Skip to content
STIMSMITH

SOURCE ARCHIVE

SHA256: b02ba97fcd3d13ab93ac1960076f54cc5b4f64ec369f4f4fb79f89285920efb2
TYPE: text/html
SIZE: 313.2 KB
FETCHED: 7/30/2026, 10:11:09 AM
EXTRACTOR: http-html
CHARS: 47,751

EXTRACTED CONTENT

47,751 chars

Fuzzing

Awesome Fuzzing Awesome

Fuzzing or fuzz testing is an automated software testing technique that involves providing invalid, unexpected, or random data as inputs to a computer program. The program is then monitored for exceptions such as crashes, failing built-in code assertions, or potential memory leaks. Typically, fuzzers are used to test programs that take structured inputs.

A curated list of references to awesome Fuzzing for security testing. Additionally there is a collection of freely available academic papers, tools and so on.

Your favorite tool or your own paper is not listed? Fork and create a Pull Request to add it!

Books

Talks

Papers

To achieve a well-defined scope, I have chosen to include publications on fuzzing from 4 top major security conferences (2008–2025): (i) Network and Distributed System Security Symposium (NDSS), (ii) IEEE Symposium on Security and Privacy (S&P), (iii) USENIX Security Symposium (USEC), and (iv) ACM Conference on Computer and Communications Security (CCS).

Note: Papers are selected based on whether the title contains the keyword "fuzz." If a paper is related to fuzzing but does not include "fuzz" in its title, it may have been missed. In that case, please open a Pull Request and it will be reviewed for inclusion.

The Network and Distributed System Security Symposium (NDSS)

2025 (10 papers)

IEEE Symposium on Security and Privacy (IEEE S&P)

2025 (7 papers)

USENIX Security

2025 (15 papers)

ACM Conference on Computer and Communications Security (ACM CCS)

2025 (11 papers)

ArXiv (Fuzzing with Artificial Intelligence & Machine Learning)

The others

A curated collection of open-source fuzzing tools, organized by target category based on the taxonomy from fuzzing-survey.org. Tools are selected based on a combination of factors including GitHub popularity, recency, availability of official repositories from original authors, and whether the project is actively maintained.

File

  • AFL++ - A superior fork to Google's AFL with more speed, more and better mutations, more and better instrumentation, and custom module support.
  • Angora - A mutation-based coverage guided fuzzer that increases branch coverage by solving path constraints without symbolic execution.

Kernel

  • ACTOR (2023) - An action-guided kernel fuzzing framework that generates inputs leveraging triggered actions and their temporal relationships.
  • NTFuzz (2021) - A type-aware Windows kernel fuzzer that statically analyzes system binaries to infer system call types for more effective fuzzing.
  • KRACE (2020) - A coverage-guided fuzzing framework that detects data races in kernel file systems by exploring concurrency through multi-threaded syscall sequences.
  • Razzer (2019) - A kernel fuzzer that uses static analysis and two-phase fuzzing to detect race conditions and concurrency bugs in Linux kernels.
  • Hydra (2019) - A fuzzing framework for automatically discovering semantic bugs in file systems using input mutators, feedback engines, and customizable checkers.
  • Janus (2019) - A file system fuzzer that finds memory corruptions in Linux kernel file systems by mutating both filesystem images and syscall sequences simultaneously.
  • DIFUZE (2017) - An interface-aware fuzzer for Linux kernel drivers that automatically recovers ioctl interfaces via LLVM analysis and generates targeted test cases.
  • IMF (2017) - A kernel API fuzzer that leverages automated API model inference to discover vulnerabilities in macOS kernel APIs.
  • kAFL (2017) - A hardware-assisted x86-64 VM kernel fuzzing framework with performant VM reloads for finding OS kernel vulnerabilities.
  • syzkaller (2015) - An unsupervised coverage-guided kernel fuzzer supporting FreeBSD, Fuchsia, gVisor, Linux, NetBSD, OpenBSD, and Windows.
  • Trinity (2012) - A Linux system call fuzzer that generates semi-intelligent random arguments to syscalls, including valid file descriptors, flags, and range-biased values.

Network

API

  • WuppieFuzz - A coverage-guided REST API fuzzer developed on top of LibAFL.
  • IvySyn - A fully-automated framework for discovering memory error vulnerabilities in Deep Learning (DL) frameworks.
  • MINER - A REST API fuzzer that utilizes three data-driven designs working together to guide sequence generation, improve request generation quality, and capture unique errors caused by incorrect parameter usage.
  • RestTestGen - A robust tool and framework designed for automated black-box testing of RESTful web APIs.
  • GraphFuzz - An experimental framework for building structure-aware, library API fuzzers.
  • Minerva - A browser fuzzer augmented by API mod-ref relations, aiming to synthesize highly-relevant browser API invocations in each test case.
  • FANS - A fuzzing tool for Android native system services with four components: interface collector, interface model extractor, dependency inferer, and fuzzer engine.

JavaScript

Firmware

Hypervisor

CPU

  • DifuzzRTL - A differential fuzz testing approach for CPU verification.
  • MorFuzz - A generic RISC-V processor fuzzing framework that can efficiently detect software triggerable functional bugs.
  • SpecFuzz - A tool to enable fuzzing for Spectre vulnerabilities.
  • Transynther - Automatically generates and tests building blocks for Meltdown attacks with various faults and microcode assists.

Lib

Web

  • TEFuzz - A tailored fuzzing-based framework to facilitate the detection and exploitation of template escape bugs.
  • Witcher - A web application fuzzer that utilizes mutational fuzzing to explore web applications and fault escalation to detect command and SQL injection vulnerabilities.
  • CorbFuzz - A state-aware fuzzer for generating as many responses from a web application as possible without need of setting up a database.

DOM

Argument

Blockchain

  • Fluffy - A multi-transaction differential fuzzer for finding consensus bugs in Ethereum.
  • LOKI - A Blockchain consensus protocol fuzzing framework that detects consensus memory related and logic bugs.

DBMS

  • Squirrel - A fuzzer for database management systems (DBMSs).

Contribute

Contributions welcome! Read the contribution guidelines first.