---
name: analyze-crash-exploitability
description: Extract bounded, deterministic evidence from crash and sanitizer logs, including signals, sanitizer classes, memory-safety indicators, stack-frame hashes, and source provenance, while reserving exploitability judgment for manual analysis.
metadata:
  domain: evidence-analysis
  subdomain: crash-analysis
  triggers:
    - analyze crash exploitability
    - inspect sanitizer crash log
    - triage memory safety crash
    - crash evidence analysis
    - stack trace fingerprinting
    - reproduce crash evidence
  tags:
    - crash
    - exploitability
    - sanitizer
    - memory-safety
    - stack-trace
    - offline-analysis
  frameworks:
    nist_csf:
      - DE.AE-02
---

# Analyze Crash Exploitability

Use the analyzer to normalize crash evidence, not to label a crash exploitable. Exploitability depends on attacker control, reachable state, mitigations, allocator behavior, process privilege, and reliable influence over control or sensitive data.

## Extract reproducible evidence

Read [references/crash-evidence-method.md](references/crash-evidence-method.md). Stage [scripts/analyze_crash_exploitability.py](scripts/analyze_crash_exploitability.py), [assets/crash-analysis.example.json](assets/crash-analysis.example.json), and [assets/crash-analysis.schema.json](assets/crash-analysis.schema.json). The script snapshots confined regular text logs and emits bounded indicators, sanitizer and signal classes, hashed normalized frames, and source digests under [assets/crash-evidence.schema.json](assets/crash-evidence.schema.json).

Evidence indicators are literal matches in supplied logs. They can prioritize reproduction and debugging but cannot establish attacker control, primitive quality, or exploit reliability. Preserve build identity, input digest, runtime arguments, environment, mitigations, and the unmodified crash artifact separately.

## Decide manually

Reproduce under the same and hardened builds, determine the faulting operation and controlled bytes, trace lifetime and bounds, assess read/write/control effects, and test relevant mitigations. Report the smallest supported primitive and uncertainty, never a score inferred only from a signal or sanitizer label.
