Skip to content
Skillv1.0.0

performing-fuzzing-with-aflplusplus

Performs coverage-guided fuzzing of compiled binaries with AFL++, instrumenting targets via afl-cc/afl-clang-fast, minimizing corpora with afl-cmin and afl-tmin, running parallel campaigns with afl-fu

by mukul975(0) 0 installs
Free
Sign in to install

Free account. Installing gives you the manifest plus copy-paste snippets.

See reviews

About

Imported from mukul975/anthropic-cybersecurity-skills (skills/performing-fuzzing-with-aflplusplus/SKILL.md). Install upstream with npx skills add mukul975/anthropic-cybersecurity-skills --skill performing-fuzzing-with-aflplusplus. Copyright stays with the author (Apache-2.0).

Performing Fuzzing with AFL++

Overview

AFL++ is a community-maintained fork of American Fuzzy Lop (AFL) that provides coverage-guided fuzzing for compiled binaries. It instruments targets at compile time or via QEMU/Unicorn mode for binary-only fuzzing, then mutates input corpora to discover new code paths. AFL++ includes advanced scheduling (MOpt, rare), custom mutators, CMPLOG for input-to-state comparison solving, and persistent mode for high-throughput fuzzing.

When to Use

  • When conducting security assessments that involve performing fuzzing with aflplusplus
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing

Prerequisites

  • AFL++ installed (apt install afl++ or build from source)
  • Target binary source code (for compile-time instrumentation) or QEMU mode for binary-only
  • Initial seed corpus of valid inputs for the target format
  • Linux system with /proc/sys/kernel/core_pattern configured

Steps

  1. Instrument the target binary with afl-cc or afl-clang-fast
  2. Prepare seed corpus directory with minimal valid inputs
  3. Minimize corpus with afl-cmin to remove redundant seeds
  4. Run afl-fuzz with appropriate flags (-i input -o output)
  5. Monitor fuzzing progress via afl-whatsup and UI stats
  6. Triage crashes with afl-tmin minimization and CASR/GDB analysis
  7. Report unique crashes with reproduction steps

Expected Output

+++ Findings +++
  unique crashes: 12
  unique hangs: 3
  last crash: 00:02:15 ago
+++ Coverage +++
  map density: 4.23% / 8.41%
  paths found: 1847
  exec speed: 2145/sec

Use it

Copy one of these into your project. Installing also returns the manifest and these snippets.

yaml
targets:
  - https://api.opensmartroute.ai/api/v1/registry/mukul975-anthropic-cybersecurity-skills-performing-fuzzi-62b5bc/manifest   # or paste the manifest below

Manifest

An Open Capability Manifest: the router reads it to know what this does, what it costs and when to pick it.

mukul975-anthropic-cybersecurity-skills-performing-fuzzi-62b5bc.ocm.jsonjson
{
  "ocm": "1",
  "id": "mukul975-anthropic-cybersecurity-skills-performing-fuzzi-62b5bc",
  "kind": "skill",
  "name": "performing-fuzzing-with-aflplusplus",
  "description": "Performs coverage-guided fuzzing of compiled binaries with AFL++, instrumenting targets via afl-cc/afl-clang-fast, minimizing corpora with afl-cmin and afl-tmin, running parallel campaigns with afl-fuzz, and triaging crashes with CASR or GDB scripts. Use for binary fuzzing, crash and memory-corruption discovery, coverage-guided testing, or running AFL++ fuzzing campaigns.",
  "publisher": "mukul975",
  "version": "1.0.0",
  "capabilities": {
    "domains": [
      "general"
    ],
    "tags": [
      "skill-md",
      "fuzzing",
      "aflplusplus",
      "coverage-guided",
      "crash-triage",
      "binary-analysis",
      "security-testing",
      "skills-sh"
    ],
    "languages": [
      "en"
    ]
  },
  "quality_prior": 0.6,
  "examples": [
    "Performs coverage-guided fuzzing of compiled binaries with AFL++, instrumenting targets via afl-cc/afl-clang-fast, minimizing corpora with afl-cmin and afl-tmin, running parallel campaigns with afl-fuzz, and triaging crashes with CASR or GDB scripts. Use for binary fuzzing, crash and memory-corruption discovery, coverage-guided testing, or running AFL++ fuzzing campaigns."
  ],
  "primary": false,
  "metadata": {
    "source": {
      "provider": "skills.sh",
      "repository": "https://github.com/mukul975/anthropic-cybersecurity-skills",
      "path": "skills/performing-fuzzing-with-aflplusplus/SKILL.md",
      "ref": "HEAD",
      "url": "https://github.com/mukul975/anthropic-cybersecurity-skills/blob/HEAD/skills/performing-fuzzing-with-aflplusplus/SKILL.md",
      "key": "mukul975/anthropic-cybersecurity-skills/skills/performing-fuzzing-with-aflplusplus/SKILL.md"
    },
    "license": "Apache-2.0"
  },
  "instructions": "# Performing Fuzzing with AFL++\n\n## Overview\n\nAFL++ is a community-maintained fork of American Fuzzy Lop (AFL) that provides coverage-guided\nfuzzing for compiled binaries. It instruments targets at compile time or via QEMU/Unicorn mode\nfor binary-only fuzzing, then mutates input corpora to discover new code paths. AFL++ includes\nadvanced scheduling (MOpt, rare), custom mutators, CMPLOG for input-to-state comparison solving,\nand persistent mode for high-throughput fuzzing.\n\n\n## When to Use\n\n- When conducting security assessments that involve performing fuzzing with aflplusplus\n- When following ",
  "cost": {
    "context_tokens": 428
  }
}

Fetch it by URL: GET /api/v1/registry/mukul975-anthropic-cybersecurity-skills-performing-fuzzi-62b5bc/manifest?version=1.0.0

Reviews

Star ratings from people who tried it. One review per account; edit yours any time.

No reviews yet. Install it, try it, and be the first to rate it.