Fuzzing Open Source Projects
Browse 418 Fuzzing open source projects, ranked by GitHub stars. Find the most popular Fuzzing tools and libraries.
Hack-with-Github/Awesome-Hacking
A collection of various awesome lists for hackers, pentesters and security researchers
Metrics details
| Stars | 116,474 |
danielmiessler/SecLists
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
Metrics details
| Stars | 72,302 |
ffuf/ffuf
Fast web fuzzer written in Go
Metrics details
| Stars | 16,399 |
maurosoria/dirsearch
Web path scanner
Metrics details
| Stars | 14,521 |
google/oss-fuzz
OSS-Fuzz - continuous fuzzing for open source software.
Metrics details
| Stars | 12,450 |
foundry-rs/foundry
Foundry is a blazing fast, portable and modular toolkit for Ethereum application development written in Rust.
Metrics details
| Stars | 10,493 |
spacejam/sled
the champagne of beta embedded databases
Metrics details
| Stars | 9,046 |
HypothesisWorks/hypothesis
The property-based testing library for Python
Metrics details
| Stars | 8,795 |
TheKingOfDuck/fuzzDicts
You Know, For WEB Fuzzing !
Metrics details
| Stars | 8,386 |
six2dez/reconftw
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
Metrics details
| Stars | 7,866 |
AFLplusplus/AFLplusplus
The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power schedules, MOpt mutators, unicorn_mode, and a lot more!
Metrics details
| Stars | 6,663 |
google/syzkaller
syzkaller is an unsupervised coverage-guided kernel fuzzer
Metrics details
| Stars | 6,273 |
secfigo/Awesome-Fuzzing
A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Development like root cause analysis.
Metrics details
| Stars | 5,876 |
elceef/dnstwist
Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation
Metrics details
| Stars | 5,709 |
google/clusterfuzz
Scalable fuzzing infrastructure.
Metrics details
| Stars | 5,582 |
dubzzz/fast-check
Property based testing framework for JavaScript (like QuickCheck) written in TypeScript
Metrics details
| Stars | 5,070 |
dvyukov/go-fuzz
Randomized testing for Go
Metrics details
| Stars | 4,853 |
fwupd/fwupd
A system daemon to allow session software to update firmware
Metrics details
| Stars | 4,077 |
1N3/IntruderPayloads
A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.
Metrics details
| Stars | 3,959 |
arainho/awesome-api-security
A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.
Metrics details
| Stars | 3,854 |
antonio-morales/Fuzzing101
An step by step fuzzing tutorial. A GitHub Security Lab initiative
Metrics details
| Stars | 3,807 |
evyatarmeged/Raccoon
A high performance offensive security tool for reconnaissance and vulnerability scanning
Metrics details
| Stars | 3,786 |
google/fuzzing
Tutorials, examples, discussions, research proposals, and other resources related to fuzzing
Metrics details
| Stars | 3,778 |
unicode-org/icu
The home of the ICU project source code.
Metrics details
| Stars | 3,555 |
google/honggfuzz
Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)
Metrics details
| Stars | 3,366 |
rtcatc/Packer-Fuzzer
Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.
Metrics details
| Stars | 3,252 |
six2dez/OneListForAll
Rockyou for web fuzzing
Metrics details
| Stars | 3,198 |
crytic/echidna
Ethereum smart contract fuzzer
Metrics details
| Stars | 3,160 |
devanshbatham/ParamSpider
Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing
Metrics details
| Stars | 3,136 |
microsoft/restler-fuzzer
RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and reliability bugs in these services.
