What it does. 'Performs coverage-guided fuzzing of compiled binaries with AFL++, instrumenting Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-fuzzing-with-aflplusplus, or copy the skill folder into ~/.claude/skills/performing-fuzzing-with-aflplusplus/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/performing-fuzzing-with-aflplusplus/SKILL.md
SKILL.md (verbatim)
name: performing-fuzzing-with-aflplusplus
description: 'Performs coverage-guided fuzzing of compiled binaries with AFL++, instrumenting
targets via afl-cc/afl-clang-fast, minimizing corpora with afl-cmin and afl-tmin,
running parallel campaigns with afl-fuzz, and triaging crashes with CASR or GDB
scripts. Use for binary fuzzing, crash and memory-corruption discovery, coverage-guided
testing, or running AFL++ fuzzing campaigns.
'
domain: cybersecurity
subdomain: application-security
tags:
- fuzzing
- aflplusplus
- coverage-guided
- crash-triage
- binary-analysis
- security-testing
version: '1.0'
author: mahipal
license: Apache-2.0
nist_ai_rmf:
- MEASURE-2.7
- MAP-5.1
- MANAGE-2.4
atlas_techniques:
- AML.T0070
- AML.T0066
- AML.T0082
nist_csf:
- PR.PS-01
- PR.PS-04
- ID.RA-01
- PR.DS-10
mitre_attack:
- T1078
- T1190
- T1059
- T1005
Performing Fuzzing with AFL++
Overview
AFL++ is a community-maintained fork of American Fuzzy Lop (AFL) that provides coverage-guided
fuzzing for compiled binaries. It instruments targets at compile time or via QEMU/Unicorn mode
for binary-only fuzzing, then mutates input corpora to discover new code paths. AFL++ includes
advanced scheduling (MOpt, rare), custom mutators, CMPLOG for input-to-state comparison solving,
and persistent mode for high-throughput fuzzing.
When to Use
- When conducting security assessments that involve performing fuzzing with aflplusplus
- When following incident response procedures for related security events
- When performing scheduled security testing or auditing activities
- When validating security controls through hands-on testing
Prerequisites
- AFL++ installed (
apt install afl++ or build from source)
- Target binary source code (for compile-time instrumentation) or QEMU mode for binary-only
- Initial seed corpus of valid inputs for the target format
- Linux system with /proc/sys/kernel/core_pattern configured
Steps
- Instrument the target binary with
afl-cc or afl-clang-fast
- Prepare seed corpus directory with minimal valid inputs
- Minimize corpus with
afl-cmin to remove redundant seeds
- Run
afl-fuzz with appropriate flags (-i input -o output)
- Monitor fuzzing progress via afl-whatsup and UI stats
- Triage crashes with
afl-tmin minimization and CASR/GDB analysis
- Report unique crashes with reproduction steps
Expected Output
+++ Findings +++
unique crashes: 12
unique hangs: 3
last crash: 00:02:15 ago
+++ Coverage +++
map density: 4.23% / 8.41%
paths found: 1847
exec speed: 2145/sec
Other files in this skill
references/api-reference.md (verbatim)
AFL++ Fuzzing — API Reference
Installation
apt install afl++ # Ubuntu/Debian
# Or build from source:
git clone https://github.com/AFLplusplus/AFLplusplus && cd AFLplusplus && make all
| Tool |
Description |
afl-cc / afl-clang-fast |
Compile-time instrumentation compiler wrapper |
afl-fuzz |
Main fuzzer — coverage-guided mutation engine |
afl-cmin |
Corpus minimization — remove redundant seeds |
afl-tmin |
Test case minimization — shrink individual inputs |
afl-whatsup |
Multi-instance campaign status summary |
afl-plot |
Generate fuzzing progress plots |
afl-showmap |
Display coverage map for a single input |
afl-fuzz Key Flags
| Flag |
Description |
-i <dir> |
Input seed corpus directory |
-o <dir> |
Output directory for findings |
-m <MB> |
Memory limit (use none for ASAN) |
-t <ms> |
Execution timeout per test case |
-x <dict> |
Optional fuzzing dictionary |
-p <sched> |
Power schedule: fast, coe, explore, rare, mmopt |
-l <level> |
CMPLOG instrumentation level (2=transforms, 3=all) |
-c <bin> |
CMPLOG binary for input-to-state |
-M <name> |
Main fuzzer instance (parallel mode) |
-S <name> |
Secondary fuzzer instance (parallel mode) |
-Q |
QEMU mode (binary-only fuzzing) |
-U |
Unicorn mode |
fuzzer_stats File Fields
| Field |
Description |
execs_done |
Total executions completed |
execs_per_sec |
Current execution speed |
corpus_count |
Total paths in corpus |
saved_crashes |
Unique crashes discovered |
saved_hangs |
Unique hangs discovered |
stability |
Execution stability percentage |
bitmap_cvg |
Code coverage bitmap density |
| Tool |
Purpose |
casr-afl |
CASR crash severity analysis for AFL++ |
afl-tmin |
Minimize crash inputs |
gdb --batch -ex run |
Reproduce crash under debugger |
External References
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.