AI-Powered Application Penetration Testing—Scale Security Without Compromise Learn More

Reports

Ransomware Scenario Emulation Report with Illumio

Ransomware Scenario Emulation Report with Illumio

Illumio, Inc. engaged Bishop Fox to measure the effectiveness of Illumio Core for blue teams to detect and contain a ransomware attack. The report details the findings identified during the course of the engagement, which started on March 10, 2022.

Read Report
Virtual Sessions

Watch a Special Livestream From DEF CON 30

Watch a Special Livestream From DEF CON 30

Watch the lineup of leaders & influencers from the infosec community who joined us live at DEF CON 30!

Watch Session
Virtual Sessions

Leveraging Nuclei for Scalable, Custom Vulnerability Scanning

Leveraging Nuclei for Scalable, Custom Vulnerability Scanning

In our third edition of the Tool Talk series, we dive into the open-source tool Nuclei, a fast and customizable vulnerability scanner based on simple YAML-based DSL.

Watch Session
Resource

CISO Stories featuring Will Lin, Founding Team Member at ForgePoint Capital

CISO Stories featuring Will Lin, Founding Team Member at ForgePoint Capital

Will Lin, founding team member at ForgePoint Capital (and investor in Bishop Fox) and co-creator of the CISO community Security Tinkerers, discusses his passion for technology and how it led him to a career helping security companies launch, as well as his work supporting CISOs through collaboration and knowledge sharing.

Learn More
Reports

CyberRisk Alliance Cloud Adoption Security Report

CyberRisk Alliance Cloud Adoption Security Report

Explore key findings and insights from the CRA Business Intelligence Cloud Security Survey of more than 300 security leaders & practitioners.

Read Report
Virtual Sessions

2022 GigaOm Analyst Webcast: Everything You Need to Know About Attack Surface Management

2022 GigaOm Analyst Webcast: Everything You Need to Know About Attack Surface Management

Tune into our webcast to learn more about Attack Surface Management and tips for evaluating solutions. GigaOm analyst Chris Ray joins us to share his insights!

Watch Session
Virtual Sessions

Tool Talks: Debugging Ruby Exploits

Tool Talks: Debugging Ruby Exploits

In our sixth edition of the Tool Talk series, we explore a new test harness for discovering and crafting Ruby exploits.

Watch Session
Resource

Tool Talk: ripgen

Tool Talk: ripgen

In our fifth edition of the Tool Talk series, we explore ripgen, a subdomain discovery tool designed to significantly increase permutation combinations.

Learn More
Virtual Sessions

Achieving Warp Speed to Continuous Testing: How to Calculate ROI for your Business

Achieving Warp Speed to Continuous Testing: How to Calculate ROI for your Business

Uncover your organization’s unique cost savings and risk mitigation strategy for a continuous offensive testing solution with our customized ROI calculation.

Watch Session
Virtual Sessions

Combating Ransomware with an Offensive Roadmap

Combating Ransomware with an Offensive Roadmap

Examine your organization’s level of ransomware preparedness through the lens of offensive security considerations.

Watch Session
Methodologies

Bishop Fox Secure Code Review Methodology

Bishop Fox Secure Code Review Methodology

Overview of Bishop Fox’s methodology for Secure Code Review.

Read Methodology
Virtual Sessions

SC Media Special Event: Continuously Hacking Yourself

SC Media Special Event: Continuously Hacking Yourself

Explore the benefits of continually hacking yourself to discover new assets (including many you don’t even know you have) and their associated vulnerabilities.

Watch Session
Guides

Evaluating Offensive Security Solutions: Top 50 Questions to Ask

Evaluating Offensive Security Solutions: Top 50 Questions to Ask

To ensure your security investments offer complete visibility into your attack surface and uncover critical risks at scale, we've compiled questions to help you evaluate solutions. We focus on six key areas: attack surface discovery, exposure identification, triage, validation, remediation, and outputs.

Read Guide
Guides

SW Labs Product Review: Cosmos Attack Surface Management Platform

SW Labs Product Review: Cosmos Attack Surface Management Platform

SW Labs assessed Bishop Fox’s Cosmos (formerly CAST) the “Best Emerging Technology" Attack Surface Management Platform of 2021.

Read Guide
Guides

SW Labs Category Overview: Attack Surface Management (ASM) Solutions

SW Labs Category Overview: Attack Surface Management (ASM) Solutions

Comprehensive overview of the fast-growing Attack Surface Management category from the cybersecurity experts at Security Weekly Labs.

Read Guide
Guides

The Wolf in Sheep’s Clothing

The Wolf in Sheep’s Clothing

See how low-risk exposures can become catalysts for destructive attacks. We include examples of exposures found in real-world environments, including a step-by-step view into how ethical hackers exploited them to reach high-value targets.

Read Guide
Virtual Sessions

Cracking the Code: Secure Code Review in DevSecOps

Cracking the Code: Secure Code Review in DevSecOps

On-demand webcast offers an in-depth look at how DevOps can integrate both automated and manual code review into the software development lifecycle.

Watch Session
Virtual Sessions

The Wolf in Sheep's Clothing: How Innocuous Exposures Become Infamous

The Wolf in Sheep's Clothing: How Innocuous Exposures Become Infamous

In the hands of skilled attackers, many "low risk" exposures serve as launching pads or steppingstones to more complex and destructive attacks. Join our webcast as we dive into real-world examples.

Watch Session
Virtual Sessions

What Bad Could Happen? Managing Application Risk with Threat Modeling

What Bad Could Happen? Managing Application Risk with Threat Modeling

What if security could become an integral framework within the software development process? Join Tom Eston and Chris Bush to learn how Threat Modeling is changing the way organizations manage application security risks.

Watch Session
Virtual Sessions

A Deep Dive Into Fuzzing

A Deep Dive Into Fuzzing

Get the buzz on fuzz testing in software development.

Watch Session
Virtual Sessions

Outpacing the Speed and Precision of Modern Attackers with Continuous Attack Surface Testing

Outpacing the Speed and Precision of Modern Attackers with Continuous Attack Surface Testing

On-demand webcast provides an in-depth look at using Continuous Attack Surface Testing (CAST) to identify and close attack windows before it’s too late.

Watch Session
Guides

Penetration Testing Resource Guide

Penetration Testing Resource Guide

This handy guide provides a list of great resources for learning to be a pen tester.

Read Guide
Virtual Sessions

How to Build a DevSecOps Program that Works for Developers AND Security

How to Build a DevSecOps Program that Works for Developers AND Security

On-demand webcast explores how the right DevSecOps strategy empowers both your security and development teams.

Watch Session
Virtual Sessions

DevSecOps and Application Penetration Testing: Defying the Myth

DevSecOps and Application Penetration Testing: Defying the Myth

On-demand webcast dives into the role of application penetration testing in today’s software development lifecycle (SDLC).

Watch Session

This site uses cookies to provide you with a great user experience. By continuing to use our website, you consent to the use of cookies. To find out more about the cookies we use, please see our Privacy Policy.