Discover offensive security resources ranging from reports and guides to our latest webcasts and livestreams.
Ham Hacks: Breaking into the world of software-defined radio
DerpCon 2020 presentation explores how to find, capture, and reverse-engineer RF signals.
Demystifying Capture the Flags (CTFs)
DerpCon 2020 presentation on CTF formats, the skills they require, and the experience they develop.
Salesflare Focuses on Application Security for the G Suite Marketplace
When Salesflare knew they needed to complete the new, required security assessment for the G Suite Marketplace, they chose Bishop Fox to secure their CRM product and verify their compliance.
Scaling up Google's Third-Party Security Program
When Google needed to ensure that their user data was being handled securely, they partnered with Bishop Fox to design a security assessment program that could validate the security posture of their 1,000+ G Suite partners. The result: the largest and most successful public third-party ecosystem testing program ever.
Expose Yourself Without Insecurity: Cloud Breach Patterns
Presentation from BSides Atlanta 2020 explores the unprecedented level of exposures in the Cloud and how they can be found.
Attacking the Data Before the Decision
Presentation from BSides Tampa 2020 explores the vulnerabilities of machine learning systems and how to mitigate them.
How to Write Like It's Your Job
Presentation from BSides San Francisco 2020 offers practical advice for security writers.
Sonos Makes Secure Moves with Bishop Fox
Secured a new voice-enabled speaker at launch by integrating security testing into every stage of development.
Zigbee Hacking: Smarter Home Invasion with ZigDiggity
Existing Zigbee hacking solutions have fallen into disrepair, having barely been maintained, let alone improved upon. Left without a practical way to evaluate the security of Zigbee networks, we've created ZigDiggity, a new open-source pentest arsenal from Bishop Fox.
Finding Secrets In Publicly Exposed EBS Volumes
In this talk, Ben Morris shows how he found all sorts of secrets and associated data—passwords, SSH private keys, TLS certificates, application source code, API keys, and anything else that might be stored on a server hard disk.
ZigDiggity: ZigBee Hacking Toolkit
Presentation from Black Hat USA 2019 reveals an open-source pentest arsenal for Zigbee networks.
Ghost In The Browser - Broad-Scale Espionage With Bitsquatting
Presentation from Kapersky SAS 2019 on an unfortunate side effect to achieving HTTPS everywhere and learn what can be done to mitigate the risk.
Wickr: How Bishop Fox Enables Wickr's Security Assurance
Validated products against real-world attack scenarios, delivering the transparency and assurance promised to customers.
Reverse Engineering Mobile Apps
Presentation from BSides Las Vegas 2019 demonstrates the successful exploitation of transit system mobile apps.
Securing Boost.Beast
A Non-Traditional Source Code Review Securing the Foundation of Thousands of Web Applications.
Twist & Shout: Ferris Bueller's Guide to Abuse Domain Permutations
Presentation from Sqr00t 2019 explores the ins and outs of domain abuse, and how to prevent it.
Check Your Privilege (Escalation)
Presentation from BSides Columbus 2019 discusses common privilege escalation paths on Linux systems.
Network Penetration Testing Toolkit: Netcat, Nmap, and Metasploit Basics
Presentation from Day of Shecurity 2019 familiarizes you with the necessary tools to continue your ethical hacking journey.
Introduction to Linux - Privilege Escalation Methods
Presentation from Day of Shecurity 2019 explores privilege escalation methods in Linux.
Pose a Threat: How Perceptual Analysis Helps Bug Hunters
Presentation from OWASP AppSec California 2019 offers up dirty tricks to optimize the hunt for security exposures.
Coinbase: Managing Security Through Collaboration
Combining the HackerOne Platform with Bishop Fox Security Consultants.
Change Healthcare: Securing a Competitive Advantage
As their business expanded, we were there to help Change Healthcare grow and evolve their security posture.
Securing Mobile Security with Bluebox
Software Security Meets Cybersecurity. Bluebox needed a vendor to conduct a mobile security assessment of their solution. Bishop Fox established that security was the foundation of their software.
Iotium: Securing an Industrial IoT Platform
IoTium, a solution designed for the Industrial Internet of Things (IIoT), enlisted Bishop Fox to verify the security of their product offering.
This site uses cookies to provide you with a great user experience. By continuing to use our website, you consent to the use of cookies. To find out more about the cookies we use, please see our Privacy Policy.