Files
Anthropic-Cybersecurity-Skills/skills/performing-fuzzing-with-aflplusplus/SKILL.md
T
Mahipal 2fb6a9faff Rewrite 548 skill descriptions to the activation rubric
Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
2026-08-02 09:32:13 -07:00

2.5 KiB

name, description, domain, subdomain, tags, version, author, license, nist_ai_rmf, atlas_techniques, nist_csf, mitre_attack
name description domain subdomain tags version author license nist_ai_rmf atlas_techniques nist_csf mitre_attack
performing-fuzzing-with-aflplusplus Performs coverage-guided fuzzing of compiled binaries with AFL++, instrumenting targets via afl-cc/afl-clang-fast, minimizing corpora with afl-cmin and afl-tmin, running parallel campaigns with afl-fuzz, and triaging crashes with CASR or GDB scripts. Use for binary fuzzing, crash and memory-corruption discovery, coverage-guided testing, or running AFL++ fuzzing campaigns. cybersecurity application-security
fuzzing
aflplusplus
coverage-guided
crash-triage
binary-analysis
security-testing
1.0 mahipal Apache-2.0
MEASURE-2.7
MAP-5.1
MANAGE-2.4
AML.T0070
AML.T0066
AML.T0082
PR.PS-01
PR.PS-04
ID.RA-01
PR.DS-10
T1078
T1190
T1059
T1005

Performing Fuzzing with AFL++

Overview

AFL++ is a community-maintained fork of American Fuzzy Lop (AFL) that provides coverage-guided fuzzing for compiled binaries. It instruments targets at compile time or via QEMU/Unicorn mode for binary-only fuzzing, then mutates input corpora to discover new code paths. AFL++ includes advanced scheduling (MOpt, rare), custom mutators, CMPLOG for input-to-state comparison solving, and persistent mode for high-throughput fuzzing.

When to Use

  • When conducting security assessments that involve performing fuzzing with aflplusplus
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing

Prerequisites

  • AFL++ installed (apt install afl++ or build from source)
  • Target binary source code (for compile-time instrumentation) or QEMU mode for binary-only
  • Initial seed corpus of valid inputs for the target format
  • Linux system with /proc/sys/kernel/core_pattern configured

Steps

  1. Instrument the target binary with afl-cc or afl-clang-fast
  2. Prepare seed corpus directory with minimal valid inputs
  3. Minimize corpus with afl-cmin to remove redundant seeds
  4. Run afl-fuzz with appropriate flags (-i input -o output)
  5. Monitor fuzzing progress via afl-whatsup and UI stats
  6. Triage crashes with afl-tmin minimization and CASR/GDB analysis
  7. Report unique crashes with reproduction steps

Expected Output

+++ Findings +++
  unique crashes: 12
  unique hangs: 3
  last crash: 00:02:15 ago
+++ Coverage +++
  map density: 4.23% / 8.41%
  paths found: 1847
  exec speed: 2145/sec