0% found this document useful (0 votes)
8 views5 pages

Defensics Fuzz Testing Datasheet

Defensics® Fuzz Testing is an automated black box solution designed to enhance software security by identifying vulnerabilities through intelligent fuzzing techniques. It offers over 300 prebuilt test suites, customizable options, and detailed reporting to streamline the testing process and integrate into various development life cycles. The solution supports multiple protocols and technologies, making it adaptable for different industries and environments.

Uploaded by

Aik Meng Toh
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views5 pages

Defensics Fuzz Testing Datasheet

Defensics® Fuzz Testing is an automated black box solution designed to enhance software security by identifying vulnerabilities through intelligent fuzzing techniques. It offers over 300 prebuilt test suites, customizable options, and detailed reporting to streamline the testing process and integrate into various development life cycles. The solution supports multiple protocols and technologies, making it adaptable for different industries and environments.

Uploaded by

Aik Meng Toh
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

DEFENSICS

FUZZ TESTING

Improve software OVERVIEW


robustness, ensure Defensics® Fuzzing is a comprehensive, powerful, and automated black box solution
systems interoperability, that enables organizations to effectively and efficiently discover and remediate
and identify vulnerabilities, security weaknesses in software. By taking a systematic and intelligent approach
to negative testing, Defensics allows organizations to ensure software security
whether you’re procuring without compromising on product innovation, increasing time to market, or inflating
software for business operational costs.
operations or building it.

Defensics’ logical user interface walks users through each step of the process,
making advanced fuzz testing easy.

KEY FEATURES
Intelligent fuzzing engine
The Defensics engine is programmed with knowledge on input type, whether it’s an
interface, protocol, or file format. Because the engine has a deep understanding of
the rules that govern communication within the input type, it can deliver targeted
test cases that exploit that input type’s inherent security weaknesses. This intelligent
and systematic approach to fuzz testing allows you to reduce testing time without
compromising cost or security.

[Link] | 1
A comprehensive fuzzing solution
Our 300+ prebuilt, generational test suites ensure quick time to fuzz and relieve you of
the burden of creating manual tests. We continuously update our test suites for new
input types, specifications, and RFCs.
• Customize any of our test suites by fine-tuning the message sequence. The data
sequence editor allows you to cover corner cases not within Defensics’ predefined
scope.
• Need added extensibility? Use our template fuzzers. Universal Data Fuzzer is a
file format template fuzzer, and SDK Express helps generate test cases by reverse
engineering sample files you provide.
• Have proprietary or custom input types? Write your own test suites with Defensics
SDK, which supports Java and selected transport layers and comes equipped with
instrumentations.
• Speed up testing with FuzzBox support. It’s now easy to fuzz wireless LAN and IoT
protocols, with test runs directly on custom hardware.
• Choose from five new vertical solution bundles: automotive, ICS, IoT, networking,
Defensics reports contain message and telecom. Vertical solution bundles include foundational protocols in addition to
sequence logs to help users identify the protocols relevant to that vertical market.
root cause of an anomalous reaction.
Fits into most development life cycles
Defensics contains workflows that enable it to fit almost any environment from a
technological and process standpoint. Whether you employ a traditional SDL or a CI
development life cycle, Defensics brings fuzz testing into development early, allowing
you to catch and remediate vulnerabilities more cost-effectively. Got an unconventional
development life cycle? Our experienced Professional Services team can help you
identify fuzz testing checkpoints, define fuzz testing metrics, and establish a fuzz testing
maturity program.

It’s not just about fitting into the development process; it’s also about working with
surrounding technologies. API and data export capabilities allow Defensics to share data
for additional reporting and analysis, making Defensics a true plug-and-play fuzzer.

Detailed, data-rich reports for efficient remediation


• Contextualized logs. Remediation logs detail the protocol path and message
Defensics offers automated capabilities sequences between Defensics and the system under test (SUT) to help you identify the
trigger and technical impact of each vulnerability.
throughout the testing process, such as
Device Explorer, to relieve users of the • Vulnerability mapping. Defensics maps each vulnerability to industry standards such
as CWE and injection type to enhance information discovery and expedite remediation.
burden of manual configuration.
• Issue re-creation. Defensics narrows the vulnerability trigger to a single test case so
you can re-create the issue and verify the fix.
• Remediation packages. Generate encrypted remediation packages for your software
suppliers to facilitate secure, collaborative remediation across the supply chain.

