven fuzzing based on code coverage. Supports GNU/Linux, FreeBSD, Mac OSX and Android.

In 4 listsDetails

zzuf

A transparent application input fuzzer. It works by intercepting file operations and changing random bits in the program's input.

radamsa

A general purpose fuzzer and test case generator.

binspector

A binary format analysis and fuzzing tool

In 2 lists

grammarinator

Fuzzing tool for file formats based on ANTLR v4 grammars (lots of grammars already available from the ANTLR project).

Sloth

Sloth 🦥 is a coverage guided fuzzing framework for fuzzing Android Native libraries that makes use of libFuzzer and QEMU user-mode emulation.

ManuFuzzer

Binary code-coverage fuzzer for macOS, based on libFuzzer and LLVM.

Tools >Network Protocol Fuzzers

Peach Fuzzer

Framework which helps to create custom dumb and smart fuzzers.

Sulley

A fuzzer development and fuzz testing framework consisting of multiple extensible components by Pedram Amini.

boofuzz

A fork and successor of Sulley framework.

In 4 lists

Spike

A fuzzer development framework like sulley, a predecessor of sulley.

In 2 lists

Metasploit Framework

A framework which contains some fuzzing capabilities via Auxiliary modules.

In 7 listsDetails

Nightmare

A distributed fuzzing testing suite with web administration, supports fuzzing using network protocols.

rage_fuzzer

A dumb protocol-unaware packet fuzzer/replayer.

Fuzzotron

A simple network fuzzer supporting TCP, UDP and multithreading.

Mutiny

The Mutiny Fuzzing Framework is a network fuzzer that operates by replaying PCAPs through a mutational fuzzer.

Fuzzing For Worms

A fuzzing framework for network servers.

AFL (w/ networking patch)

An unofficial american fuzzy lop capable of network fuzzing.

AFLNet

A Greybox Fuzzer for Network Protocols (an extention of AFL).

Pulsar

Protocol Learning, Simulation and Stateful Fuzzer.

Tools >Browser Fuzzing

BFuzz

An input based, browser fuzzing framework. Fuzzinator - Fuzzinator Random Testing Framework Grizzly - A cross-platform browser fuzzing framework

Tools >Misc

Choronzon

An evolutionary knowledge-based fuzzer

In 2 lists

QuickFuzz

A tool written in Haskell designed for testing un-expected inputs of common file formats on third-party software, taking advantage of off-the-shelf, well known fuzzers.

gramfuzz

A grammar-based fuzzer that lets one define complex grammars to model text and binary data formats

KernelFuzzer

Cross Platform Kernel Fuzzer Framework.

honggfuzz

A general-purpose, easy-to-use fuzzer with interesting analysis options.

Hodor Fuzzer

Yet Another general purpose fuzzer.

libFuzzer

In-process, coverage-guided, evolutionary fuzzing engine for targets written in C/C++.

syzkaller

Distributed, unsupervised, coverage-guided Linux syscall fuzzer.

In 6 listsDetails

ansvif

An advanced cross platform fuzzing framework designed to find vulnerabilities in C/C++ code.

In 2 lists

Tribble

Easy-to-use, coverage-guided JVM fuzzing framework.

go-fuzz

Coverage-guided testing of go packages.

In 6 listsDetails

FExM

Automated Large-Scale Fuzzing Framework

Jazzer

A coverage-guided, in-process fuzzer for the Java Virtual Machine based on libFuzzer.

cifuzz

A command line tool for executing coverage-guided fuzz tests in multiple languages and targets.

WebGL Fuzzer

WebGL Fuzzer

fast-check

A fuzzer tool written in TypeScript and designed to run un-expected inputs against JavaScript code.

Tools >Taint Analysis

PANDA ( Platform for Architecture-Neutral Dynamic Analysis )

Platform for Architecture-Neutral Dynamic Analysis.

In 2 lists

QIRA (QEMU Interactive Runtime Analyser)

kfetch-toolkit

Tool to perform advanced logging of memory references performed by operating systems’ kernels

moflow

A software security framework containing tools for vulnerability, discovery, and triage.

