- Home
- Application Security
- Static Application Security Testing
- Variegate Variegate
Variegate Variegate
Source code diversification tool that creates program variants with diversity

Variegate Variegate
Source code diversification tool that creates program variants with diversity
Variegate Variegate Description
Variegate is a source code diversification tool that addresses IT monoculture vulnerabilities by creating multiple functionally equivalent versions of software with varied attack surfaces. The tool takes an original program and test suite as input and produces a set of program variants that maintain functionality while achieving binary diversity. Variegate operates by applying mutations to source code, ranging from simple code deletions to complex structured refactorings such as variable or function inlining or extraction. The tool validates that mutations do not affect program functionality by verifying that transformed programs behave correctly against the provided test suite. When an extensive test suite is not available, Variegate can be restricted to safe, functionality-preserving mutations that mimic refactoring code changes. This approach creates a population of correct program versions that reduce the risk of widespread exploitation, as malware attacks that succeed on one instance may fail against diversified variants. The tool was developed with support from the Navy, Office of Naval Research, and DARPA under contracts N68335-17-C-0700 and D17PC00096.
Variegate Variegate FAQ
Common questions about Variegate Variegate including features, pricing, alternatives, and user reviews.
Variegate Variegate is Source code diversification tool that creates program variants with diversity developed by GrammaTech. It is a Application Security solution designed to help security teams with Application Security, Binary Security, Code Security.
FEATURED
Cybercrime intelligence tools for searching compromised credentials from infostealers
Password manager with end-to-end encryption and identity protection features
VPN service providing encrypted internet connections and privacy protection
Fractional CISO services for B2B companies to build security programs
Stay Updated with Mandos Brief
Get the latest cybersecurity updates in your inbox
TRENDING CATEGORIES
POPULAR
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
AI security assurance platform for red-teaming, guardrails & compliance
Real-time OSINT monitoring for leaked credentials, data, and infrastructure