about summary refs log tree commit diff
path: root/custom_mutators/symqemu/README.md
diff options
context:
space:
mode:
Diffstat (limited to 'custom_mutators/symqemu/README.md')
-rw-r--r--custom_mutators/symqemu/README.md10
1 files changed, 9 insertions, 1 deletions
diff --git a/custom_mutators/symqemu/README.md b/custom_mutators/symqemu/README.md
index b7702c06..c3071afc 100644
--- a/custom_mutators/symqemu/README.md
+++ b/custom_mutators/symqemu/README.md
@@ -2,10 +2,18 @@
 
 This uses the symcc to find new paths into the target.
 
+## How to build and use
+
 To use this custom mutator follow the steps in the symqemu repository 
 [https://github.com/eurecom-s3/symqemu/](https://github.com/eurecom-s3/symqemu/) 
 on how to build symqemu-x86_x64 and put it in your `PATH`.
 
-just type `make` to build this custom mutator.
+Just type `make` to build this custom mutator.
 
 ```AFL_CUSTOM_MUTATOR_LIBRARY=custom_mutators/symqemu/symqemu-mutator.so AFL_DISABLE_TRIM=1 afl-fuzz ...```
+
+## Options
+
+`SYMQEMU_ALL=1` - use concolic solving on **all** queue items, not only interesting/favorite ones.
+
+`SYMQEMU_LATE=1` - use concolic solving only after there have been no finds for 5 minutes.