Metrics details
| Stars | 2,924 |
dloss/python-pentest-tools
Python tools for penetration testers
Metrics details
| Stars | 2,880 |
microsoft/onefuzz
A self-hosted Fuzzing-As-A-Service platform
Metrics details
| Stars | 2,828 |
gh0stkey/Web-Fuzzing-Box
Web Fuzzing Box - Web 模糊测试字典与一些Payloads
Metrics details
| Stars | 2,768 |
wcventure/FuzzingPaper
Recent Fuzzing Paper
Metrics details
| Stars | 2,767 |
asatarin/testing-distributed-systems
Curated list of resources on testing distributed systems
Metrics details
| Stars | 2,625 |
AFLplusplus/LibAFL
Advanced Fuzzing Library - Slot your Fuzzer together in Rust! Scales across cores and machines. For Windows, Android, MacOS, Linux, no_std, ...
Metrics details
| Stars | 2,608 |
googleprojectzero/winafl
A fork of AFL for fuzzing Windows binaries
Metrics details
| Stars | 2,584 |
Ignitetechnologies/BurpSuite-For-Pentester
This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and completely with "BurpSuite".
Metrics details
| Stars | 2,562 |
jtpereyda/boofuzz
A fork and successor of the Sulley Fuzzing Framework
Metrics details
| Stars | 2,349 |
googleprojectzero/fuzzilli
A JavaScript Engine Fuzzer
Metrics details
| Stars | 2,314 |
p0dalirius/Coercer
A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
Metrics details
| Stars | 2,293 |
Escapingbug/awesome-browser-exploit
awesome list of browser exploitation tutorials
Metrics details
| Stars | 2,290 |
felixguendling/cista
Cista is a simple, high-performance, zero-copy C++ serialization & reflection library.
Metrics details
| Stars | 2,231 |
insightglacier/Dictionary-Of-Pentesting
Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。
Metrics details
| Stars | 2,065 |
yahoo/gryffin
Gryffin is a large scale web security scanning platform.
Metrics details
| Stars | 2,052 |
0xSobky/HackVault
A container repository for my public web hacks!
Metrics details
| Stars | 2,033 |
a3vilc0de/PentesterSpecialDict
Dictionary for penetration testers happy hacker
Metrics details
| Stars | 1,905 |
rust-fuzz/cargo-fuzz
Command line helpers for fuzzing
Metrics details
| Stars | 1,851 |
rust-fuzz/afl.rs
🐇 Fuzzing Rust code with American Fuzzy Lop
Metrics details
| Stars | 1,834 |
parsiya/Hacking-with-Go
Golang for Security Professionals
Metrics details
| Stars | 1,821 |
googleprojectzero/domato
DOM fuzzer
Metrics details
| Stars | 1,788 |
0vercl0k/wtf
wtf is a distributed, code-coverage guided, customizable, cross-platform snapshot-based fuzzer designed for attacking user and / or kernel-mode targets running on Microsoft Windows and Linux user-mode (experimental!).
Metrics details
| Stars | 1,778 |
sqlancer/sqlancer
Automated testing to find logic and performance bugs in database systems
Metrics details
| Stars | 1,741 |
bowu678/php_bugs
PHP代码审计分段讲解
Metrics details
| Stars | 1,722 |
cn0xroot/RFSec-ToolKit
RFSec-ToolKit is a collection of Radio Frequency Communication Protocol Hacktools.无线通信协议相关的工具集,可借助SDR硬件+相关工具对无线通信进行研究。Collect with ♥ by HackSmith
Metrics details
| Stars | 1,706 |
crossbario/autobahn-testsuite
Autobahn WebSocket protocol testsuite
Metrics details
| Stars | 1,681 |
swisskyrepo/GraphQLmap
GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)
Metrics details
| Stars | 1,678 |
marin-m/pbtk
A toolset for reverse engineering and fuzzing Protobuf-based apps
Metrics details
| Stars | 1,674 |
google/atheris
Metrics details
| Stars | 1,648 |
veo/vscan
开源、轻量、快速、跨平台 的网站漏洞扫描工具,帮助您快速检测网站安全隐患。功能 端口扫描(port scan) 指纹识别(fingerprint) 漏洞检测(nday check) 智能爆破 (admin brute) 敏感文件扫描(file fuzz)
Metrics details
| Stars | 1,630 |
