Different attack surfaces require different methodologies. Each engagement is scoped to the specific system and threat model.
Web Application Testing
OWASP Top 10 coverage, business logic testing, authentication bypass, authorisation flaws (IDOR, privilege escalation), injection attacks, XSS/CSRF, session management and API security. Authenticated and unauthenticated assessment.
API Security Testing
REST and GraphQL API testing — BOLA/IDOR, broken authentication, mass assignment, rate limiting bypass, GraphQL introspection abuse, injection via API parameters, JWT vulnerabilities and API versioning issues.
Mobile Application Testing
iOS and Android testing — insecure data storage, certificate validation bypass (SSL pinning), client-side injection, improper authentication, binary analysis for hardcoded credentials, API traffic interception and runtime manipulation with Frida.
Cloud Infrastructure Testing
AWS/GCP/Azure misconfiguration — IAM privilege escalation, publicly accessible S3 buckets, metadata service exploitation (SSRF → IMDS), exposed management interfaces, secrets in environment variables and container escape.
Network & Infrastructure Testing
Internal network segmentation testing, exposed services on non-standard ports, SSL/TLS configuration review, default credential testing on network devices and VPN configuration assessment.
Social Engineering Assessment
Phishing simulation, pretexting scenarios, physical security assessment and security awareness baseline measurement — with metrics on click rate, credential submission and reporting rate.