Skip to content
STIMSMITH

Fuzzware

Tool
First seen 7/19/2026
Last seen 7/19/2026
Evidence 5 chunks

NEIGHBORHOOD

14 nodes · 19 edges
graph · Fuzzware · depth=1

RELATIONSHIPS

13 connections
Aurora-Fuzz Configuration Script ← uses 95% 2e
The Aurora-Fuzz Configuration Script automates Fuzzware configuration and can start fuzzing sessions.
Firmware Fuzzing implements → 100% 2e
Fuzzware is a firmware fuzzing tool designed to test embedded firmware binaries.
Aurora-Fuzz ← uses 95% 2e
Aurora-Fuzz is built on top of Fuzzware and automates its configuration process for nRF52 binaries.
The Fuzzware paper introduces the Fuzzware tool for effective firmware fuzzing.
Memory-Mapped I/O (MMIO) uses → 100% 1e
Fuzzware models MMIO accesses to simulate hardware peripheral responses during firmware emulation.
Coverage Feedback uses → 95% 1e
Fuzzware monitors code coverage and uses it as feedback to guide fuzzing.
Raw Input uses → 95% 1e
Fuzzware's fuzzing engine generates raw input bytes that are consumed by MMIO models.
ISA Emulator uses → 95% 1e
Fuzzware uses an ISA emulator to execute firmware as if on real hardware.
Crash Bucket Analysis implements → 95% 1e
Fuzzware has built-in functionality to gather crash buckets mapping crashes based on instruction pointer and link registers.
MMIO Modeling implements → 100% 1e
Fuzzware implements precise MMIO modeling to handle hardware peripheral interactions during firmware fuzzing.
Crash Trace Replay implements → 95% 1e
Fuzzware has built-in functionality to replay crash traces showing the path taken in the emulator up to the crash.
Coverage-Guided Fuzzing implements → 95% 1e
Fuzzware uses coverage feedback to guide the fuzzing process.
Emulation-Based Fuzzing implements → 95% 1e
Fuzzware uses an ISA emulator to run firmware in a virtual environment during fuzzing.