Skip to content
@trailofbits

Trail of Bits

More code: binary lifters @lifting-bits, blockchain @crytic, forks @trail-of-forks
The Trail of Bits logo

Since 2012, Trail of Bits has helped secure some of the world's most targeted organizations and devices.

We combine high-end security research with a real-world attacker mentality to reduce risk and fortify code.

Some of our work:


Pinned Loading

  1. publications Public

    Publications from Trail of Bits

    Python 1.5k 187

  2. algo Public

    Set up a personal VPN in the cloud

    Jinja 29.3k 2.3k

  3. fickling Public

    A Python pickling decompiler and static analyzer

    Python 485 53

  4. vscode-weaudit Public

    Create code bookmarks and code highlights with a click.

    TypeScript 194 19

  5. semgrep-rules Public

    Semgrep queries developed by Trail of Bits.

    Go 392 40

  6. codeql-queries Public

    CodeQL queries developed by Trail of Bits

    CodeQL 89 4

Repositories

Showing 10 of 204 repositories
  • dylint Public

    Run Rust lints from dynamic libraries

    Rust 436 Apache-2.0 29 24 (1 issue needs help) 8 Updated Mar 31, 2025
  • necessist Public

    A mutation-based tool for finding bugs in tests

    Rust 115 AGPL-3.0 12 17 4 Updated Mar 31, 2025
  • cargo-unmaintained Public

    Find unmaintained packages in Rust projects

    Rust 70 AGPL-3.0 7 8 0 Updated Mar 31, 2025
  • sigstore-rekor-types Public

    Python models for Rekor's API types

    Python 5 Apache-2.0 1 0 2 Updated Mar 31, 2025
  • pypi-attestations Public

    A library to convert between Sigstore Bundles and PEP 740 Attestation objects

    Python 4 Apache-2.0 4 3 0 Updated Mar 30, 2025
  • instafix-llvm Public Forked from llvm/llvm-project

    LLVM fork for INSTAFIX

    LLVM 0 13,313 0 10 Updated Mar 29, 2025
  • emit-lsp Public Forked from llvm/llvm-project

    The LLVM Project is a collection of modular and reusable compiler and toolchain technologies.

    LLVM 0 13,310 0 2 Updated Mar 28, 2025
  • vscode-sarif-explorer Public

    SARIF Explorer: A VSCode extension that helps you visualize and triage static analysis results

    TypeScript 22 GPL-3.0 3 5 (1 issue needs help) 2 Updated Mar 28, 2025
  • semgrep-rules Public

    Semgrep queries developed by Trail of Bits.

    Go 392 AGPL-3.0 40 7 2 Updated Mar 28, 2025
  • vast Public

    VAST is an experimental compiler pipeline designed for program analysis of C and C++. It provides a tower of IRs as MLIR dialects to choose the best fit representations for a program analysis or further program abstraction.

    C++ 411 Apache-2.0 26 168 (19 issues need help) 3 Updated Mar 27, 2025