onefuzz

A self-hosted Fuzzing-As-A-Service platform

  • 所有者: microsoft/onefuzz
  • 平台:
  • 许可证: MIT License
  • 分类:
  • 主题:
  • 喜欢:
    0
      比较:

Github星跟踪图

OneFuzz

A self-hosted Fuzzing-As-A-Service platform

Project OneFuzz enables continuous developer-driven fuzzing to proactively
harden software prior to release. With a single
command
, which can be baked into
CICD
, developers can launch
fuzz jobs from a few virtual machines to thousands of cores.

Build Status

Build Onefuzz

Features

  • Composable fuzzing workflows: Open source allows users to onboard their own
    fuzzers, swap instrumentation, and manage seed inputs.
  • Built-in ensemble fuzzing: By default, fuzzers work as a team to share strengths,
    swapping inputs of interest between fuzzing technologies.
  • Programmatic triage and result de-duplication: It provides unique flaw cases that
    always reproduce.
  • On-demand live-debugging of found crashes: It lets you summon a live debugging
    session on-demand or from your build system.
  • Observable and Debug-able: Transparent design allows introspection into every
    stage.
  • Fuzz on Windows and Linux: Multi-platform by design. Fuzz using your own OS
    build
    , kernel, or nested hypervisor.
  • Crash reporting notification callbacks: Including Azure DevOps Work
    Items
    and Microsoft Teams
    messages

For information, check out some of our guides:

Are you a Microsoft employee interested in fuzzing? Join us on Teams at Fuzzing @ Microsoft.

Contributing

This project welcomes contributions and suggestions. Most contributions require
you to agree to a Contributor License Agreement (CLA) declaring that you have
the right to, and actually do, grant us the rights to use your contribution.
For details, visit https://cla.microsoft.com.

When you submit a pull request, a CLA-bot will automatically determine whether
you need to provide a CLA and decorate the PR appropriately (e.g., label,
comment). Simply follow the instructions provided by the bot. You will only
need to do this once across all repositories using our CLA.

This project has adopted the Microsoft Open Source Code of Conduct.
For more information see the Code of Conduct FAQ
or contact opencode@microsoft.com with any
additional questions or comments.

Data Collection

The software may collect information about you and your use of the software and
send it to Microsoft. Microsoft may use this information to provide services
and improve our products and services. You may turn off the telemetry as
described in the
repository
.
There are also some features in the software that may enable you and Microsoft
to collect data from users of your applications. If you use these features, you
must comply with applicable law, including providing appropriate notices to
users of your applications together with a copy of Microsoft's privacy
statement. Our privacy statement is located at
https://go.microsoft.com/fwlink/?LinkID=824704. You can learn more about data
collection and use in the help documentation and our privacy statement. Your
use of the software operates as your consent to these practices.

For more information:

Reporting Security Issues

Security issues and bugs should be reported privately, via email, to the
Microsoft Security Response Center (MSRC) at
secure@microsoft.com. You should receive a
response within 24 hours. If for some reason you do not, please follow up via
email to ensure we received your original message. Further information,
including the MSRC PGP
key, can be found in the Security TechCenter.

主要指标

概览
名称与所有者microsoft/onefuzz
主编程语言C#
编程语言Rust (语言数: 10)
平台
许可证MIT License
所有者活动
创建于2020-07-27 22:23:30
推送于2023-11-01 09:22:49
最后一次提交
发布数111
最新版本名称8.9.0 (发布于 )
第一版名称1.0.0 (发布于 )
用户参与
星数2.8k
关注者数90
派生数198
提交数2.2k
已启用问题?
问题数928
打开的问题数192
拉请求数2174
打开的拉请求数41
关闭的拉请求数451
项目设置
已启用Wiki?
已存档?
是复刻?
已锁定?
是镜像?
是私有?