CoreTrace is a Static Application Security Testing product by CoreTrace. Pricing is free.
CoreTrace is an open source security analysis toolchain for C/C++ code that combines static analysis, dynamic analysis, and fuzzing in a single tool built on LLVM. The static analysis component detects vulnerabilities such as buffer overflows and use-after-free without executing code, using specialized analyzer modules for stack issues, concurrency problems, and binary analysis of PE and ELF formats. The dynamic analysis component uses instrumented execution to track memory allocations, bounds, race conditions, and other runtime bugs. The fuzzing component generates automated test cases using coverage-guided fuzzing integrated with AFL++ and LibFuzzer to discover edge cases. Results are output as detailed reports including stack traces, fix suggestions, and CVSS scoring, and can be exported in JSON, XML, HTML, or SARIF formats. CoreTrace is distributed as a command-line interface with additional interfaces under development, including a desktop GUI, a VS Code extension, and a web platform. It integrates into CI/CD pipelines through plugins for GitHub Actions, GitLab CI, and Jenkins, and can block pull requests containing critical vulnerabilities. A GitHub Actions Marketplace listing (CoreTrace Stack Analyzer) provides stack usage analysis including detection of stack overflows, variable-length arrays, and recursion issues, with SARIF upload to GitHub Code Scanning. The project consists of an organization of over 20 repositories covering the core CLI orchestrator, a Clang-based compiler wrapper, specialized analyzers, developer tool interfaces, and shared libraries.
Common questions about CoreTrace including features, pricing, alternatives, and user reviews.
CoreTrace is Open source static/dynamic analysis and fuzzing toolchain for C/C++ code, developed by CoreTrace. It is a Application Security solution designed to help security teams with Sast, Fuzzing, CI/CD.
CoreTrace is built for security teams handling Sast, Fuzzing, CI/CD, C2. Teams typically adopt CoreTrace when they need to application security capabilities integrated into their existing stack. Explore similar tools at https://cybersectools.com/alternatives/coretrace
CoreTrace is a free Application Security tool. This makes it accessible for organizations of all sizes, from startups to enterprises. Visit https://coretrace.fr/ for download and installation instructions.
Popular alternatives to CoreTrace include:
Compare all CoreTrace alternatives at https://cybersectools.com/alternatives/coretrace
CoreTrace is for security teams and organizations that need Sast, Fuzzing, CI/CD, C2, Vulnerability. It's particularly suitable for small to medium-sized teams looking for cost-effective solutions. Other Application Security tools can be found at https://cybersectools.com/categories/application-security
Head-to-head feature, pricing, and rating breakdowns.
AI-powered static and formal-verification security scanner for smart contracts
AI platform for automated code review, security risk detection across the SDLC.