Méthodologie
How we test — and what we cover
Expert-led web application assessment: hypothesis-first, evidence-backed, and scoped to what you authorize. This page describes our paid methodology — not the Free Exposure Brief.
- 40+Classes de vulnérabilités exercées
- 10Phases d'évaluation structurées
- 100%Constats prouvés par des preuves
Approche
How we think before we probe
Testing built like an investigation — not a one-size scanner run.
Hypothesis-first
We form attack hypotheses from your architecture, stack, and business flows. Each test answers a precise question.
Attack-chain thinking
Small issues often combine. We treat every result as new information and chase how findings link into real impact.
Scope-respecting expansion
We start with core auth, workflows, and APIs — and only widen when a signal justifies it, inside your authorized boundaries.
Evidence-first reporting
A finding ships only with a reproducible artifact. Unproven theories stay out of the report.
Cycle de vie
Assessment phases
The same disciplined path every engagement — tailored to your app, never shortcut.
Scope & threat model
Confirm authorized scope, crown-jewel assets, entry points, trust zones, and data flows before any probe.
Recon & surface mapping
Passive discovery and controlled fingerprinting to map what is actually reachable within scope.
Authentication & sessions
Login, registration, reset, MFA, SSO/OAuth, and session or token handling under adversarial conditions.
Access control
Can one user reach another’s data or actions? Privilege escalation, tenant isolation, and API authorization.
Injection & input handling
Inputs that reach databases, commands, templates, or files — tested for injection-class weaknesses.
Business logic
Pricing, checkout, coupons, races, and multi-step workflows that need product context.
Client-side & APIs
Browser-side risks and modern API surfaces (REST/GraphQL, webhooks) within scope.
Infra & configuration
Exposed panels, misconfigurations, outdated components, TLS posture, and storage exposure — as authorized.
Validation & evidence
Candidate findings are re-verified and documented with reproducible proof before they are reported.
Reporting & remediation
Risk-prioritized findings, business impact framing, and concrete fix guidance your team can act on.
Couverture
What we test
A coverage map for paid Outside-in and scoped upgrades. Severity tags reflect typical impact when exploited — calibrated per engagement.
Critical pre-authentication
- CriticalAuthentication bypass
Access without valid credentials.
- CriticalSQL / NoSQL injection
Database manipulation via untrusted input, including blind variants.
- CriticalServer-Side Request Forgery (SSRF)
Forcing the server to reach internal systems or cloud metadata.
- CriticalRemote code execution
Command injection, unsafe deserialization, and upload paths that can take over the server.
Auth, session & access
- HighIDOR / BOLA
Accessing or changing another user’s data by manipulating identifiers.
- HighJWT & token weaknesses
Algorithm confusion, weak secrets, forgery, and privilege claim tampering.
- HighOAuth / SSO flaws
Trust-boundary abuse between identity providers and your app.
- HighAccount takeover & MFA gaps
Reset and recovery abuse, and multi-factor downgrade paths.
- HighMass assignment
Changing fields the client was never meant to control.
- MediumRate limit & enumeration
Brute-force exposure and username or account enumeration.
Injection & client-side
- HighCross-Site Scripting (XSS)
Reflected, stored, and DOM-based script injection.
- MediumCSRF
Forcing authenticated users into unintended actions.
- MediumXXE
File disclosure or SSRF via XML parsers.
- MediumPrototype pollution
Client-side gadget chains leading to XSS or logic bypass.
- MediumCORS misconfiguration
Cross-origin data leakage from permissive policies.
- MediumOpen redirect & cache poisoning
Redirect abuse and web-cache deception chains.
Business logic
- HighRace conditions
Timing gaps in payments, inventory, or limits.
- HighPricing & checkout abuse
Coupon stacking, price manipulation, and payment workflow bypass.
- MediumWorkflow skip
Bypassing required steps in multi-stage processes.
- MediumPath-based IDOR
File and resource access via traversal or predictable paths.
Infra & supply chain
- MediumSecurity misconfiguration
Exposed admin panels, debug endpoints, default credentials.
- MediumCryptographic failures
Weak TLS, insecure storage, predictable tokens.
- MediumSensitive data exposure
Cloud storage, leaked source, backups, and secrets.
- MediumSupply-chain risk
Outdated or vulnerable third-party components.
- LowLogging & alerting gaps
Weak detection for real attacks.
- MediumRequest smuggling
HTTP desync and proxy or CDN-layer inconsistencies.
API & modern surfaces
- HighGraphQL-specific risks
Introspection abuse, batching, and resolver-level authorization gaps.
- MediumWebhooks & integrations
Auth and trust validation on inbound and outbound integrations.
AI & LLM (when applicable)
- HighPrompt injection
Manipulating AI features via user input or poisoned content.
- MediumRAG / retrieval exfiltration
Bypassing access controls through AI-powered search or assistants.
- MediumTool & agent abuse
Coercing agents into unauthorized actions or tool calls.
Comparaison
Where human assessment outperforms scanners alone
Scanners are useful for breadth. They cannot model your business, chain issues, or prove real exploitability the way an assessor can.
| Automated scanner | Truehat approach | |
|---|---|---|
| Understands business logic | No product context | Modeled per engagement |
| Chains issues into impact | Reports in isolation | Attack-chain analysis |
| Validates before reporting | High false-positive noise | Every finding proven |
| Auth & workflow-specific logic | Limited on custom flows | Manually modeled trust zones |
| Adapts mid-assessment | Fixed rule set | Hypothesis-driven |
| Business-logic & races | Usually out of reach | Core testing phase |
| Prioritizes by business impact | Generic severity scores | Impact framed for your business |
Scanners describe what a page looks like. We show what an attacker could do — and prove it.
Preuves
How we prove impact
Trust comes from proof, not adjectives. Every finding meets an evidence bar before it reaches your team.
Reproducible proof
Exact steps, requests, and observed responses so engineers can confirm independently.
Independent re-verification
Candidates are re-tested before they are finalized — reducing false positives.
Business-impact framing
What data, money, or control an attacker could obtain — not only a score.
Severity calibration
Ratings reflect exploitability and context, not default scanner output.
Non-destructive by default
Validation stays inside agreed Rules of Engagement without harming availability or integrity.
Severity framework
- CriticalHigh-confidence path to compromise, mass data exposure, or financial loss.
- HighSignificant unauthorized access or data exposure with limited preconditions.
- MediumReal risk that needs specific conditions or chaining for meaningful impact.
- LowDefense-in-depth weakness with limited standalone impact.
Livrables
What you receive
Reporting built for leadership and engineering — so the engagement does not stop at the last page.
- Executive
Executive summary
Concise overview of posture, key findings, and business impact for decision-makers.
- Technical
Technical assessment report
Detailed findings with reproduction steps, evidence, assets, and severity.
- Action
Remediation roadmap
Prioritized plan grouped by urgency so the team knows what to fix first.
- Presentation
Walkthrough presentation
Ready-to-present summary of findings, risk, and next steps.
Étape suivante
Ready to scope a paid assessment?
Book a scope call for Outside-in fit, timing, and authorization path — or start with a Free Brief if you only need public-surface orientation first.
Free Brief ≠ paid testing. Active assessment starts only after written authorization.
