Discover offensive security resources ranging from reports and guides to our latest webcasts and livestreams.
Attacking the Data Before the Decision
Presentation from BSides Tampa 2020 explores the vulnerabilities of machine learning systems and how to mitigate them.
How to Write Like It's Your Job
Presentation from BSides San Francisco 2020 offers practical advice for security writers.
Sonos Makes Secure Moves with Bishop Fox
Secured a new voice-enabled speaker at launch by integrating security testing into every stage of development.
Zigbee Hacking: Smarter Home Invasion with ZigDiggity
Existing Zigbee hacking solutions have fallen into disrepair, having barely been maintained, let alone improved upon. Left without a practical way to evaluate the security of Zigbee networks, we've created ZigDiggity, a new open-source pentest arsenal from Bishop Fox.
Finding Secrets In Publicly Exposed EBS Volumes
In this talk, Ben Morris shows how he found all sorts of secrets and associated data—passwords, SSH private keys, TLS certificates, application source code, API keys, and anything else that might be stored on a server hard disk.
ZigDiggity: ZigBee Hacking Toolkit
Presentation from Black Hat USA 2019 reveals an open-source pentest arsenal for Zigbee networks.
Ghost In The Browser - Broad-Scale Espionage With Bitsquatting
Presentation from Kapersky SAS 2019 on an unfortunate side effect to achieving HTTPS everywhere and learn what can be done to mitigate the risk.
Wickr: How Bishop Fox Enables Wickr's Security Assurance
Validated products against real-world attack scenarios, delivering the transparency and assurance promised to customers.
Reverse Engineering Mobile Apps
Presentation from BSides Las Vegas 2019 demonstrates the successful exploitation of transit system mobile apps.
Securing Boost.Beast
A Non-Traditional Source Code Review Securing the Foundation of Thousands of Web Applications.
Twist & Shout: Ferris Bueller's Guide to Abuse Domain Permutations
Presentation from Sqr00t 2019 explores the ins and outs of domain abuse, and how to prevent it.
Check Your Privilege (Escalation)
Presentation from BSides Columbus 2019 discusses common privilege escalation paths on Linux systems.
Network Penetration Testing Toolkit: Netcat, Nmap, and Metasploit Basics
Presentation from Day of Shecurity 2019 familiarizes you with the necessary tools to continue your ethical hacking journey.
Introduction to Linux - Privilege Escalation Methods
Presentation from Day of Shecurity 2019 explores privilege escalation methods in Linux.
Pose a Threat: How Perceptual Analysis Helps Bug Hunters
Presentation from OWASP AppSec California 2019 offers up dirty tricks to optimize the hunt for security exposures.
Coinbase: Managing Security Through Collaboration
Combining the HackerOne Platform with Bishop Fox Security Consultants.
Change Healthcare: Securing a Competitive Advantage
As their business expanded, we were there to help Change Healthcare grow and evolve their security posture.
Securing Mobile Security with Bluebox
Software Security Meets Cybersecurity. Bluebox needed a vendor to conduct a mobile security assessment of their solution. Bishop Fox established that security was the foundation of their software.
Iotium: Securing an Industrial IoT Platform
IoTium, a solution designed for the Industrial Internet of Things (IIoT), enlisted Bishop Fox to verify the security of their product offering.
Drone Hacking: Wireless Mouse Flyby Hijack with DangerDrone
Some quick live footage of flying the Danger Drone, a free penetration testing platform from Bishop Fox.
Zephyr Health: Building a Healthy Security Program
Designed a security program that meets the highest privacy standards to protect sensitive patient health data.
Weaponizing Machine Learning
At risk of appearing like mad scientists, reveling in our latest unholy creation, we proudly introduce you to DeepHack: the open-source hacking AI. This bot learns how to break into web applications using a neural network, trial-and-error, and a frightening disregard for humankind.
DEF CON 25 (2017) - Game of Drones
We’ve taken a MythBusters-style approach to testing the effectiveness of a variety of drone defense solutions, pitting them against our DangerDrone. Videos demonstrating the results should be almost as fun for you to watch as they were for us to produce. Expect to witness epic aerial battles against an assortment of drone defense types.
Drone Hacking: Defeating Net Defense Products with a Protective Chicken Wire Cage
Defeating net-based drone defense products by using a protective chicken wire bubble would defeat the majority of net drone defensive products which rely on the net getting caught in the propellers to take down the drone.
This site uses cookies to provide you with a great user experience. By continuing to use our website, you consent to the use of cookies. To find out more about the cookies we use, please see our Privacy Policy.