Tool integration

ClusterFuzz Integration Guide

Google's scalable distributed fuzzing infrastructure that powers OSS-Fuzz

Get a Free API Key

Integrate ClusterFuzz with Vulnetix. Deploy ClusterFuzz for internal fuzzing at scale, monitor crash findings via the web UI and API, and export discovered vulnerabilities to Vulnetix.

SaaS platformJSON

Install & scan

$ # Deploy ClusterFuzz on GCP
git clone https://github.com/google/clusterfuzz
cd clusterfuzz
python butler.py create_config
python butler.py deploy
$ # ClusterFuzz REST API (requires API key from ClusterFuzz admin)
CF_URL="https://your-clusterfuzz.appspot.com"
CF_TOKEN="your-access-token"

# List open testcases
curl -s "${CF_URL}/testcases/load"   -H "Authorization: Bearer ${CF_TOKEN}"   | jq '.testcases' > clusterfuzz-crashes.json

vulnetix upload --file clusterfuzz-crashes.json

How Vulnetix compares: better together

Vulnetix does not replace ClusterFuzz. Keep running it. Vulnetix sits on top of ClusterFuzz (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

CapabilityVulnetixClusterFuzz
Security coverage
SAST (static code analysis)Built-in rules + Semgrep augmentation
SCA / dependencies40+ ecosystems, transitive graph
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine
Container & imageImage CVEs, base image, Dockerfile
IaC / misconfigurationTerraform, k8s, CloudFormation
Secret scanning1,000+ rules, source + binary + git history
Cloud / CSPMCloud-posture findings, compliance tab
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine
License complianceSPDX, copyleft/AGPL/SSPL policy
SBOM generationCycloneDX 1.7 + SPDX 2.3, cosign-signable
Malware / supply-chainDe-duplicated corpus + install-time firewall (25+ registries)
Network / infra vuln~ Ingests network scanner output; no native network scanner
FuzzingIngests fuzzing crashes; no native fuzzerCore: distributed continuous fuzzing infra powering OSS-Fuzz; multi-engine, corpus and crash management
Pentest / bug bountyIngests pentest/bug-bounty findings; not a testing service
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)Correlates every scanner into one prioritised queue with ownership routing~ Deduplicates crash testcases within fuzzing only; not cross-scanner ASPM consolidation of SAST/SCA/etc.
Exploit-intel prioritisationEPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV
Reachability analysisTree-sitter + CVEAffected; direct/transitive/semantic
Versioned VEX + audit trailImmutable OpenVEX/CycloneDX, cosign-signable
Safe Harbour autofixResolves + applies the nearest safe version
End-of-life policyFlags/blocks past-EOL runtimes & packages
SSVC / risk-based policySSVC v2 + CISA/FedRAMP/Essential-8 presets

✓ full · ~ partial · ✗ not covered

What ClusterFuzz does well

Where Vulnetix adds to it: Vulnetix runs no fuzzers and does not stand up fuzzing fleets; it ingests ClusterFuzz/OSS-Fuzz crash reports and consolidates them into a single prioritised queue with exploit-intel scoring, reachability, VEX and EOL/SSVC policy. ClusterFuzz's dedup is crash-level within one engine, whereas Vulnetix dedups across all scanners; the two are complementary. ClusterFuzz discovers, Vulnetix orchestrates.

No migration, no rip-and-replace. ClusterFuzz keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise ClusterFuzz results in Vulnetix

Upload ClusterFuzz JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

ClusterFuzz documentation ↗  ·  Source repository ↗

Wire ClusterFuzz into your CI/CD pipeline →