March 31 & April 7, 2026
Workshop Series: Inside Cirro
Get a practical look at Cirro with creator Leron Gray, a new open-source tool for modeling Azure and Entra ID environments as relationship graphs to make privilege and attack paths easier to understand.
Past Event: Wednesday, February 18
Building Tools: What, When, and How
Surrounded by security tools but still tempted to “just build it”? This hands-on workshop breaks down when custom tooling is worth it, when it’s not, and how to build fast, focused tools without overengineering.
Past Event: Tuesday, December 9
Sliver Workshop Part 3: Building Better Encoders
In our third Sliver workshop, we explore how Sliver handles traffic encoding by default and how attackers can extend its capabilities with custom Wasm-based encoders. We dive into Sliver’s encoder framework works, what’s possible with WebAssembly, and how to design and test your own encoders.
Past Event: Thursday, October 16
Demystifying 5G Security: Understanding the Registration Protocol
In this hands-on workshop, Senior Security Consultant Drew Jones will break down the fundamentals of the 5G registration protocol, explore where security gaps can emerge, and walk through a live simulated lab demonstrating real-world vulnerabilities.
Past Event: October 1st, 2025
CloudFox: Cloud Enumeration for Penetration Testing
In this session, Mitchell Sperling, Senior Security Consultant at Bishop Fox, will demonstrate how he uses CloudFox during cloud penetration tests to quickly enumerate large cloud environments and identify interesting attack paths.
Past Event: July 9, 2025
Sliver Workshop Part 2: Staging & Automation
In our second workshop, we’ll explore Sliver’s new implant staging process and demonstrate basic CLI automation features. We’ll also walk through Sliver’s supported pivot types for lateral movement, including TCP, and wrap up by exploring automation options using the SliverPy project.
Past Event: May 8, 2025
Sliver Workshop Part 1: Getting Started & 1.6 Features
Watch an interactive Discord workshop led by Bishop Fox Senior Security Consultant, Tim Ghatas, as we dive into Sliver, the open-source C2 framework making waves in Red Team ops.
Past Event: Wednesday, June 26
Come WiFind Me: WiFi & Other RF Surveillance
Join Alissa Gilbert (dnsprincess) as she dispels myths around RF tracking, negates some fears, and gives completely new ones in its place.
Past Event: June, 3rd, 2025
Patch Perfect: Harmonizing with LLMs to Find Security Vulns
This talk led by Bishop Fox researchers Caleb Gross & Josh Shomo cuts through the hype and offers a practical perspective that’s grounded in real-world analysis of critical bugs in widely used products.
Past Event: 05/27/2024
CloudFoxable: A Practical Demo of AWS Cloud Security Misconfiguration Attacks
This practical demonstration features Bishop Fox security expert Seth Art showcasing CloudFoxable, an open-source AWS security training tool that simulates real-world cloud security misconfigurations.
Past Event: Friday, March 1, 2024
Workshop: Upgrade Your Job Search with AI
Dive into the world of AI-driven job searching with @Kaitlin O'Neil! Join us for a Discord exclusive workshop on March 1 for an in-depth exploration of ChatGPT and other AI tools.
Past Event: Tuesday, January 30, 2024 at 2pm ET / 11am PT
Sliver Mastery: Dominating Active Directory Through Advanced Trust Exploitation
Security expert John Guylde demonstrates sophisticated techniques for escalating from domain user to Enterprise Admin using the Sliver C2 framework. Learn how to leverage Kerberos delegation, trust relationships, and SID history to compromise even well-segmented Active Directory environments.
Past Event: On-Demand Session
Swagger Jacker: Improved Auditing of OpenAPI Definition Files
Discover the power of Swagger Jacker, an open-source audit tool designed to improve inspection of unintentionally exposed OpenAPI definition files for penetration testers.
Past Event: Tuesday, October 10, 2023 at 11am PT / 2pm ET
Ace the OSEP Exam with Sliver Framework
Unlock the secrets of passing the OSEP exam with our senior security expert, Jon Guild. Join us as Jon shares his invaluable tips and tricks for conquering this benchmark exam designed for penetration testers.
Past Event: Wednesday, July 20, 2023 at 11am PT / 2 pm ET
JavaScript Vulnerability Mining: Mastering jsluice for Advanced Web App Testing
Tune in to the eleventh episode of our Tool Talk series to hear Tom Hudson speak about jsluice, an open-source, Go package and command-line tool used to extract information from JavaScript files and code.
Past Event: On-Demand Workshop
Powering Up Burp Suite: Building Custom Extensions for Advanced Web Application Testing
Learn how to power up web application security testing with tips on creating customized extensions featuring BurpCage, an extension that replaces any image proxied through Burp Suite leveraging the Montoya API.
This site uses cookies to provide you with a great user experience. By continuing to use our website, you consent to the use of cookies. To find out more about the cookies we use, please see our Privacy Policy.