Scale fuzz testing with automation


From scanning for the test target to determining the number of layers to connect to,
Defensics offers a rich set of APIs for flexible, scalable automation to meet all your
needs:
• Test single devices
• Set up repeatable automation to ensure test plans are followed every time
• Reduce testing times with the latest in scalable virtualization

[Link] | 2
DEFENSICS FUZZ TESTING | TEST SUITE CATALOG
Authentication, Authorization, and Core IP IoT*
Accounting (AAA) • DHCP/BOOTP Client/Server • Thread
• Diameter Client/Server • DHCPv6 Client/Server • BT
• EAPOL Server • DNS Client/Server • Wi-Fi AP
• Kerberos Server • FTP Client/Server • gRPC
• LDAPv3 Client/Server • HTTP Client/Server • Zigbee
• RADIUS Client/Server • HTTP/2 Client/Server
• TACACS+ Client/Server • HTTP/3 Server Link Management
• ICAP Server • LACP (802.3ad)
• MACsec Server
• IPv4 Package • STP/RSTP/MSTP/ESTP
Application – ARP Client/Server
• FIX Media
– ICMP • Archives Package
• JSON Format – IGMP
• Web Application – GZIP
– IPv4 – JAR
• WebSocket Client/Server – TCP for IPv4 Client/Server
• XML SOAP Client/Server – ZIP
• IPv6 Package • Audio Package
• XML File – ICMPv6
• XMPP Server – MP3
– IPv6 – MPEG4 (M4A/MP4)
• AMQP Server – TCP for IPv6 Client/Server
• WAMP Server – OGG
• SOCKS Client/Server – WAV
• OWAMP Server • Multicast DNS
• TWAMP Server – Windows Media (WMA/WMV)
• PPP over L2TP Client • Images Package
Automotive* • PPPoE – GIF
• CAN Bus Email – JPEG
• CAN FD • IMAP4 Client/Server – PNG
• DoIP Server • MIME – TIFF
• gPTP Server • POP3 Server • Video Package
• SOME/IP • SMTP Client/Server – H.264 File Suite
• SRP Server – H.264 RTP Format
General Purpose – MPEG2-TS
Cellular Core • SDK Express – MPEG4 (M4A/MP4)
• BICC/M3UA • Universal ASN.1 BER – OGG
• GRE • Universal Fuzzer – Windows Media (WMA/WMV)
• GTP Prime
• GTPv0 ICS* Medical
• PMIPv6 Client/Server • 60870-5-104 (iec104) Client/Server • DICOM Server
• SCTP Client/Server • 61850/Goose/SV • HL7v2 Server
• SMPP • 61850/MMS Client/Server
• FHIR Client/Server
• SMS (SMPP injection) • BACNET
• SMS (file injection) • CIP Server Metro Ethernet
• MAP • COAP Server • BFD
• BSSAP • DNP3 Client/Server • CFM (802.1ag, Y.1731)
• BSSAP+ • MQTT Client/Server • E-LMI (MEF-16)
• CAP • Modbus Master • Ethernet (802.3, 802.1Q)
• INAP • Modbus PLC • GARP (802.1D)
• ISUP • OPC UA Server • LLDP (802.1AB)
• MTP3 / M2UA|M2PA • Profinet DCP • OAM (802.3ah)
• TCAP / SCCP / M3UA • Profinet PTCP Client/Server • PBB-TE Server
• DLMS/COSEM Client/Server • Synchronous Ethernet (ESMC)
• SBI Client/Server
• ISASecure Testing Solution

* Vertical market solutions that can be purchased together.

