Skip to content
@trailofbits

Trail of Bits

More code: binary lifters @lifting-bits, blockchain @crytic, forks @trail-of-forks
The Trail of Bits logo

Since 2012, Trail of Bits has helped secure some of the world's most targeted organizations and devices.

We combine high-end security research with a real-world attacker mentality to reduce risk and fortify code.

Some of our work:


Pinned Loading

  1. publications publications Public

    Publications from Trail of Bits

    Python 1.7k 210

  2. algo algo Public

    Set up a personal VPN in the cloud

    Python 30.2k 2.4k

  3. fickling fickling Public

    A Python pickling decompiler and static analyzer

    Python 597 65

  4. vscode-weaudit vscode-weaudit Public

    Create code bookmarks and code highlights with a click.

    TypeScript 223 26

  5. semgrep-rules semgrep-rules Public

    Semgrep queries developed by Trail of Bits.

    Go 465 46

  6. codeql-queries codeql-queries Public

    CodeQL queries developed by Trail of Bits

    CodeQL 139 7

Repositories

Showing 10 of 249 repositories
  • instafix-llvm Public Forked from llvm/llvm-project

    LLVM fork for INSTAFIX

    trailofbits/instafix-llvm’s past year of commit activity
    LLVM 3 15,991 0 5 Updated Jan 11, 2026
  • build-wrap Public

    Help protect against malicious build scripts

    trailofbits/build-wrap’s past year of commit activity
    Rust 22 AGPL-3.0 4 2 1 Updated Jan 10, 2026
  • test-fuzz Public

    To make fuzzing Rust easy

    trailofbits/test-fuzz’s past year of commit activity
    Rust 193 AGPL-3.0 24 14 2 Updated Jan 10, 2026
  • cargo-unmaintained Public

    Find unmaintained packages in Rust projects

    trailofbits/cargo-unmaintained’s past year of commit activity
    Rust 83 AGPL-3.0 13 11 0 Updated Jan 10, 2026
  • necessist Public

    A mutation-based tool for finding bugs in tests

    trailofbits/necessist’s past year of commit activity
    Rust 129 AGPL-3.0 18 17 7 Updated Jan 10, 2026
  • dylint Public

    Run Rust lints from dynamic libraries

    trailofbits/dylint’s past year of commit activity
    Rust 521 Apache-2.0 49 44 (1 issue needs help) 8 Updated Jan 10, 2026
  • fickling Public

    A Python pickling decompiler and static analyzer

    trailofbits/fickling’s past year of commit activity
    Python 597 LGPL-3.0 65 15 4 Updated Jan 9, 2026
  • sleepy-pickle-public Public

    AI model compromise through malicious pickle files

    trailofbits/sleepy-pickle-public’s past year of commit activity
    Python 0 MIT 1 0 8 Updated Jan 9, 2026
  • testing-handbook Public

    Trail of Bits Testing Handbook - appsec.guide

    trailofbits/testing-handbook’s past year of commit activity
    Rust 89 CC-BY-4.0 17 15 (3 issues need help) 2 Updated Jan 9, 2026
  • buttercup Public

    Buttercup finds and patches software vulnerabilities

    trailofbits/buttercup’s past year of commit activity
    Python 1,428 AGPL-3.0 158 52 8 Updated Jan 9, 2026