Skip to content
@trailofbits

Trail of Bits

More code: binary lifters @lifting-bits, blockchain @crytic, forks @trail-of-forks
The Trail of Bits logo

Since 2012, Trail of Bits has helped secure some of the world's most targeted organizations and devices.

We combine high-end security research with a real-world attacker mentality to reduce risk and fortify code.

Some of our work:


Pinned Loading

  1. publications publications Public

    Publications from Trail of Bits

    Python 1.6k 189

  2. algo algo Public

    Set up a personal VPN in the cloud

    Jinja 29.3k 2.3k

  3. fickling fickling Public

    A Python pickling decompiler and static analyzer

    Python 493 53

  4. vscode-weaudit vscode-weaudit Public

    Create code bookmarks and code highlights with a click.

    TypeScript 197 19

  5. semgrep-rules semgrep-rules Public

    Semgrep queries developed by Trail of Bits.

    Go 399 41

  6. codeql-queries codeql-queries Public

    CodeQL queries developed by Trail of Bits

    CodeQL 97 4

Repositories

Showing 10 of 213 repositories
  • check-up-to-dateness Public

    Check whether a merge group PR is up to date relative to its base branch

    trailofbits/check-up-to-dateness’s past year of commit activity
    Shell 0 1 0 2 Updated Apr 26, 2025
  • cookiecutter-python Public

    A cookiecutter template for a best-practices Python project

    trailofbits/cookiecutter-python’s past year of commit activity
    Python 16 Apache-2.0 5 0 5 Updated Apr 25, 2025
  • publications Public

    Publications from Trail of Bits

    trailofbits/publications’s past year of commit activity
    Python 1,562 CC-BY-SA-4.0 189 4 3 Updated Apr 25, 2025
  • dylint Public

    Run Rust lints from dynamic libraries

    trailofbits/dylint’s past year of commit activity
    Rust 445 Apache-2.0 36 40 (1 issue needs help) 13 Updated Apr 25, 2025
  • pypi-attestations Public

    A library to convert between Sigstore Bundles and PEP 740 Attestation objects

    trailofbits/pypi-attestations’s past year of commit activity
    Python 7 Apache-2.0 5 5 0 Updated Apr 25, 2025
  • pip-plugin-pep740 Public

    An implementation of a pip plugin that verifies PEP-740 attestations before installing a package, and aborts the installation if verification fails.

    trailofbits/pip-plugin-pep740’s past year of commit activity
    Python 1 Apache-2.0 0 1 2 Updated Apr 25, 2025
  • trailofbits/awesome-ml-security’s past year of commit activity
    128 CC-BY-4.0 16 1 1 Updated Apr 25, 2025
  • test-fuzz Public

    To make fuzzing Rust easy

    trailofbits/test-fuzz’s past year of commit activity
    Rust 177 AGPL-3.0 24 12 3 Updated Apr 25, 2025
  • rfc3161-client Public

    An Opinionated Python RFC3161 Client

    trailofbits/rfc3161-client’s past year of commit activity
    Rust 2 Apache-2.0 2 2 0 Updated Apr 25, 2025
  • trailofbits/gh-action-adapt-sigstore-pypi’s past year of commit activity
    Python 1 Apache-2.0 0 0 2 Updated Apr 24, 2025