Skip to content
@trailofbits

Trail of Bits

More code: binary lifters @lifting-bits, blockchain @crytic, forks @trail-of-forks
The Trail of Bits logo

Since 2012, Trail of Bits has helped secure some of the world's most targeted organizations and devices.

We combine high-end security research with a real-world attacker mentality to reduce risk and fortify code.

Some of our work:


Pinned Loading

  1. publications publications Public

    Publications from Trail of Bits

    Python 1.5k 184

  2. algo algo Public

    Set up a personal VPN in the cloud

    Jinja 29.1k 2.3k

  3. fickling fickling Public

    A Python pickling decompiler and static analyzer

    Python 423 50

  4. vscode-weaudit vscode-weaudit Public

    Create code bookmarks and code highlights with a click.

    TypeScript 180 17

  5. semgrep-rules semgrep-rules Public

    Semgrep queries developed by Trail of Bits.

    Go 349 35

  6. codeql-queries codeql-queries Public

    CodeQL queries developed by Trail of Bits

    CodeQL 81 3

Repositories

Showing 10 of 200 repositories
  • build-wrap Public

    Help protect against malicious build scripts

    trailofbits/build-wrap’s past year of commit activity
    Rust 7 AGPL-3.0 3 0 1 Updated Dec 14, 2024
  • polytracker Public

    An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

    trailofbits/polytracker’s past year of commit activity
    C++ 537 Apache-2.0 45 45 (2 issues need help) 1 Updated Dec 13, 2024
  • pip-plugin-pep740 Public

    An implementation of a pip plugin that verifies PEP-740 attestations before installing a package, and aborts the installation if verification fails.

    trailofbits/pip-plugin-pep740’s past year of commit activity
    Python 0 Apache-2.0 0 1 1 Updated Dec 13, 2024
  • it-depends Public

    A tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositories.

    trailofbits/it-depends’s past year of commit activity
    Python 334 LGPL-3.0 20 24 0 Updated Dec 12, 2024
  • publications Public

    Publications from Trail of Bits

    trailofbits/publications’s past year of commit activity
    Python 1,495 CC-BY-SA-4.0 184 4 2 Updated Dec 12, 2024
  • test-fuzz Public

    To make fuzzing Rust easy

    trailofbits/test-fuzz’s past year of commit activity
    Rust 163 AGPL-3.0 16 11 (1 issue needs help) 2 Updated Dec 12, 2024
  • rfc3161-client Public

    An Opinionated Python RFC3161 Client

    trailofbits/rfc3161-client’s past year of commit activity
    Rust 2 Apache-2.0 0 1 0 Updated Dec 11, 2024
  • ruzzy Public

    A coverage-guided fuzzer for pure Ruby code and Ruby C extensions

    trailofbits/ruzzy’s past year of commit activity
    Ruby 90 AGPL-3.0 6 10 0 Updated Dec 11, 2024
  • pypi-attestations Public

    A library to convert between Sigstore Bundles and PEP 740 Attestation objects

    trailofbits/pypi-attestations’s past year of commit activity
    Python 4 Apache-2.0 2 3 0 Updated Dec 11, 2024
  • semgrep-rules Public

    Semgrep queries developed by Trail of Bits.

    trailofbits/semgrep-rules’s past year of commit activity
    Go 349 AGPL-3.0 35 7 3 Updated Dec 11, 2024