The core engagement: every request path in your application tested for injection, access control, transport, and configuration weaknesses — the same scope you would expect from a traditional web app pentest, run end to end.
What's included
Every JMX-defined endpoint tested for injectable parameters, GET and POST alike.
Reflected, stored, and DOM-based XSS across forms and parameters.
Out-of-band detection for server-side request forgery and blind command execution.
Cross-tenant IDOR/BOLA checks between two live accounts.
HTTP header coverage and CORS policy review.
Protocol, cipher, and certificate review.
Exposed .git/.env/backups and forgotten hidden endpoints.
Why it matters
The web application is still the most common way into an organization — one endpoint with a missed authorization check or an injectable parameter can be worth more to an attacker than the rest of the perimeter combined.
This engagement does not stop at an automated top-10 checklist: every layer a request passes through — injection, access control, transport, and the HTTP layer itself — is in scope, and every automated finding is verified by hand before it is called real.
What to expect
Agree the target, accounts, and rules of engagement before a single request is sent.
Enumerate live endpoints, parameters, and technologies so testing is targeted, not blind.
Injection, access control, auth, transport, and configuration, run through the Security Console.
Findings ranked by real business risk, then a retest once fixes ship.
Tell us about your application or infrastructure and we will follow up with next steps.