Microsoft has open sourced its tool for sniffing out Windows 10 bugs

(Image credit: Shutterstock)

Microsoft has open sourced its internal fuzzing tool - Project OneFuzz - which is designed to automatically detect software security vulnerabilities, the company has revealed.

The fuzz testing framework is built for Azure and has been used by the firm to interrogate various products, including Windows 10, Microsoft Edge and more.

The release of Project OneFuzz delivers on promises made earlier this year to transition away from the Microsoft Security Risk Detection (MSRD) service and towards an automated, open-source equivalent.

In a blog post, the Redmond giant confirmed the tool is available immediately, for any development team that might want to use it.

Windows 10 bug hunt

According to Microsoft, advancements in the world of compilers has made fuzz testing code for vulnerabilities far cheaper and more accessible than ever before.

The company credits Google’s pioneering work in the space, which has served to streamline engineering tasks such as crash detection, coverage tracking and input harnessing.

“Fuzz testing is a highly effective method for increasing the security and reliability of native code - it is the gold standard for finding and removing costly, exploitable security flaws,” explained Justin Campbell and Mike Walker of Microsoft Security.

“Traditionally, fuzz testing has been a double-edged sword for developers: mandated by the software development lifecycle, highly effective in finding actionable flaws, yet very complicated to harness, execute and extract information from.” 

According to the pair, making the Project OneFuzz framework widely available will mean bugs are discovered earlier in the development process and allow security staff to actively hunt down vulnerabilities.

The tool can reportedly be used to launch fuzz tasks, “ranging in size from a few virtual machines to thousands of cores”, with just a single line of code.

Project OneFuzz is available to download immediately via GitHub, published under the highly permissive MIT license, and will continue to receive regular updates from Microsoft.

TOPICS
Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in Pro
cybersecurity
What's the right type of web hosting for me?
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
construction
Building in the digital age: why construction’s future depends on scaling jobsite intelligence
Latest in News
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost