Skip to content
@trailofbits

Trail of Bits

More code: binary lifters @lifting-bits, blockchain @crytic, forks @trail-of-forks
The Trail of Bits logo

Since 2012, Trail of Bits has helped secure some of the world's most targeted organizations and devices.

We combine high-end security research with a real-world attacker mentality to reduce risk and fortify code.

Some of our work:


Pinned Loading

  1. publications publications Public

    Publications from Trail of Bits

    Python 1.6k 201

  2. algo algo Public

    Set up a personal VPN in the cloud

    Python 29.7k 2.4k

  3. fickling fickling Public

    A Python pickling decompiler and static analyzer

    Python 546 61

  4. vscode-weaudit vscode-weaudit Public

    Create code bookmarks and code highlights with a click.

    TypeScript 212 22

  5. semgrep-rules semgrep-rules Public

    Semgrep queries developed by Trail of Bits.

    Go 432 46

  6. codeql-queries codeql-queries Public

    CodeQL queries developed by Trail of Bits

    CodeQL 113 6

Repositories

Showing 10 of 235 repositories
  • cookiecutter-python Public

    A cookiecutter template for a best-practices Python project

    trailofbits/cookiecutter-python’s past year of commit activity
    Python 19 Apache-2.0 6 0 3 Updated Sep 1, 2025
  • buttercup Public

    Buttercup finds and patches software vulnerabilities

    trailofbits/buttercup’s past year of commit activity
    Python 1,173 AGPL-3.0 119 33 6 Updated Sep 1, 2025
  • elaborate Public

    Wrappers for standard library functions and types to produce more elaborate error messages

    trailofbits/elaborate’s past year of commit activity
    Rust 2 1 1 0 Updated Sep 1, 2025
  • dylint Public

    Run Rust lints from dynamic libraries

    trailofbits/dylint’s past year of commit activity
    Rust 494 Apache-2.0 44 46 (1 issue needs help) 10 Updated Sep 1, 2025
  • necessist Public

    A mutation-based tool for finding bugs in tests

    trailofbits/necessist’s past year of commit activity
    Rust 124 AGPL-3.0 20 17 2 Updated Sep 1, 2025
  • sigstore-rekor-types Public

    Python models for Rekor's API types

    trailofbits/sigstore-rekor-types’s past year of commit activity
    Python 6 Apache-2.0 3 1 9 Updated Sep 1, 2025
  • pypi-attestations Public

    A library to convert between Sigstore Bundles and PEP 740 Attestation objects

    trailofbits/pypi-attestations’s past year of commit activity
    Python 9 Apache-2.0 6 7 2 Updated Sep 1, 2025
  • go-panikint Public Forked from golang/go

    It's the Go compiler, but it panics on arithmetic and truncation issues.

    trailofbits/go-panikint’s past year of commit activity
    Go 5 BSD-3-Clause 19,378 1 0 Updated Sep 1, 2025
  • go-fuzz-utils Public
    trailofbits/go-fuzz-utils’s past year of commit activity
    Go 20 AGPL-3.0 3 1 1 Updated Aug 30, 2025
  • rfc8785.py Public

    A pure-Python implementation of RFC8785 (JSON Canonicalization Scheme)

    trailofbits/rfc8785.py’s past year of commit activity
    Python 5 Apache-2.0 2 0 0 Updated Aug 30, 2025