Skip to content
@trailofbits

Trail of Bits

More code: binary lifters @lifting-bits, blockchain @crytic, forks @trail-of-forks
The Trail of Bits logo

Since 2012, Trail of Bits has helped secure some of the world's most targeted organizations and devices.

We combine high-end security research with a real-world attacker mentality to reduce risk and fortify code.

Some of our work:


Pinned Loading

  1. publications Public

    Publications from Trail of Bits

    Python 1.6k 197

  2. algo Public

    Set up a personal VPN in the cloud

    Jinja 29.5k 2.3k

  3. fickling Public

    A Python pickling decompiler and static analyzer

    Python 525 56

  4. vscode-weaudit Public

    Create code bookmarks and code highlights with a click.

    TypeScript 204 21

  5. semgrep-rules Public

    Semgrep queries developed by Trail of Bits.

    Go 416 42

  6. codeql-queries Public

    CodeQL queries developed by Trail of Bits

    CodeQL 104 4

Repositories

Showing 10 of 220 repositories
  • dylint Public

    Run Rust lints from dynamic libraries

    Rust 477 Apache-2.0 45 44 (1 issue needs help) 9 Updated Jul 12, 2025
  • publications Public

    Publications from Trail of Bits

    Python 1,618 CC-BY-SA-4.0 197 3 4 Updated Jul 11, 2025
  • instafix-llvm Public Forked from llvm/llvm-project

    LLVM fork for INSTAFIX

    LLVM 2 14,692 0 2 Updated Jul 11, 2025
  • deptective Public

    Deptective automatically determines the native dependencies required to run any arbitrary program or command.

    Python 65 LGPL-3.0 0 1 0 Updated Jul 9, 2025
  • sleepy-pickle-public Public

    AI model compromise through malicious pickle files

    Python 0 MIT 0 0 3 Updated Jul 8, 2025
  • necessist Public

    A mutation-based tool for finding bugs in tests

    Rust 120 AGPL-3.0 17 17 0 Updated Jul 8, 2025
  • fickling Public

    A Python pickling decompiler and static analyzer

    Python 525 LGPL-3.0 56 15 (1 issue needs help) 5 Updated Jul 8, 2025
  • windows-ctl Public

    Rust libraries and utilities for parsing Windows Certificate Trust Lists

    Rust 9 Apache-2.0 2 0 1 Updated Jul 7, 2025
  • anchor-coverage Public

    A wrapper around `anchor test` for computing test coverage

    Rust 4 AGPL-3.0 2 2 4 Updated Jul 7, 2025
  • sigstore-rekor-types Public

    Python models for Rekor's API types

    Python 6 Apache-2.0 2 1 5 Updated Jul 7, 2025