Skip to content
@trailofbits

Trail of Bits

More code: binary lifters @lifting-bits, blockchain @crytic, forks @trail-of-forks
The Trail of Bits logo

Since 2012, Trail of Bits has helped secure some of the world's most targeted organizations and devices.

We combine high-end security research with a real-world attacker mentality to reduce risk and fortify code.

Some of our work:


Pinned Loading

  1. publications publications Public

    Publications from Trail of Bits

    Python 1.7k 211

  2. algo algo Public

    Set up a personal VPN in the cloud

    Python 30.2k 2.4k

  3. fickling fickling Public

    A Python pickling decompiler and static analyzer

    Python 597 65

  4. vscode-weaudit vscode-weaudit Public

    Create code bookmarks and code highlights with a click.

    TypeScript 223 27

  5. semgrep-rules semgrep-rules Public

    Semgrep queries developed by Trail of Bits.

    Go 466 46

  6. codeql-queries codeql-queries Public

    CodeQL queries developed by Trail of Bits

    CodeQL 138 7

Repositories

Showing 10 of 251 repositories
  • skills Public

    Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

    trailofbits/skills’s past year of commit activity
    Python 3 CC-BY-SA-4.0 0 1 0 Updated Jan 14, 2026
  • buttercup Public

    Buttercup finds and patches software vulnerabilities

    trailofbits/buttercup’s past year of commit activity
    Python 1,432 AGPL-3.0 159 52 8 Updated Jan 14, 2026
  • rfc3161-client Public

    An Opinionated Python RFC3161 Client

    trailofbits/rfc3161-client’s past year of commit activity
    Rust 4 Apache-2.0 4 2 2 Updated Jan 14, 2026
  • it-depends Public

    A tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositories.

    trailofbits/it-depends’s past year of commit activity
    Python 381 LGPL-3.0 22 14 4 Updated Jan 14, 2026
  • anamorpher Public

    image scaling attacks for multi-modal prompt injection

    trailofbits/anamorpher’s past year of commit activity
    Python 1,016 Apache-2.0 88 2 0 Updated Jan 14, 2026
  • algo Public

    Set up a personal VPN in the cloud

    trailofbits/algo’s past year of commit activity
    Python 30,235 AGPL-3.0 2,354 65 2 Updated Jan 14, 2026
  • dylint Public

    Run Rust lints from dynamic libraries

    trailofbits/dylint’s past year of commit activity
    Rust 522 Apache-2.0 49 45 (1 issue needs help) 8 Updated Jan 14, 2026
  • cargo-unmaintained Public

    Find unmaintained packages in Rust projects

    trailofbits/cargo-unmaintained’s past year of commit activity
    Rust 83 AGPL-3.0 13 11 1 Updated Jan 14, 2026
  • test-fuzz Public

    To make fuzzing Rust easy

    trailofbits/test-fuzz’s past year of commit activity
    Rust 194 AGPL-3.0 24 14 2 Updated Jan 14, 2026
  • vendetect Public

    A tool to automatically detect copy+pasted and vendored code between repositories

    trailofbits/vendetect’s past year of commit activity
    Python 74 AGPL-3.0 6 2 2 Updated Jan 14, 2026