Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
ClusterFuzz is an advanced fuzzing platform designed to identify security vulnerabilities and stability problems within software applications. Utilized by Google for all its products, it also serves as the fuzzing backend for OSS-Fuzz. This infrastructure offers a plethora of features that facilitate the integration of fuzzing into the development lifecycle of software projects. It includes fully automated processes for bug filing, triage, and resolution across different issue trackers. Moreover, it supports various coverage-guided fuzzing engines to achieve optimal outcomes through techniques like ensemble fuzzing and diverse fuzzing strategies. The platform provides detailed statistics for evaluating fuzzer efficiency and tracking crash rates. Its user-friendly web interface simplifies management tasks and crash examinations, while it also accommodates multiple authentication providers via Firebase. Additionally, ClusterFuzz supports black-box fuzzing, minimizes test cases, and employs regression identification through bisection techniques, making it a comprehensive solution for software testing. The versatility and robustness of ClusterFuzz truly enhance the software development process.
Description
Without access to source code, discover and certify security weaknesses in any product. Any protocol or hardware can be tested with beSTORM. This includes those used in IoT and process control, CANbus-compatible automotive and aerospace. Realtime fuzzing is possible without needing access to the source code. There are no cases to download. One platform, one GUI to use, with more than 250+ pre-built protocol testing modules, and the ability to create custom and proprietary ones. Identify security flaws before deployment. These are the ones that are most commonly discovered by outside actors after release. In your own testing center, certify vendor components and your applications. Software module self-learning and propriety testing. Scalability and customization for all business sizes. Automate the generation and delivery of near infinite attack vectors. Also, document any product failures. Record every pass/fail and manually engineer the exact command that caused each failure.
API Access
Has API
No
API Access
Has API
No
Integrations
Firebase
Yes
Google OSS-Fuzz
Yes
Honggfuzz
Yes
Jira
Yes
LibFuzzer
Yes
american fuzzy lop
Yes
Integrations
Firebase
No
Google OSS-Fuzz
No
Honggfuzz
No
Jira
No
LibFuzzer
No
american fuzzy lop
No
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Pricing Details
$50,000.00/one-time
Free Trial
Yes
Free Version
No
Deployment
Web-Based
No
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
Yes
Mac
Yes
Linux
Yes
Chromebook
No
Deployment
Web-Based
No
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
Yes
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
Yes
Live Rep (24/7)
Yes
Online Support
No
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
No
Webinars
No
Live Training (Online)
Yes
In Person
Yes
Vendor Details
Company Name
Country
United States
Website
google.github.io/clusterfuzz/
Vendor Details
Company Name
Beyond Security (Fortra)
Founded
1999
Country
United States
Website
beyondsecurity.com/solutions/bestorm-dynamic-application-security-testing.html
Product Features
Product Features
Automated Testing
Hierarchical View
No
Move & Copy
No
Parameterized Testing
No
Requirements-Based Testing
No
Security Testing
Yes
Supports Parallel Execution
No
Test Script Reviews
No
Unicode Compliance
No
Software Testing
Automated Testing
No
Black-Box Testing
No
Dynamic Testing
No
Issue Tracking
No
Manual Testing
No
Quality Assurance Planning
No
Reporting / Analytics
No
Static Testing
No
Test Case Management
No
Variable Testing Methods
No
White-Box Testing
No