offensive-tools/fuzzing/restler/SKILL.md
Auth/lab ref: Stateful REST API fuzzer from OpenAPI specs. For testing complex API dependency chains, producer-consumer request sequencing, and replayable bug-bucket workflows for API reliability/security testing.
npx skillsauth add aeondave/malskill restlerInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
RESTler explores deeper API states by inferring request dependencies from OpenAPI definitions.
# Build (local)
python build-restler.py --dest_dir <restler_bin>
# Typical campaign starts with compile + test before fuzz modes
restler.exe fuzz-lean --grammar_file <grammar.py> --dictionary_file <dict.json>
restler.exe fuzz --grammar_file <grammar.py> --dictionary_file <dict.json> --time_budget 1
test/smoke style workflow to confirm dependencies and dictionary values.fuzz-lean for quick risk discovery.fuzz for deeper sequence exploration with settings file tuning.test mode before deep fuzzing.fuzzing_mode (bfs, bfs-cheap, random-walk, directed-smoke-test)max_sequence_length, max_combinationsinclude_requests, exclude_requests, path_regex)custom_retry_settings, producer_timing_delay)use_trace_database) for structured replay workflowsbug_buckets.txt summary.development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.