performing-fuzzing-with-aflplusplus skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. 'Performs coverage-guided fuzzing of compiled binaries with AFL++, instrumenting Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/performing-fuzzing-with-aflplusplus/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-fuzzing-with-aflplusplus, or copy the skill folder into ~/.claude/skills/performing-fuzzing-with-aflplusplus/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/performing-fuzzing-with-aflplusplus/SKILL.md

SKILL.md (verbatim)

name: performing-fuzzing-with-aflplusplus
description: 'Performs coverage-guided fuzzing of compiled binaries with AFL++, instrumenting
  targets via afl-cc/afl-clang-fast, minimizing corpora with afl-cmin and afl-tmin,
  running parallel campaigns with afl-fuzz, and triaging crashes with CASR or GDB
  scripts. Use for binary fuzzing, crash and memory-corruption discovery, coverage-guided
  testing, or running AFL++ fuzzing campaigns.

  '
domain: cybersecurity
subdomain: application-security
tags:
- fuzzing
- aflplusplus
- coverage-guided
- crash-triage
- binary-analysis
- security-testing
version: '1.0'
author: mahipal
license: Apache-2.0
nist_ai_rmf:
- MEASURE-2.7
- MAP-5.1
- MANAGE-2.4
atlas_techniques:
- AML.T0070
- AML.T0066
- AML.T0082
nist_csf:
- PR.PS-01
- PR.PS-04
- ID.RA-01
- PR.DS-10
mitre_attack:
- T1078
- T1190
- T1059
- T1005

Performing Fuzzing with AFL++

Overview

AFL++ is a community-maintained fork of American Fuzzy Lop (AFL) that provides coverage-guided fuzzing for compiled binaries. It instruments targets at compile time or via QEMU/Unicorn mode for binary-only fuzzing, then mutates input corpora to discover new code paths. AFL++ includes advanced scheduling (MOpt, rare), custom mutators, CMPLOG for input-to-state comparison solving, and persistent mode for high-throughput fuzzing.

When to Use

  • When conducting security assessments that involve performing fuzzing with aflplusplus
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing

Prerequisites

  • AFL++ installed (apt install afl++ or build from source)
  • Target binary source code (for compile-time instrumentation) or QEMU mode for binary-only
  • Initial seed corpus of valid inputs for the target format
  • Linux system with /proc/sys/kernel/core_pattern configured

Steps

  1. Instrument the target binary with afl-cc or afl-clang-fast
  2. Prepare seed corpus directory with minimal valid inputs
  3. Minimize corpus with afl-cmin to remove redundant seeds
  4. Run afl-fuzz with appropriate flags (-i input -o output)
  5. Monitor fuzzing progress via afl-whatsup and UI stats
  6. Triage crashes with afl-tmin minimization and CASR/GDB analysis
  7. Report unique crashes with reproduction steps

Expected Output

+++ Findings +++
  unique crashes: 12
  unique hangs: 3
  last crash: 00:02:15 ago
+++ Coverage +++
  map density: 4.23% / 8.41%
  paths found: 1847
  exec speed: 2145/sec

Other files in this skill

references/api-reference.md (verbatim)

AFL++ Fuzzing — API Reference

Installation

apt install afl++                    # Ubuntu/Debian
# Or build from source:
git clone https://github.com/AFLplusplus/AFLplusplus && cd AFLplusplus && make all

AFL++ CLI Tools

Tool Description
afl-cc / afl-clang-fast Compile-time instrumentation compiler wrapper
afl-fuzz Main fuzzer — coverage-guided mutation engine
afl-cmin Corpus minimization — remove redundant seeds
afl-tmin Test case minimization — shrink individual inputs
afl-whatsup Multi-instance campaign status summary
afl-plot Generate fuzzing progress plots
afl-showmap Display coverage map for a single input

afl-fuzz Key Flags

Flag Description
-i <dir> Input seed corpus directory
-o <dir> Output directory for findings
-m <MB> Memory limit (use none for ASAN)
-t <ms> Execution timeout per test case
-x <dict> Optional fuzzing dictionary
-p <sched> Power schedule: fast, coe, explore, rare, mmopt
-l <level> CMPLOG instrumentation level (2=transforms, 3=all)
-c <bin> CMPLOG binary for input-to-state
-M <name> Main fuzzer instance (parallel mode)
-S <name> Secondary fuzzer instance (parallel mode)
-Q QEMU mode (binary-only fuzzing)
-U Unicorn mode

fuzzer_stats File Fields

Field Description
execs_done Total executions completed
execs_per_sec Current execution speed
corpus_count Total paths in corpus
saved_crashes Unique crashes discovered
saved_hangs Unique hangs discovered
stability Execution stability percentage
bitmap_cvg Code coverage bitmap density

Crash Triage Tools

Tool Purpose
casr-afl CASR crash severity analysis for AFL++
afl-tmin Minimize crash inputs
gdb --batch -ex run Reproduce crash under debugger

External References

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.