FuzzyNop
Josh Schwartz — red teamer, social engineer, and professional bogeyman. A computer who knows how to computer. Builder of corporate red teams by day; Fuzzy of The Fuzzy Place by night. One stop for all of it.
Break it to understand it
It started with cheating at video games — bending a system's rules to see how it really works underneath. That instinct became a career spent on the attacker's side of the glass: building and leading red teams inside some of the largest companies on the internet.
The through-line of the work: the most interesting attack surface is people. Talks and trainings across the global conference circuit on red teaming, adversary simulation, behavioral security, and offensive psychology at scale — how organizations actually get compromised, and how to build cultures that don't.
Six marks, one operator
The whole story told in glyphs — every one drawn from the record, and every one a door. Tap a mark to go deeper: my own talks and tools where they exist, the canonical source where they don't.
The NOP Sled
fuzz + no-op — the handle is the exploit
read: what a NOP sled is ↗The Operator's Eye
you watch the system — not the other way
watch: Embrace the Bogeyman ↗The First Hack
cheating at games → reverse engineering
read: the Konami Code ↗The Human Exploit
the unpatchable vuln is people
watch: Behavioral Security ↗MEATPISTOL
the implant you shipped · DEF CON 25
watch: the DEF CON 25 talk ↗The Glider
the hacker's mark — one of the tribe
read: the hacker emblem ↗The record
The conference circuit
A decade-plus of talks and trainings on red teaming, social engineering, and adversary simulation — DEF CON, DerbyCon, BruCON, NolaCon, HushCon, SXSW, RSAC.
source: InfoconDB talk archive ↗Red Team Lead
Led the internal red team conducting high-impact offensive security engagements against one of the world's largest SaaS platforms.
source: QCon SF 2016 speaker bio ↗Director, Offensive Security
Oversaw offensive security, product security engineering, and security engagement functions across the Verizon Media → Yahoo estate.
source: RSAC expert bio ↗ Security Conversations podcast ↗Independent consultant
Full-spectrum red team and adversary emulation engagements, plus training on social engineering and behavioral security. Authorized targets only — that's the whole point.
Stage time
MEATPISTOL — A Modular Malware Implant Framework
Co-presented tooling for red team implant development, on the biggest stage in the industry.
watch: official DEF CON video ↗ NolaCon 2019 · DerbyCon 9Behavioral Security & Offensive Psychology at Scale
Why humans are the persistent attack surface — and what scaling defense against that actually looks like.
watch: full talk ↗ NolaCon 2017Embrace the Bogeyman: Tactical Fear Mongering for Those Who Penetrate
On being the monster your org needs: making red team findings land instead of getting filed.
watch: full talk ↗ NolaCon 2018Your Mac Defenestrated — Post-OSXploitation Elevated
macOS post-exploitation tradecraft.
source: InfoconDB ↗ HushCon Seattle 2019Business Tradecraft for Hackers in the Corporate Industrial Complex
Surviving — and steering — the enterprise as a hacker.
watch: LevelUp 0x06 recording ↗ Full archive~23 talks, 2013–2019
The complete catalogue across DEF CON, DerbyCon, NolaCon, and HushCon.
browse: the whole archive ↗Behind the decks
Same wiring, different output. Fuzzy plays long, textural sets at the immersive-art parties he throws — after-hours music for the people who stay late.
Sets and originals live across the usual places:
SC SoundCloud ↗ SP Spotify ↗ MC Mixcloud ↗The Fuzzy Place
An immersive art space in San Francisco. Counter-surveillance as performance, games that follow you home, and a rotating cast of mimes, clowns, and hackers exploring what privacy means when everything watches back. Art and education — the same curiosity as the day job, pointed somewhere stranger.
Crews & co-conspirators
My own crew, and allied outfits whose work I back. The bogeyman keeps good company.
Security Theater Drama Club
Artists, performers, and hackers automating their craft — and getting paid for it. The paid room where the game gets serious.
join: skool.com/stdc ↗ Allied · SecurityProper Villains
Personal security enlightenment powered by the digital dark arts — high-class hackers for hire for clients in the spotlight.
visit: propervillains.io ↗ Allied · ResearchPink Team
Human-layer security research — a new shade of red teaming, studying trust, identity, and influence in the age of AI.
visit: pinkteam.xyz ↗ Allied · Invitation onlyParasol Society
By invitation. By summons.
visit: parasolsociety.com ↗