Offensive security
AR / SERVICE
Web application VAPTbeyond the top ten.
Assess authentication, authorisation, sessions, business logic, and data flows in the context of how the application is actually used.
Typical coverage
The scope follows the system.
These are common areas, not a pre-filled checklist. Final coverage is agreed around the environment, risks, access, and decisions the engagement needs to support.
01OWASP risks
02Business logic
03Access control
04Session security
05Input handling
06Sensitive data
What leaves the engagement
Output somebody can own.
01
Reproducible proof
02
Affected workflow and impact
03
Fix guidance for engineers
04
Focused retest
Interactive lab
Explore the immersive model for this practice.
Start somewhere honest
Start with the system and the decision.
Tell us what is in scope, what is changing, and who needs to act on the output. We will shape the method around that context.
Start a conversation