Skip to content
@trailofbits

Trail of Bits

More code: binary lifters @lifting-bits, blockchain @crytic, forks @trail-of-forks
The Trail of Bits logo

Since 2012, Trail of Bits has helped secure some of the world's most targeted organizations and devices.

We combine high-end security research with a real-world attacker mentality to reduce risk and fortify code.

Some of our work:


Pinned Loading

  1. publications publications Public

    Publications from Trail of Bits

    Python 1.7k 211

  2. algo algo Public

    Set up a personal VPN in the cloud

    Python 30.2k 2.4k

  3. fickling fickling Public

    A Python pickling decompiler and static analyzer

    Python 597 65

  4. vscode-weaudit vscode-weaudit Public

    Create code bookmarks and code highlights with a click.

    TypeScript 223 27

  5. semgrep-rules semgrep-rules Public

    Semgrep queries developed by Trail of Bits.

    Go 465 46

  6. codeql-queries codeql-queries Public

    CodeQL queries developed by Trail of Bits

    CodeQL 138 7

Repositories

Showing 10 of 250 repositories
  • anamorpher Public

    image scaling attacks for multi-modal prompt injection

    trailofbits/anamorpher’s past year of commit activity
    Python 1,016 Apache-2.0 88 2 1 Updated Jan 14, 2026
  • algo Public

    Set up a personal VPN in the cloud

    trailofbits/algo’s past year of commit activity
    Python 30,234 AGPL-3.0 2,354 65 3 Updated Jan 14, 2026
  • vendetect Public

    A tool to automatically detect copy+pasted and vendored code between repositories

    trailofbits/vendetect’s past year of commit activity
    Python 74 AGPL-3.0 6 2 3 Updated Jan 14, 2026
  • elaborate Public

    Wrappers for standard library functions and types to produce more elaborate error messages

    trailofbits/elaborate’s past year of commit activity
    Rust 4 1 2 1 Updated Jan 14, 2026
  • rfc3161-client Public

    An Opinionated Python RFC3161 Client

    trailofbits/rfc3161-client’s past year of commit activity
    Rust 4 Apache-2.0 4 2 1 Updated Jan 14, 2026
  • cookiecutter-python Public

    A cookiecutter template for a best-practices Python project

    trailofbits/cookiecutter-python’s past year of commit activity
    Python 22 Apache-2.0 7 0 1 Updated Jan 13, 2026
  • pylock-attestations Public

    CLI tool to add attestation identities to `pylock.toml` files

    trailofbits/pylock-attestations’s past year of commit activity
    Python 5 Apache-2.0 1 4 0 Updated Jan 13, 2026
  • pajaMAS Public

    Multi-agent system (MAS) hijacking demos

    trailofbits/pajaMAS’s past year of commit activity
    Python 39 Apache-2.0 3 3 6 Updated Jan 13, 2026
  • mrva Public

    A terminal-first approach to CodeQL multi-repo variant analysis

    trailofbits/mrva’s past year of commit activity
    Python 10 AGPL-3.0 0 1 1 Updated Jan 13, 2026
  • sleepy-pickle-public Public

    AI model compromise through malicious pickle files

    trailofbits/sleepy-pickle-public’s past year of commit activity
    Python 0 MIT 1 0 8 Updated Jan 13, 2026