Expert Analysis of Recent SaaS Attacks That Shocked Global Brands. Watch now

Featured Resource

LLM-Assisted Vulnerability Research

Explore Bishop Fox's experimental research into applying Large Language Models to vulnerability research and patch diffing workflows. This technical guide presents methodology, data, and insights from structured experiments testing LLM capabilities across high-impact CVEs, offering a transparent look at where AI shows promise and where challenges remain.

Parrot chose Bishop Fox to conduct a security assessment of FreeFlight mobile app and its web API.
Customer Story

Parrot Chooses Bishop Fox for Privacy Audit and Application Penetration Testing

Underwent rigorous privacy audits and penetration testing for the FreeFlight 6 mobile app and API to ensure a secure user experience.

Bishop Fox Google Partner What to Expect Guide C
Guide

What to Expect of Your Google Partner Security Assessment

This guide covers what to expect when engaging Bishop Fox to perform a Google Partner OAuth Application security assessment, including project timeline, onboarding and scoping, and deliverables.

Bishop Fox Nest Security Assessment What to Expect Guide C
Guide

What to Expect of Your Nest Security Assessment

This guide covers what to expect when engaging Bishop Fox to perform a Google Nest Security Assessment, including timeline, scoping, scheduling, and reporting.

Illumio and Bishop Fox measure the impact of Micro-Segmentation on network security.
Customer Story

Developing a New Methodology for Illumio to Measure the Power of Micro-Segmentation

Proved the impact of micro-segmentation in slowing attackers with a custom testing methodology.

SmogCloud video thumbnail with overlay play button.
Workshops & Training

SmogCloud: Expose Yourself Without Insecurity - Cloud Breach Patterns

Presented at Black Hat 2020, this presentation looks at the most pragmatic ways to continuously analyze your AWS environments and operationalize that information to answer vital security questions. Demonstrations include integration between IAM Access Analyzer, Tiros Reachability API, and Bishop Fox CAST Cloud Connectors, along with a new open source tool SmogCloud to find continuously changing AWS internet-facing services.

Cover slide deck expose yourself without insecurity blackhat arsenal 2020
Workshops & Training

SmogCloud: Expose Yourself Without Insecurity - Cloud Breach Patterns

Black Hat USA 2020 presentation looks at pragmatic ways to answer vital security questions in your AWS environment.

Efficacy of micro segmentation illumio Video Thumbnail
Virtual Session

Illumio Assessment Report: Interview with Raghu Nandakumara and Rob Ragan

Illumio Field CTO Raghu Nandakumara and Bishop Fox Principal Researcher Rob Ragan discuss the efficacy of microsegmentation in this interview.
Dufflebag uncovering secrets in exposed ebs volumes Video Thumbnail
Workshops & Training

Dufflebag Deep Dive: Uncovering Secrets in Exposed EBS Volumes

In this video, Dan Petro demonstrates how the Bishop Fox open source tool Dufflebag works.

Watch our Derpcon 2020 demystifying capture the flags ctfs video
Workshops & Training

DerpCon 2020 - Demystifying Capture The Flags (CTF)s

In the talk: Demystifying CTFs, Barrett Darnell will provide an overview of CTF formats, the skills they require and the experience they develop, and conclude with a plethora of CTF resources for those wanting to participate.
Watch our Derpcon 2020 Video: ham hacks breaking into the world of software defined radio with kelly albrink
Workshops & Training

Ham Hacks: Breaking into the World of Software Defined Radio

If you’re a hacker who has always been too afraid of RF protocols to try getting into SDRs, or you have a HackRF collecting dust in your closet, this talk will show you the ropes.

Watch our Derpcon 2020 net roulette exploiting insecure deserialization in telerik ui video
Workshops & Training

.NET Roulette: Exploiting Insecure Deserialization in Telerik UI

Telerik UI for ASP.NET AJAX is a widely used suite of UI components for web applications.
Cover page .net roulette exploiting insecure deserialization in Telerik ui
Workshops & Training

.Net Roulette Exploiting Insecure Deserialization in Telerik UI

DerpCon 2020 presentation reviews how .NET deserialization works and how to get shells on real applications.

This site uses cookies to provide you with a great user experience. By continuing to use our website, you consent to the use of cookies. To find out more about the cookies we use, please see our Privacy Policy.