offensive-tools/fuzzing/aflplusplus/SKILL.md
Auth/lab ref: Coverage-guided fuzzing framework for source and binary targets.
npx skillsauth add aeondave/malskill aflplusplusInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
AFL++ is a modern AFL fork with stronger instrumentation, mutation strategies, and binary-only options.
# Build target with AFL++ wrappers
CC=afl-cc CXX=afl-c++ ./configure --disable-shared --disable-werror
make -j"$(nproc)"
# Fuzz stdin target
afl-fuzz -i seeds -o out -- ./target_bin
# Fuzz file-based target
afl-fuzz -i seeds -o out -- ./target_bin @@
afl-clang-lto (or afl-clang-fast fallback).afl-cmin).-o dir.CMPLOG/Redqueen) in parallel.afl-tmin, replay under sanitizer, and bucket by stack/PC.| Flag | Description |
|------|-------------|
| -i <dir> | Seed corpus directory |
| -o <dir> | Output campaign directory |
| -x <dict> | Dictionary for structured tokens |
| -m <mb> | Memory limit |
| -t <ms> | Per-exec timeout |
| -M / -S | Parallel main/secondary instances |
| -d | Skip deterministic stage (faster starts) |
Useful env variables in real campaigns:
AFL_USE_ASAN=1 / AFL_USE_UBSAN=1 for sanitizer build variants.AFL_LLVM_CMPLOG=1 for compare tracing binary used with -c.AFL_LLVM_LAF_ALL=1 for compare splitting (when needed).AFL_IMPORT_FIRST=1 to sync-import queue items early.AFL_TMPDIR=/dev/shm/... to reduce disk I/O pressure.# 1) Corpus cleanup
afl-cmin -i seeds -o seeds_min -- ./parser @@
# 2) Main instance
afl-fuzz -M main -i seeds_min -o out -- ./parser @@
# 3) Secondary instances (example)
afl-fuzz -S fast -i seeds_min -o out -p fast -- ./parser @@
afl-fuzz -S explore -i seeds_min -o out -p explore -- ./parser @@
# 4) Resume campaign later
afl-fuzz -i - -o out -- ./parser @@
# 5) Minimize crash for triage
afl-tmin -i out/default/crashes/id:000000* -o crash.min -- ./parser @@
FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION) to bypass blockers in harness builds.-m, -t) on unstable targets: noisy campaigns.development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.