boofuzz

B
B tier on Fuzz Testing SoftwareScore 7.1 · #6 of 27
Android app
Not listed
Free plan
Yes
Runs on
api, Linux, self-hosted, Windows
github.com
The boofuzz homepage

Summary

boofuzz is a free, open-source framework for fuzzing network protocols, and a fork and successor to Sulley. It installs as a Python library with `pip install boofuzz` and requires Python 3.9 or later. Its workflow generates data, detects failures, resets targets after failures, and records test data. Documented connections include TCP, UDP, SSL, raw sockets, and serial; it also supports Ethernet and IP-layer communication and UDP broadcast fuzzing. Run logs are stored in a SQLite database in the boofuzz-results directory, and saved runs can be reopened in the web interface with `boo open`. Results can be exported as CSV. The process monitor detects crashes and restarts applications on Windows or Linux, but must run on the target machine. The optional network monitor requires Pcapy and Impacket, which are not installed automatically. Public FTP and HTTP protocol libraries are available, though their implementations do not cover the full protocols. The project uses the GPL-2.0 license and directs usage questions to Stack Overflow and bug reports to GitHub issues.

Who it is for

boofuzz suits Python developers working with protocol fuzzing across network and serial connections. It may also fit users who need crash monitoring, target resets, and saved run logs.

What is good

  • Free and open source under GPL-2.0.
  • Supports TCP, UDP, SSL, raw sockets, and serial.
  • Records run logs in SQLite.
  • Exports test results as CSV.
  • Can detect crashes and restart applications.

What to know first

  • Requires Python 3.9 or later.
  • Network monitoring requires separately installed Pcapy and Impacket.
  • Process monitoring must run on the target machine.
  • FTP and HTTP libraries do not provide full protocol coverage.

Verdict

boofuzz provides a Python-based workflow for generating test data, detecting failures, resetting targets, and preserving run results. Users should account for its Python requirement, optional network-monitor dependencies, and the limited coverage of its public FTP and HTTP libraries.

boofuzz plans and pricing

All plans
Free and open source Free Python library for building fuzzer scripts · GPL-2.0 license github.com · 5 Oct 2026

Compared on fuzz testing software

Free plan
Yesgithub.com
Input generation methods
hybridgithub.com
Target types
network protocols, serial, Ethernet/IP, UDP broadcast, TCP, UDP, SSL, raw socketsgithub.com
Crash triage
Yesgithub.com
Execution mode
localgithub.com
Supported languages
Pythongithub.com

Facts

Purpose
Boofuzz is a network protocol fuzzing framework and a fork and successor to Sulley.github.com · 4 Oct 2026
Installation
Boofuzz installs as a Python library for building fuzzer scripts using `pip install boofuzz`.github.com · 4 Oct 2026
Python requirement
Boofuzz requires Python 3.9 or later.github.com · 4 Oct 2026
Fuzzing workflow
Its core capabilities include data generation, failure detection, target reset after failure, and recording test data.boofuzz.readthedocs.io · 4 Oct 2026
Communications
It supports arbitrary communications media, including serial, Ethernet and IP layer, and UDP broadcast fuzzing.boofuzz.readthedocs.io · 4 Oct 2026
Results
It records test data and supports exporting test results as CSV.boofuzz.readthedocs.io · 4 Oct 2026
Protocol suites
The documentation lists public boofuzz FTP and HTTP protocol libraries and says their implementations do not approach full protocol coverage.boofuzz.readthedocs.io · 4 Oct 2026
Monitoring
The process monitor detects crashes and restarts applications on Windows or Linux, and must run on the target machine.github.com · 4 Oct 2026
Optional dependency
The network monitor requires Pcapy and Impacket, which are not installed automatically with boofuzz.github.com · 4 Oct 2026
License
The GitHub repository identifies the project license as GPL-2.0.github.com · 4 Oct 2026
Support
The project directs users to Stack Overflow for usage questions and GitHub issues for bugs and suggestions.github.com · 4 Oct 2026
Documentation
The project provides online documentation with quickstarts and API documentation.boofuzz.readthedocs.io · 4 Oct 2026
Fuzzer workflow
It provides data generation, failure detection instrumentation, target reset after failure, and test data recording.github.com · 5 Oct 2026
Protocol support
It supports arbitrary communication media and includes serial, Ethernet and IP-layer, and UDP broadcast fuzzing.github.com · 5 Oct 2026
Extensibility
The project describes extensibility as a goal and supports extending instrumentation and failure detection.github.com · 5 Oct 2026
Connections
Documented connection options include TCP, UDP, SSL, raw sockets, and serial connections.boofuzz.readthedocs.io · 5 Oct 2026
Run logs
Each run's log data is saved to a SQLite database in the boofuzz-results directory.boofuzz.readthedocs.io · 5 Oct 2026
Web interface
The quickstart says users can reopen the web interface on a saved run database with the boo open command.boofuzz.readthedocs.io · 5 Oct 2026
Protocol libraries
The documentation links free, open-source FTP and HTTP protocol libraries and says their implementations do not provide full protocol coverage.boofuzz.readthedocs.io · 5 Oct 2026
Target monitoring
The process monitor detects crashes and restarts applications on Windows or Linux, and must run on the target machine.boofuzz.readthedocs.io · 5 Oct 2026
Community support
The project directs bug reports and improvement ideas to GitHub issues or pull requests and suggests Stack Overflow for usage questions.github.com · 5 Oct 2026
Security and license
GitHub identifies the repository license as GPL-2.0.github.com · 5 Oct 2026

Best boofuzz alternatives

See all 20

Where it ranks on Everything Xiaomi

Is boofuzz yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources