| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Lightweight, extensible vulnerability research pipeline.
Target --> Collector --> Fuzzing --> Crash Detector --> Triage --> Report
SRF wires the boring parts of vulnerability research together: build targets with sanitizers, run mutation-based fuzzing, capture and deduplicate crashes, then emit triaged HTML/Markdown reports. Python-first, stdlib-only core, designed so heavy components (coverage guidance, AFL++/libFuzzer adapters, triage heuristics) can be swapped in later without touching the CLI contract.
pip install -e .cd examples && make && cd ..
srf fuzz \
--target ./examples/vuln-parser \
--corpus examples/corpus \
--crashes out/crashes \
--iterations 5000 \
--seed 42
srf triage --crashes out/crashes
srf report --crashes out/crashes --output out/report.htmlThe example target (examples/vuln-parser.c) contains a deliberate stack buffer overflow reachable via SRF/-prefixed input; ASAN output is parsed into stack hashes automatically.
| command | purpose |
|---|---|
| collect | clone + build a repo with sanitizer env defaults |
| fuzz | mutation-fuzz a target, store deduplicated crashes |
| triage | group crashes by stack hash, rank by frequency |
| report | render HTML + Markdown crash report |
An execution counts as a crash when any of these hold:
Stack hashes are derived from sanitizer frames (#0 0x... in function), falling back to first stderr line when symbols are unavailable.
Every crash stores its input (SHA-256 named), metadata JSON, and the exact target argv. Fuzzing sessions are seedable (--seed), so a crashing run can be replayed deterministically.
MIT — see LICENSE.
| Back | FazBrowse Home | New Git URL |