HTTP/2 200
date: Thu, 31 Jul 2025 12:40:59 GMT
content-type: text/html; charset=utf-8
vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With,Accept-Encoding, Accept, X-Requested-With
etag: W/"b651c81665a4dd68bc81977df0d47936"
cache-control: max-age=0, private, must-revalidate
strict-transport-security: max-age=31536000; includeSubdomains; preload
x-frame-options: deny
x-content-type-options: nosniff
x-xss-protection: 0
referrer-policy: origin-when-cross-origin, strict-origin-when-cross-origin
content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net/ productionresultssa1.blob.core.windows.net/ productionresultssa2.blob.core.windows.net/ productionresultssa3.blob.core.windows.net/ productionresultssa4.blob.core.windows.net/ productionresultssa5.blob.core.windows.net/ productionresultssa6.blob.core.windows.net/ productionresultssa7.blob.core.windows.net/ productionresultssa8.blob.core.windows.net/ productionresultssa9.blob.core.windows.net/ productionresultssa10.blob.core.windows.net/ productionresultssa11.blob.core.windows.net/ productionresultssa12.blob.core.windows.net/ productionresultssa13.blob.core.windows.net/ productionresultssa14.blob.core.windows.net/ productionresultssa15.blob.core.windows.net/ productionresultssa16.blob.core.windows.net/ productionresultssa17.blob.core.windows.net/ productionresultssa18.blob.core.windows.net/ productionresultssa19.blob.core.windows.net/ github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com/ user-images.githubusercontent.com/ private-user-images.githubusercontent.com opengraph.githubassets.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com/ secured-user-images.githubusercontent.com/ private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
server: github.com
content-encoding: gzip
accept-ranges: bytes
set-cookie: _gh_sess=5UGj8%2Bxw6stQSCk%2BWFH1yD%2FMF2QrEpsdCTnOz7ae6W3kLzgsVJBveIDtVJ1iO6lMzSg6uBmnLvkTRPm91ryb%2FcwrYFnxPfgnRoBSn%2Fdm3pjIg%2BOq%2Fqw0fH6XMS%2FkJeDMQ8skDNEeb4q%2FJC38g%2B46fKc9XOyztc%2FX4xDeVt%2FK3WaVCqcCH7FXpvzMoysrEIZ%2Bkv%2B6sGLqf9v1vsMpD8lzJvIvraL3THH6593hHazoF33QGwAsEhEu3AWUXlxBwCYcD9SMtfW3V6f2RGWOt1s5bA%3D%3D--ytdmMnH94tArzt%2B8--g4%2B8PnbRVhcIQTi8%2BBffpA%3D%3D; Path=/; HttpOnly; Secure; SameSite=Lax
set-cookie: _octo=GH1.1.1275296656.1753965659; Path=/; Domain=github.com; Expires=Fri, 31 Jul 2026 12:40:59 GMT; Secure; SameSite=Lax
set-cookie: logged_in=no; Path=/; Domain=github.com; Expires=Fri, 31 Jul 2026 12:40:59 GMT; HttpOnly; Secure; SameSite=Lax
x-github-request-id: C25A:FA5FC:A42FF3:C2ED0C:688B645B
Trail of Bits · GitHub
Trail of Bits
Verified
We've verified that the organization trailofbits controls the domains:
www.trailofbits.com
trailofbits.com
Since 2012, Trail of Bits has helped secure some of the world's most targeted
organizations and devices.
We combine high-end security research with a
real-world attacker mentality to reduce risk and fortify code.
Some of our work:
Pinned
Loading
Publications from Trail of Bits
Python
1.6k
198
Set up a personal VPN in the cloud
Jinja
29.6k
2.3k
A Python pickling decompiler and static analyzer
Python
530
57
Create code bookmarks and code highlights with a click.
TypeScript
204
21
Semgrep queries developed by Trail of Bits.
Go
418
42
CodeQL queries developed by Trail of Bits
CodeQL
106
5
Repositories
Showing 10 of 226 repositories
pajaMAS
Public
Multi-agent system (MAS) hijacking demos
trailofbits/pajaMAS’s past year of commit activity
Python
2
Apache-2.0
0
2
0
Updated Jul 30, 2025
trailofbits/mcp-context-protector’s past year of commit activity
Python
72
Apache-2.0
1
1
3
Updated Jul 30, 2025
trailofbits/instafix-llvm’s past year of commit activity
trailofbits/cookiecutter-python’s past year of commit activity
Python
16
Apache-2.0
6
0
2
Updated Jul 30, 2025
trailofbits/rfc3161-client’s past year of commit activity
Rust
2
Apache-2.0
4
2
0
Updated Jul 29, 2025
siderophile
Public
Find the ideal fuzz targets in a Rust codebase
trailofbits/siderophile’s past year of commit activity
necessist
Public
A mutation-based tool for finding bugs in tests
trailofbits/necessist’s past year of commit activity
Rust
121
AGPL-3.0
17
17
1
Updated Jul 29, 2025
build-wrap
Public
Help protect against malicious build scripts
trailofbits/build-wrap’s past year of commit activity
Rust
13
AGPL-3.0
3
0
4
Updated Jul 28, 2025
vendetect
Public
A tool to automatically detect copy+pasted and vendored code between repositories
trailofbits/vendetect’s past year of commit activity
Python
46
AGPL-3.0
5
1
1
Updated Jul 28, 2025
dylint
Public
Run Rust lints from dynamic libraries
trailofbits/dylint’s past year of commit activity
You can’t perform that action at this time.