Tools >Symbolic Execution SAT and SMT Solvers

Z3

A theorem prover from Microsoft Research.

In 3 lists

SMT-LIB

An international initiative aimed at facilitating research and development in Satisfiability Modulo Theories (SMT)

Symbolic execution with KLEE: From installation and introduction to bug-finding in open source software

A set of four instructional videos introducing KLEE, starting with how to get started with KLEE and ending with a demo that finds memory corruption bugs in real code.

Tools >References

I haven't included some of the legends like AxMan, please refer the following link for more information.

Tools >Essential Tools

Windbg

The preferred debugger by exploit writers.

In 2 lists

Immunity Debugger

Immunity Debugger by Immunity Sec.

In 2 lists

OllyDbg

The debugger of choice by reverse engineers and exploit writers alike.

In 5 listsDetails

Mona.py ( Plugin for windbg and Immunity dbg )

Awesome tools that makes life easy for exploit developers.

x64dbg

An open-source x64/x32 debugger for windows.

In 2 lists

Evan's Debugger (EDB)

Front end for gdb.

In 3 lists

GDB - Gnu Debugger

The favorite linux debugger.

In 2 lists

PEDA

Python Exploit Development Assistance for GDB.

In 5 listsDetails

Radare2

Framework for reverse-engineering and analyzing binaries.

In 2 lists

IDA Pro

The best disassembler

In 2 lists

binnavi

Binary analysis IDE, annotates control flow graphs and call graphs of disassembled code.

In 2 lists

Capstone

Capstone is a lightweight multi-platform, multi-architecture disassembly framework.

In 4 lists

ltrace

Intercepts library calls

In 3 lists

strace

Intercepts system calls

In 2 lists

Vulnerable Applications

Exploit-DB -

(search and pick the exploits, which have respective apps available for download, reproduce the exploit by using fuzzer of your choice)

In 8 listsDetails

PacketStorm -

Fuzzgoat

Vulnerable C program for testing fuzzers.

In 2 lists

vulnserver

A vulnerable server for testing fuzzers.

In 2 lists

https://files.fuzzing-project.org/

PDF Test Corpus from Mozilla

PDF Reader in JavaScript.

In 5 listsDetails

MS Office file format documentation

Fuzzer Test Suite

Set of tests for fuzzing engines. Includes different well-known bugs such as Heartbleed, c-ares $100K bug and others.

Fuzzing Corpus

A corpus, including various file formats for fuzzing multiple targets in the fuzzing literature.

Anti Fuzzing

Introduction to Anti-Fuzzing: A Defence In-Depth Aid

Fuzzification: Anti-Fuzzing Techniques

In 2 lists

AntiFuzz: Impeding Fuzzing Audits of Binary Executables

In 2 lists
See category
94

Awesome OpenClaw Skills

VoltAgent/awesome-openclaw-skills

The awesome collection of OpenClaw skills. 5,400+ skills filtered and categorized from the official OpenClaw Skills Registry.🦞

Fresh★ 53k830 entriesPushed today
92

Awesome DeepSeek Harness (DSH) Plugin

awesome-dsh-plugin/awesome-dsh-plugin

A curated list of plugins for DeepSeek Harness (dsh) · DeepSeek Harness 插件精选列表

Fresh★ 17k1654 entriesPushed today
91

Awesome Guidelines

Kristories/awesome-guidelines

Programming style, best practices, and coding conventions.

Fresh★ 11k166 entriesPushed 2 days ago
90

Awesome

sindresorhus/awesome

😎 Awesome lists about all kinds of interesting topics [NOTE: Pull requests are temporarily disabled until I have a chance to catch up with the existing ones]

Fresh★ 513k51 entriesPushed 28 days ago
90

Awesome Prompts

ai-boost/awesome-prompts

Curated list of chatgpt prompts from the top-rated GPTs in the GPTs Store. Prompt Engineering, prompt attack & prompt protect. Advanced Prompt Engineering papers.

Fresh★ 9k288 entriesPushed yesterday
90

Awesome README

matiassingers/awesome-readme

A curated list of awesome READMEs

Fresh★ 22k143 entriesPushed yesterday