Offensive security

AR / SERVICE

Web application VAPTbeyond the top ten.

Assess authentication, authorisation, sessions, business logic, and data flows in the context of how the application is actually used.

Typical coverage

The scope follows the system.

These are common areas, not a pre-filled checklist. Final coverage is agreed around the environment, risks, access, and decisions the engagement needs to support.

01OWASP risks
02Business logic
03Access control
04Session security
05Input handling
06Sensitive data

What leaves the engagement

Output somebody can own.

01

Reproducible proof

02

Affected workflow and impact

03

Fix guidance for engineers

04

Focused retest

Interactive lab

Explore the immersive model for this practice.

Open lab

Start somewhere honest

Start with the system and the decision.

Tell us what is in scope, what is changing, and who needs to act on the output. We will shape the method around that context.

Start a conversation