Our group is interested in theautomatic discovery of security flaws in software systems at the very large scale. Some of us work on the foundations of automatic vulnerability discovery and program analysis in general. For instance, we seek to identify fundamental limitations of existing techniques, we study empiricalmethods (incl. statistical and causal reasoning) for program analysis, and we explore the assurances that software testing provides when no bugsare found. Another part of our group develops practical vulnerability discovery tools that are widely used in software security practice. For instance, Entropic is the default power schedule in LibFuzzer which powers the largest fuzzing platforms at Google and Microsoft, fuzzing hundreds of security-critical projects on 100k machines 24/7. Our tools have discovered 100+ bugs in widely-used software systems, more than 70 of which aresecurity-critical vulnerabilities registered as CVEs at the US National Vulnerability Database. To find out more about the research in our group, headover to https://mpi-softsec.github.io .