Méthodologie

How we test — and what we cover

Expert-led web application assessment: hypothesis-first, evidence-backed, and scoped to what you authorize. This page describes our paid methodology — not the Free Exposure Brief.

  • 40+Classes de vulnérabilités exercées
  • 10Phases d'évaluation structurées
  • 100%Constats prouvés par des preuves
The Free Brief is orientation only and does not authorize active testing. Paid work needs written authorization and Rules of Engagement. How Brief vs paid works · See Outside-in package

Approche

How we think before we probe

Testing built like an investigation — not a one-size scanner run.

  • Hypothesis-first

    We form attack hypotheses from your architecture, stack, and business flows. Each test answers a precise question.

  • Attack-chain thinking

    Small issues often combine. We treat every result as new information and chase how findings link into real impact.

  • Scope-respecting expansion

    We start with core auth, workflows, and APIs — and only widen when a signal justifies it, inside your authorized boundaries.

  • Evidence-first reporting

    A finding ships only with a reproducible artifact. Unproven theories stay out of the report.

Cycle de vie

Assessment phases

The same disciplined path every engagement — tailored to your app, never shortcut.

  1. Scope & threat model

    Confirm authorized scope, crown-jewel assets, entry points, trust zones, and data flows before any probe.

  2. Recon & surface mapping

    Passive discovery and controlled fingerprinting to map what is actually reachable within scope.

  3. Authentication & sessions

    Login, registration, reset, MFA, SSO/OAuth, and session or token handling under adversarial conditions.

  4. Access control

    Can one user reach another’s data or actions? Privilege escalation, tenant isolation, and API authorization.

  5. Injection & input handling

    Inputs that reach databases, commands, templates, or files — tested for injection-class weaknesses.

  6. Business logic

    Pricing, checkout, coupons, races, and multi-step workflows that need product context.

  7. Client-side & APIs

    Browser-side risks and modern API surfaces (REST/GraphQL, webhooks) within scope.

  8. Infra & configuration

    Exposed panels, misconfigurations, outdated components, TLS posture, and storage exposure — as authorized.

  9. Validation & evidence

    Candidate findings are re-verified and documented with reproducible proof before they are reported.

  10. Reporting & remediation

    Risk-prioritized findings, business impact framing, and concrete fix guidance your team can act on.

Couverture

What we test

A coverage map for paid Outside-in and scoped upgrades. Severity tags reflect typical impact when exploited — calibrated per engagement.

Critical pre-authentication

  • Critical
    Authentication bypass

    Access without valid credentials.

  • Critical
    SQL / NoSQL injection

    Database manipulation via untrusted input, including blind variants.

  • Critical
    Server-Side Request Forgery (SSRF)

    Forcing the server to reach internal systems or cloud metadata.

  • Critical
    Remote code execution

    Command injection, unsafe deserialization, and upload paths that can take over the server.

Auth, session & access

  • High
    IDOR / BOLA

    Accessing or changing another user’s data by manipulating identifiers.

  • High
    JWT & token weaknesses

    Algorithm confusion, weak secrets, forgery, and privilege claim tampering.

  • High
    OAuth / SSO flaws

    Trust-boundary abuse between identity providers and your app.

  • High
    Account takeover & MFA gaps

    Reset and recovery abuse, and multi-factor downgrade paths.

  • High
    Mass assignment

    Changing fields the client was never meant to control.

  • Medium
    Rate limit & enumeration

    Brute-force exposure and username or account enumeration.

Injection & client-side

  • High
    Cross-Site Scripting (XSS)

    Reflected, stored, and DOM-based script injection.

  • Medium
    CSRF

    Forcing authenticated users into unintended actions.

  • Medium
    XXE

    File disclosure or SSRF via XML parsers.

  • Medium
    Prototype pollution

    Client-side gadget chains leading to XSS or logic bypass.

  • Medium
    CORS misconfiguration

    Cross-origin data leakage from permissive policies.

