FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

lshdf-labs/security-research-framework · GitHub

Latest commit

 

History

1 Commit

Folders and files

Repository files navigation

security-research-framework (SRF)

Lightweight, extensible vulnerability research pipeline.

Target --> Collector --> Fuzzing --> Crash Detector --> Triage --> Report

SRF wires the boring parts of vulnerability research together: build targets with sanitizers, run mutation-based fuzzing, capture and deduplicate crashes, then emit triaged HTML/Markdown reports. Python-first, stdlib-only core, designed so heavy components (coverage guidance, AFL++/libFuzzer adapters, triage heuristics) can be swapped in later without touching the CLI contract.

Install

pip install -e .

Quickstart

cd examples && make && cd ..

srf fuzz \
  --target ./examples/vuln-parser \
  --corpus examples/corpus \
  --crashes out/crashes \
  --iterations 5000 \
  --seed 42

srf triage --crashes out/crashes
srf report --crashes out/crashes --output out/report.html

The example target (examples/vuln-parser.c) contains a deliberate stack buffer overflow reachable via SRF/-prefixed input; ASAN output is parsed into stack hashes automatically.

Commands

command purpose
collect clone + build a repo with sanitizer env defaults
fuzz mutation-fuzz a target, store deduplicated crashes
triage group crashes by stack hash, rank by frequency
report render HTML + Markdown crash report

Crash detection

An execution counts as a crash when any of these hold:

  • POSIX: process killed by a signal (negative returncode)
  • shell signal convention: exit code >= 128
  • Windows: 0xC0000005, 0xC0000409, 0x80000003
  • custom codes supplied via --crash-exit-codes

Stack hashes are derived from sanitizer frames (#0 0x... in function), falling back to first stderr line when symbols are unavailable.

Reproducibility

Every crash stores its input (SHA-256 named), metadata JSON, and the exact target argv. Fuzzing sessions are seedable (--seed), so a crashing run can be replayed deterministically.

Roadmap

  • coverage-guided fuzzing (SanitizerCoverage / libFuzzer corpus format)
  • AFL++ persistent-mode adapter
  • input minimization (delta debugging)
  • Rust core for mutator/executor hot path
  • OSS-Fuzz style build integration in collect

License

MIT — see LICENSE.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages


Back | FazBrowse Home | New Git URL