RESOURCE HUB
RECENT WORK
Trail of Bits Testing Handbook
The Testing Handbook is a resource that guides developers and security professionals in configuring, optimizing, and automating many of the static and dynamic analysis tools we use.
Scroll zstd Compression
Effort Level: 9
MLSecOps March 20: Supply chain security
William Woodruff
MLIR is the future of program analysis
Peter Goodman
IN THE NEWS
How Bloomberg News Vetted the Jeffrey Epstein Emails
New Electron Flaw Allows Backdooring Signal, 1Password, and Slack
In Conversation: Learnings for CISOs Post Black Hat and DEF CON
AI Chatbot Users Beware: Hackers Hide Malware in LLM Images
Hackers can hide AI prompt injection attacks in resized images
SECURITY REVIEWS
VIEW MORE PUBLIC REPORTSYOLOv7 Threat Model and Code Review
EleutherAI, Hugging Face, & Stability AI SafeTensors Library
Scroll zstd Compression
Iron Fish FishHash
Scroll ZkEVM 4844 Blob
Ockam
Aleo snarkVM, snarkOS, BullsharkBFT
Scroll ZkEVM Wave 3
ACADEMIC PAPERS
VIEW ALL OF OUR PAPERSVAST: MLIR compiler for C/C++
PoTATo: Points-to analysis via domain specific MLIR dialect
Weak Fiat-Shamir Attacks on Modern Proof Systems
CONFERENCE PRESENTATIONS
WATCH MORE RECORDED TALKSDetecting variability bugs with hybrid control and data flow
MLIR is the future of program analysis
Differential analysis of x86-64 instruction decoders
How to find bugs when (ground) truth isn't real
The Treachery of Files and Two New Tools that Tame It
Symbolically Executing a Fuzzy Tyrant
Kernel space fault injection with KRF
MLSecOps March 20
Risky Biz 707
ASW 229
Risky Biz 690
Risky Biz 672
Cloud Security Reinvented
Skiff Office Hours
Risky Biz 652
GUIDES AND HANDBOOKS
SEE OUR COMPLETE LIST OF HANDBOOKSLearn about Trail of Bits' commitment to vulnerability disclosure, including our 90+30 day disclosure timeline and coordination process with vendors.
Vulnerability Disclosure Policy
The automated testing handbook is a resource that guides developers and security professionals in configuring, optimizing, and automating many of the static and dynamic analysis tools we use.
Trail of Bits Testing Handbook
ZKDocs provides comprehensive, detailed, and interactive documentation on zero-knowledge proof systems and related primitives.
ZKDocs
Guidelines and best practices for developing secure smart contracts.
Building Secure Smart Contracts
Our field guide to winning at Capture The Flag (CTF).
CTF Field Guide
Our field guide for practical Ruby security.