  • Medium
    Open redirect & cache poisoning

    Redirect abuse and web-cache deception chains.

Business logic

  • High
    Race conditions

    Timing gaps in payments, inventory, or limits.

  • High
    Pricing & checkout abuse

    Coupon stacking, price manipulation, and payment workflow bypass.

  • Medium
    Workflow skip

    Bypassing required steps in multi-stage processes.

  • Medium
    Path-based IDOR

    File and resource access via traversal or predictable paths.

Infra & supply chain

  • Medium
    Security misconfiguration

    Exposed admin panels, debug endpoints, default credentials.

  • Medium
    Cryptographic failures

    Weak TLS, insecure storage, predictable tokens.

  • Medium
    Sensitive data exposure

    Cloud storage, leaked source, backups, and secrets.

  • Medium
    Supply-chain risk

    Outdated or vulnerable third-party components.

  • Low
    Logging & alerting gaps

    Weak detection for real attacks.

  • Medium
    Request smuggling

    HTTP desync and proxy or CDN-layer inconsistencies.

API & modern surfaces

  • High
    GraphQL-specific risks

    Introspection abuse, batching, and resolver-level authorization gaps.

  • Medium
    Webhooks & integrations

    Auth and trust validation on inbound and outbound integrations.

AI & LLM (when applicable)

  • High
    Prompt injection

    Manipulating AI features via user input or poisoned content.

  • Medium
    RAG / retrieval exfiltration

    Bypassing access controls through AI-powered search or assistants.

  • Medium
    Tool & agent abuse

    Coercing agents into unauthorized actions or tool calls.

Comparaison

Where human assessment outperforms scanners alone

Scanners are useful for breadth. They cannot model your business, chain issues, or prove real exploitability the way an assessor can.

Automated scannerTruehat approach
Understands business logicNo product contextModeled per engagement
Chains issues into impactReports in isolationAttack-chain analysis
Validates before reportingHigh false-positive noiseEvery finding proven
Auth & workflow-specific logicLimited on custom flowsManually modeled trust zones
Adapts mid-assessmentFixed rule setHypothesis-driven
Business-logic & racesUsually out of reachCore testing phase
Prioritizes by business impactGeneric severity scoresImpact framed for your business
Scanners describe what a page looks like. We show what an attacker could do — and prove it.

Preuves

How we prove impact

Trust comes from proof, not adjectives. Every finding meets an evidence bar before it reaches your team.

  • Reproducible proof

    Exact steps, requests, and observed responses so engineers can confirm independently.

  • Independent re-verification

    Candidates are re-tested before they are finalized — reducing false positives.

  • Business-impact framing

    What data, money, or control an attacker could obtain — not only a score.

  • Severity calibration

    Ratings reflect exploitability and context, not default scanner output.

  • Non-destructive by default

    Validation stays inside agreed Rules of Engagement without harming availability or integrity.

Severity framework

  • CriticalHigh-confidence path to compromise, mass data exposure, or financial loss.
  • HighSignificant unauthorized access or data exposure with limited preconditions.
  • MediumReal risk that needs specific conditions or chaining for meaningful impact.
  • LowDefense-in-depth weakness with limited standalone impact.

Livrables

What you receive

Reporting built for leadership and engineering — so the engagement does not stop at the last page.

  • Executive

    Executive summary

    Concise overview of posture, key findings, and business impact for decision-makers.

  • Technical

    Technical assessment report

    Detailed findings with reproduction steps, evidence, assets, and severity.

  • Action

    Remediation roadmap

    Prioritized plan grouped by urgency so the team knows what to fix first.

  • Presentation

    Walkthrough presentation

    Ready-to-present summary of findings, risk, and next steps.

Étape suivante

Ready to scope a paid assessment?

Book a scope call for Outside-in fit, timing, and authorization path — or start with a Free Brief if you only need public-surface orientation first.

Free Brief ≠ paid testing. Active assessment starts only after written authorization.