Showing 21 of 57 projects
A state-of-the-art file system fuzzer for Linux that explores both image and syscall input spaces simultaneously to find memory corruptions.
A dependency-aware GraphQL API fuzzing tool that automatically generates and executes security tests based on schema introspection.
A high-performance, safe Rocket League replay parser library written in Rust.
A test runner-agnostic library for data-driven testing, fuzz testing, and snapshot testing with descriptive titles.
A type-aware kernel fuzzing framework for Windows that uses static binary analysis to infer system call types for more effective fuzzing.
A kernel API fuzzer for macOS that automatically infers API models from execution logs to generate targeted fuzzers.
A framework for using AFL to fuzz web applications and detect SQL/command injection vulnerabilities.
An automated IAST fuzzer for discovering vulnerabilities in CakePHP web applications with minimal false positives.
A command-line tool for fuzzing network protocols by automating packet modifications to test firewall and IDS evasion.
An Android port of the Radamsa fuzzer for security testing on Android devices.
A multi-transaction differential fuzzer for finding consensus bugs in Ethereum clients.
A fuzzing tool for detecting Spectre vulnerabilities in software through dynamic analysis.
A fuzzing tool for ROS2 nodes that tests topics and services with pseudorandom data to uncover bugs and vulnerabilities.
A formally verified XML library in SPARK 2014, proven free of runtime errors and with bounded stack usage for secure untrusted data processing.
A blockchain consensus protocol fuzzing framework that detects memory-related and logic bugs by modeling node states.
A fuzzing framework for automatically detecting and exploiting template escape bugs in template engines.
Automated synthesis tool for discovering and testing Meltdown-style microarchitectural data leakage attacks on Intel CPUs.
A fuzzer for discovering bugs and vulnerabilities in ROS nodes by testing topics with pseudorandom data.
An experimental framework for building structure-aware, library API fuzzers using lifetime-aware dataflow graphs.
Generates wordlists of Danish phone numbers filtered by area code and line type for security testing.
A state-aware fuzzer for testing browser security policies by generating diverse web application responses without database setup.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.