LibFuzzer

LibFuzzer

LLVM Project
beSTORM

beSTORM

Beyond Security (Fortra)
+
+

Related Products

  • Parasoft
    152 Ratings
    Visit Website
  • QA Wolf
    270 Ratings
    Visit Website
  • MuukTest
    34 Ratings
    Visit Website
  • TrustInSoft Analyzer
    6 Ratings
    Visit Website
  • AuthorityTech
    2 Ratings
    Visit Website
  • Orca Security
    606 Ratings
    Visit Website
  • Bluepear
    57 Ratings
    Visit Website
  • SDS Manager
    4 Ratings
    Visit Website
  • DXcharts
    28 Ratings
    Visit Website
  • TIMi
    68 Ratings
    Visit Website

About

LibFuzzer is an in-process, coverage-guided, evolutionary fuzzing engine. LibFuzzer is linked with the library under test, and feeds fuzzed inputs to the library via a specific fuzzing entry point (or target function); the fuzzer then tracks which areas of the code are reached, and generates mutations on the corpus of input data in order to maximize the code coverage. The code coverage information for libFuzzer is provided by LLVM’s SanitizerCoverage instrumentation. LibFuzzer is still fully supported in that important bugs will get fixed. The first step in using libFuzzer on a library is to implement a fuzz target, a function that accepts an array of bytes and does something interesting with these bytes using the API under test. Note that this fuzz target does not depend on libFuzzer in any way so it is possible and even desirable to use it with other fuzzing engines like AFL and/or Radamsa.

About

Discover code weaknesses and certify the security strength of any product without access to source code. Test any protocol or hardware with beSTORM, even those used in IoT, process control, CANbus compatible automotive and aerospace. Realtime fuzzing, doesn’t need access to the source code, no cases to download. One platform, one GUI to learn, with over 250+ prebuilt protocol testing modules and the ability to add custom and proprietary ones. Find the security weaknesses before deployment that are most often discovered by external actors after release. Certify vendor components and your own applications in your own testing center. Self-learning software module and propriety software testing. Customization and scalability for any business sizes up or down. Automatically generate and deliver near-infinite attack vectors and document any product failures. Record every pass/fail and hand engineering the exact command that produced each fail.

Platforms Supported

Windows Supported
Mac Not Supported
Linux Supported
Cloud Not Supported
On-Premises Not Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Platforms Supported

Windows Supported
Mac Not Supported
Linux Not Supported
Cloud Not Supported
On-Premises Not Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Audience

Users requiring a fuzzing engine to analyze their code and applications

Audience

Cybersecurity staff requiring a tool to perform comprehensive, dynamic black box security testing

Support

Phone Support Not Supported
24/7 Live Support Not Supported
Online Supported

Support

Phone Support Supported
24/7 Live Support Supported
Online Not Supported

API

Offers API Supported

API

Offers API Not Supported

Screenshots and Videos

Screenshots and Videos

Pricing

Free
Free Version Supported
Free Trial Not Supported

Pricing

$50,000.00/one-time
Free Version Not Supported
Free Trial Supported

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Training

Documentation Supported
Webinars Not Supported
Live Online Not Supported
In Person Not Supported

Training

Documentation Not Supported
Webinars Not Supported
Live Online Supported
In Person Supported

Company Information

LLVM Project
Founded: 2003
llvm.org/docs/LibFuzzer.html

Company Information

Beyond Security (Fortra)
Founded: 1999
United States
beyondsecurity.com/solutions/bestorm-dynamic-application-security-testing.html

Alternatives

afl-unicorn

afl-unicorn

Battelle

Alternatives

Atheris

Atheris

Google
Mayhem

Mayhem

ForAllSecure
Jazzer

Jazzer

Code Intelligence
NeoLoad

NeoLoad

Tricentis
Honggfuzz

Honggfuzz

Google
go-fuzz

go-fuzz

dvyukov

Categories

Fuzz Testing Supported

Categories

Automated Testing Features

Hierarchical View Not Supported
Move & Copy Not Supported
Parameterized Testing Not Supported
Requirements-Based Testing Not Supported
Security Testing Supported
Supports Parallel Execution Not Supported
Test Script Reviews Not Supported
Unicode Compliance Not Supported

Integrations

Atheris Supported
C Supported
C++ Supported
ClusterFuzz Supported
Fuzzbuzz Supported
Google ClusterFuzz Supported
Jazzer Supported

Integrations

Atheris Not Supported
C Not Supported
C++ Not Supported
ClusterFuzz Not Supported
Fuzzbuzz Not Supported
Google ClusterFuzz Not Supported
Jazzer Not Supported
Claim LibFuzzer and update features and information
Claim LibFuzzer and update features and information
Claim beSTORM and update features and information
Claim beSTORM and update features and information