Cada superfície de ataque que entrega, testada manualmente.
Seis áreas de prática especializadas, um modelo de entrega. Escolha os ativos que precisam de testes, ou defina um compromisso combinado para todos.
Cada superfície que coloca em produção, testada manualmente.
Escolha um tipo de ativo ou os seis — o âmbito determina o preço, e nada é incluído sem necessidade.
Role-aware web testing and REST/GraphQL API coverage, including undocumented routes.
- OWASP Top 10 + logic flaws
- REST & GraphQL endpoint testing
- Multi-role authz + rate limits
iOS and Android binaries plus their backend APIs.
- Static and runtime analysis
- Local storage and keychain
- Certificate pinning bypass
Internal or external hosts, on-prem or hosted.
- Service and version exposure
- Credential and lateral paths
- Segmentation checks
AWS, Azure and GCP account review.
- IAM privilege escalation
- Public storage and secrets
- Logging and guardrails
Phishing and pretext campaigns with consent.
- Targeted phishing waves
- MFA fatigue attempts
- Awareness reporting
Full adversary simulation testing detection, response and resilience.
- Multi-stage attack chains
- Detection and response gaps
- MITRE ATT&CK mapping
Cada área de prática, em detalhe.
Cada página cobre âmbito, funcionalidades, metodologia, descobertas de exemplo e FAQs especializadas.
Role-aware web testing and REST/GraphQL API coverage, including undocumented routes.
- OWASP Top 10 + logic flaws
- REST & GraphQL endpoint testing
- Multi-role authz + rate limits
iOS and Android binaries plus their backend APIs.
- Static and runtime analysis
- Local storage and keychain
- Certificate pinning bypass
Internal or external hosts, on-prem or hosted.
- Service and version exposure
- Credential and lateral paths
- Segmentation checks
AWS, Azure and GCP account review.
- IAM privilege escalation
- Public storage and secrets
- Logging and guardrails
Phishing and pretext campaigns with consent.
- Targeted phishing waves
- MFA fatigue attempts
- Awareness reporting
Full adversary simulation testing detection, response and resilience.
- Multi-stage attack chains
- Detection and response gaps
- MITRE ATT&CK mapping
Não tem a certeza de quais superfícies se aplicam a si?
Inicie o formulário de âmbito. Orienta-o pelas perguntas que o seu auditor vai fazer, e produz uma proposta no final.
