Skip to main content
REF-APP-003

Web Application VA/PT

Identifies and exploits vulnerabilities in web applications, combining automated scanning with manual exploitation of confirmed findings.

A server pulled out on its rails in a dark aisle
Objectives

What this achieves.

01

Vulnerability identification

Finds and prioritizes security vulnerabilities, including software bugs, misconfigurations, and design flaws.

02

Impact assessment

Determines the potential impact of each vulnerability on the application and its users.

03

Security measure validation

Validates existing security measures and their effectiveness at preventing unauthorized access.

04

Awareness building

Raises awareness among developers and stakeholders of the need for ongoing security testing.

Approach

Five phases.

1

Planning & Preparation

Establish scope, objectives, testing methodology, tools, and resources.

2

Reconnaissance

Gather information on the target application's structure, functionality, and technology.

3

Vulnerability Assessment

Run automated and manual scans to identify potential vulnerabilities.

4

Penetration Testing

Attempt to exploit the vulnerabilities identified in the previous phase.

5

Reporting & Remediation

Document findings and provide actionable remediation guidance.

Executive Summary Detailed Report Vulnerability Evidence Recommendations Knowledge Transfer
Deliverables

What you receive.

01

Executive Summary

A high-level overview of the results: the vulnerabilities found, their impact and severity, and a risk rating.

02

Detailed Report

Detailed information on every vulnerability found, including its description and the evidence of its existence.

03

Vulnerability Evidence

Screenshots, log files, and other evidence demonstrating that each vulnerability exists and what it exposes.

04

Recommendations

Actionable fixes for the vulnerabilities found, and for the security posture of the web application overall.

05

Knowledge Transfer

A presentation and discussion with your team covering the findings, the severe vulnerabilities, and remediation.

FAQ

Common questions.

What does the assessment look for?

Software bugs, misconfigurations, and design flaws, identified and prioritized, with the potential impact of each on the application and its users assessed rather than just listed.

Automated scanning or manual testing?

Both. Automated and manual scans identify potential vulnerabilities during the assessment phase, then the penetration testing phase attempts to exploit what was found.

Do you check whether our existing controls work?

Yes. Validating existing security measures, and how effective they are at preventing unauthorized access, is one of the stated objectives.

What do we receive?

An executive summary, a detailed report, vulnerability evidence, recommendations, and knowledge transfer, with actionable remediation guidance for each finding.

Ready to scope Web Application VA/PT?

Request an Assessment
Request an Assessment Email Us