[Link] | 3
Networking* Telecom* Wireless
• BGP • 5G • Zigbee Package
• SNMP • SMS – FuzzBox Zigbee APS
• IPv4/IPv6 • Pre-5G – FuzzBox Zigbee MAC
• SIP • O-RAN A1-P – FuzzBox Zigbee NWK
• Metro Ethernet • O-RAN-El • Thread package
– FuzzBox Thread 6LoWPAN
Public Key Infrastructure (PKI) Time Synchronization – FuzzBox Thread MAC
• CMPv2 Client/Server • IEEE1588 PTP Client/Server • Bluetooth LE Package
• CSR • NTP Client/Server – ATT Client/Server
– Advertisement
Remote Management Universal Plug and Play – HOGP Host
• CWMP (TR-69) ACS • UPnP Package – Health
• CWMP (TR-69) CPE – UPnP Multicast Eventing – L2CAP Server
• IPMI Server – UPnP SOAP – LL Peripheral
– UPnP SSDP Control Point – Profiles
• NETCONF
– UPnP SSDP Device – SMP Client/Server
• PCP Server
• Bluetooth Package
• SNMP trap VoIP – A2DP
• SNMPv2c Server • H.323 Client/Server – AVRCP
• SNMPv3 Server • H.248 GW Binary/Text – BNEP
• SSHv1 Server • H.248 MGC Binary/Text – HFP AG/Unit
• SSHv2 Server • MGCP Server – HSP AG/Unit
• Syslog – L2CAP
• MSRP Server
• TFTP Server – MAP Client
• RTP/RTCP/SRTP
• Telnet Server – OBEX-Server
• RTSP Client/Server – PBAP Client
• SIP UAC – RFCOMM
Routing
• SIP UAS (+TT) – SDP
• BGP4+ Client/Server
• SIP-I Server • Wi-Fi AP Package
• IS-IS
• STUN Client/Server – 802.11 WLAN AP
• LDP
• TURN Client/Server – 802.11 WPA AP
• MPLS Server
• SigComp Server – 802.11 WPA3 AP
• MSDP
• Wi-Fi Client Package
• OSPFv2 VPN – 802.11 WLAN Client
• OSPFv3 • DTLS Client/Server – 802.11 WPA Client
• Openflow controller • IKEv2 Client/Server – 802.11 WPA3 Client
• Openflow switch • IPSec
• PIM-SM/DM 5G technology
• ISAKMP/IKEv1 Client/Server
• RIP • GTPv2-C Client/Server
• L2TPv2/v3 Client/Server
• RIPng • S1AP/NAS Client/Server
• OCSP Client/Server
• RSVP • GTPv1 Client/Server
• SCEP
• TRILL Server • E1AP Client/Server
• SSTP
• VRRP • NGAP/NAS Client/Server
• TLS/SSL Client/Server
• COPS Client/Server • X2AP Client/Server
• X.509v3 Certificates
• XnAP Client/Server
Storage • VXLAN
• PFCP Client/Server
• CIFS/SMB Server • F1AP Client/Server
• DCE/RPC Server
• NFSv3 Server
For full list of test suites, please see
• NFSv4.0 / 4.1 Server
[Link]/security-testing/fuzz-
• Netbios Server
testing/[Link]
• DNNG
• SMBv2 Client/ServerMP
• SMBv3 Client/Server
• SunRPC Server
• iSCSI Client/Server
* Vertical market solutions that can be purchased together.

[Link] | 4
Monitoring and engine • Cross-site request forgery Anomaly categories
capabilities • Cross-site scripting • ASN.1/BER anomalies
• ECDH Public Key validation • Credential anomalies
Instrumentation
• Extra cookie compared to valid case • Deep packet inspection
• Valid case
• Syslog • Heartbleed • EICAR antivirus test file
• Agent • Information leakage • GTUBE (generic test for unsolicited bulk
• SNMP • Insufficient randomness email)
• Custom scripting at each testing • LDAP injection in response • Control plane injection anomalies
execution • Malformed HTTP • Integer anomalies
• Remote execution • Network address anomalies
SafeGuard checkers
• SQL injection in response • Overflow anomalies
• Amplification
• SMP insecure pairing parameters • Underflow anomalies
• Authentication bypass
• Unexpected data
• Blind LDAP injection
• Unprotected credentials
• Blind SQL injection Note: We add test suites frequently.
• Weak cryptography Please contact us for the latest list.
• Certificate validation
• Compressed signer’s name in RRSIG
record

About Black Duck


Black Duck® meets the board-level risks of modern software with True Scale Application Security, ensuring uncompromised trust in
software for the regulated, AI-powered world. Only Black Duck solutions free organizations from tradeoffs between speed, accuracy,
and compliance at scale while eliminating security, regulatory, and licensing risks. Whether in the cloud or on premises, Black Duck is
the only choice for securing mission-critical software everywhere code happens. With Black Duck, security leaders can make smarter
decisions and unleash business innovation with confidence. Learn more at [Link] .

©2025 Black Duck Software, Inc. All rights reserved. Black Duck is a trademark of Black Duck Software, Inc. in the United States and other countries. All other names
mentioned herein are trademarks or registered trademarks of their respective owners. September 2025

[Link] | 5

You might also like