6. Microso[ SDL Verifica>on Guidance
Fuzzing is a requirement of SDL Verifica>on:
“Win32/64/Mac: An Op6mized set of templates must be
used. Template op>miza>on is based on the maximum
amount of code coverage of the parser with the minimum
number of templates. Op6mized templates have been
shown to double fuzzing effec6veness in studies. A
minimum of 500,000 itera6ons, and have fuzzed at least
250,000 itera6ons since the last bug found/fixed that meets
the SDL Bug Bar”
hBps://msdn.microso[.com/en‐us/library/windows/desktop/cc307418.asp