A VMware image containg our software for trace-based vulnerability analysis is now available for download. The image has been tested with VMware Workstation 6.5 and VMware Player 3.1 (the latter can be downloaded free of charge from VMware). It can also be converted for use with VirtualBox or QEMU. Uncompressed, the image requires about 5GB of disk space. It is based on Ubuntu 10.04; the default user account is "bh2010" with password "bh2010". It includes example traces from an Adobe Reader crash, plus binary versions of TEMU, Traecap, alloc_reader, tracealign, tracedump, trace_reader, valset_ir, x86_slicer, and supporting programs and scripts. See the README.TXT file inside the distribution for more information.

bh2010.tar.bz2 (1.5G)

We had previously also linked here to a demo of an IDA Pro "Taint Tracker" plugin for viewing taint traces, a BitBlaze-related tool made available in a free demo version by Ensighta Security. However because of business changes at Ensighta that tool is not currently available for download here. (49MB)

Acknowledgement and Citation

To acknowledge the use of the downloaded software, please include both of the following two citations:
Mailing List and Contact

Though we are not providing formal support for Vine at this time, we would like to hear if you are making use of it, if you run into any bugs or problems, or if you have suggestions for feature additions. Please subscribe to the bitblaze-users mailing list (via Google Groups) and share your experiences.

For general questions regarding the BitBlaze project, please send email to bitblaze at

To receive announcements about code releases and other bitblaze related updates, please subscribe to the Bitblaze Announcement List

