Pickle
Python's `pickle` module serializes Python objects to bytes and deserializes them back. It supports almost any Python object but has security implications for untrusted data. The guide walks through Pickling & Unpickling, Protocol Versions, Pickle Security Warning, Custom Object Serialization. `pickle.dumps(obj)` serializes an object to bytes. `pickle.loads(data)` deserializes bytes back to an object. `pickle.dump(obj, file)` writes to a file opened in binary mode. `pickle.load(file)` reads from a binary file. Supports: integers, floats, strings, lists, dicts, tuples, sets, classes, functions (by reference), and custom objects. Complex objects like open files, network connections, and generators cannot be pickled. Pickle has multiple protocol versions: 0 (ASCII, readable but inefficient), 1 (binary, old format), 2 (Python 2.3, supports new-style classes), 3 (Python 3.0, supports bytes), 4 (Python 3.4, supports large objects), 5 (Python 3.8, out-of-band data). Specify protocol with `pickle.dumps(obj, protocol=4)`. The default protocol depends on Python version — use `protocol=pickle.HIGHEST_PROTOCOL` for the best performance. NEVER unpickle data from untrusted sources. Pickle can execute arbitrary code during deserialization because it reconstructs objects by calling `__reduce__()` methods. Attackers can craft malicious pickle payloads that execute system commands. Alternatives for trusted data only: JSON, MessagePack, Protobuf, or `pickle` with restricted unpickler. Use `pickle.Unpickler.find_class` override to restrict allowed classes in legacy code.