Web App Pentesting
Manual + tooling-assisted testing of authentication, session, business logic, and OWASP Top 10 across modern SPAs and SSR apps.
// Services
From single-app pentests to multi-week red team simulations. Every engagement is scoped collaboratively with your engineering leads.
Manual + tooling-assisted testing of authentication, session, business logic, and OWASP Top 10 across modern SPAs and SSR apps.
REST, GraphQL & gRPC. Authorization, IDOR, rate limiting, schema fuzzing and BOLA detection.
iOS & Android — runtime tampering with Frida, secure storage analysis, traffic interception, reverse engineering.
AWS, GCP & Azure: IAM hardening, S3/Bucket audits, Kubernetes posture, lateral movement paths.
Internal/external networks, Active Directory attacks, lateral movement, segmentation review.
Goal-based adversary simulation testing your detection, response, and incident playbooks end-to-end.
Manual review of authentication, crypto, deserialization and trust boundaries — directly in your repo.
Triage, scope design, payouts strategy and program management for HackerOne/Bugcrowd/private programs.