Skip to content

crucible-triage

The standalone binary replays fuzzer inputs, combines process facts with text evidence, deduplicates by Exact identity, and writes unrated investigation reports.

crucible-triage [flags]
crucible-triage watch [flags]

It does not automatically confirm vulnerabilities, score CVSS, or infer affected versions.

Replay mode

crucible-triage \
  --artifact-kind input \
  --crashes ./crashes \
  --harness ./harness/libfuzzer/crucible-libfuzzer-model \
  --output ./reports \
  --target model-loader \
  --sarif ./reports/results.sarif
Flag Default Meaning
--artifact-kind input input replays reproducers; banked-log is skipped because another execution's text carries no process facts for this run
--crashes ./crashes input directory
--output ./reports investigation report directory
--harness none executable used to replay binary inputs
--minimize false minimize while preserving the observed identity
--replay-timeout 30s per-execution deadline
--replay-env none KEY=VALUE, repeatable; environment is part of the evidence
--target auto target surface, normally inferred from the harness name
--sarif none SARIF 2.1.0 destination

Invalid artifact kinds fail. Binary inputs without an executable harness are incomplete and exit non-zero; they are never interpreted as text. Banked logs also exit non-zero after being counted as unadjudicated work.

What it records

Each surfaced observation includes:

  • process outcome and evidence class;
  • crash taxonomy and CWE hint;
  • Exact identity for build-local buckets;
  • Stable identity and normalized target site for cross-build comparison;
  • legacy HashStack for historical oracle compatibility;
  • harness, replay environment, target, input, and minimized path;
  • raw stack evidence and explicit unattributed state.

Generated reports default to UNRATED, unknown affected versions, and no CVSS vector. CWE is a taxonomy hint that still requires source-level validation.

SARIF

crucible-triage \
  --artifact-kind input \
  --crashes ./crashes \
  --harness ./harness \
  --sarif ./results.sarif

SARIF levels are taxonomy-based, not CVSS-based: memory-safety is error, crash-only is warning, and resource exhaustion is note. Importing the file does not upgrade observations to confirmed vulnerabilities.

Watch mode

crucible-triage watch \
  --harness ./harness/libfuzzer/crucible-libfuzzer-deep \
  --crashes ./crashes \
  --output ./crashes/dedup \
  --interval 30s

Watch mode:

  1. discovers newly written crash artifacts;
  2. replays each through the harness;
  3. discards executions that establish no triage-worthy fault;
  4. deduplicates by Exact identity;
  5. copies unique inputs using Exact-based filenames;
  6. appends a versioned checkpoint only after the output is safely written.

Checkpoint entries bind the harness hash, environment digest, artifact hash, Exact identity, and legacy hash. On restore, incompatible or incomplete entries are discarded and reported instead of being silently trusted.

Flag Default Meaning
--harness required replay binary
--crashes ./crashes root to poll
--output ./crashes/dedup unique-artifact/checkpoint directory
--interval 30s poll period
--replay-timeout 30s per-input replay deadline
--replay-env none repeatable replay environment

Watch mode is a triage queue, not disclosure automation. Every unique observation still requires manual replay, source inspection, HEAD verification, severity ratification, and a human disclosure decision.

Relationship to the main CLI

crucible triage and crucible report use the same report-producing path for one-shot runs. The standalone binary exists for dedicated triage/watch deployments. For the full operational sequence, see Campaign Operations and Crash Triage.