Penetration testing – simulate the attack before someone else does

We attack your application and your network, with your permission and with a report that shows what to do.

What a penetration test delivers

A vulnerability scanner finds known flaws in known software. It does not notice that tenant A can see tenant B’s invoices by changing a number in the URL.

We chain individual weaknesses the way an attacker would and show how far they get you. Every finding is proven and reproducible; false positives do not make it into the report.

SaaS applications and APIs

Login, permissions, tenant separation, interfaces and business logic.

Networks and Active Directory

From outside, or starting from an ordinary user account on the internal network.

White box: with a look at the code

In a white-box test we see source code, configuration and architecture while attacking the running application at the same time. Whatever looks suspicious in the code we test against the system until it is proven or ruled out. That finds flaws that are hard to see from outside, and lets us point your developers straight to the affected code.

Our tooling covers the breadth of an application systematically; the depth comes from experience. That makes the white-box test particularly thorough and efficient for SaaS applications.

Without code access we test as a grey box, with accounts in different roles and tenants. We usually advise against a pure black-box test: it spends a large part of the budget on finding the front door.

Approach

  1. Scope and authorisation

    What is tested, when, and what is off limits, agreed in writing.

  2. Testing

    Enumeration, exploitation, privilege escalation. Critical findings are reported immediately.

  3. Report and retest

    A debrief with your team; after remediation we test again.

What you receive

A summary for management and, for your developers, every finding with a CVSS severity rating, evidence and remediation advice. After the retest you receive a confirmation you can show to customers. A recent report answers a good share of every security questionnaire and helps in ISO 27001 audits as well.

After a short conversation about scope and architecture you receive a fixed-price offer. For Windows networks, see also our Active Directory audit.

Not sure where you stand?

In a first call we clarify your situation and what makes sense as a next step. No obligation, no cost.

Book a free first call