Too afraid to look at the haystack to find the needle? No idea where to start when searching for vulnerabilities? Finding a Bug in 10 lines of code can be hard, but how do you tackle 100000 lines? You experience a feeling of auditors block after executing tar xvz? No fear - this talk will help you find your way through the various labyrinths and disentangle the thread. This talk explains different approaches and strategies on how to audit large code bases for security vulnerabilities with a focus on C code. These will be illustrated with real world security issues from various open source projects such as Unbound, BIND9 and git.