覆盖范围
您部署的每个系统表面,均经手动测试。
选择一种或全部六种资产类型——范围决定价格,不需要的内容不会捆绑计费。
Web / API
Role-aware web testing and REST/GraphQL API coverage, including undocumented routes.
- OWASP Top 10 + logic flaws
- REST & GraphQL endpoint testing
- Multi-role authz + rate limits
Mobile
iOS and Android binaries plus their backend APIs.
- Static and runtime analysis
- Local storage and keychain
- Certificate pinning bypass
Network / infra
Internal or external hosts, on-prem or hosted.
- Service and version exposure
- Credential and lateral paths
- Segmentation checks
Cloud configuration
AWS, Azure and GCP account review.
- IAM privilege escalation
- Public storage and secrets
- Logging and guardrails
Social engineering
Phishing and pretext campaigns with consent.
- Targeted phishing waves
- MFA fatigue attempts
- Awareness reporting
Red teaming
Full adversary simulation testing detection, response and resilience.
- Multi-stage attack chains
- Detection and response gaps
- MITRE ATT&CK mapping
深度解析
每个实践领域,详细介绍。
每个页面涵盖范围、功能、方法论、示例发现和专业FAQ。
Web / API
Role-aware web testing and REST/GraphQL API coverage, including undocumented routes.
- OWASP Top 10 + logic flaws
- REST & GraphQL endpoint testing
- Multi-role authz + rate limits
Mobile
iOS and Android binaries plus their backend APIs.
- Static and runtime analysis
- Local storage and keychain
- Certificate pinning bypass
Network / infra
Internal or external hosts, on-prem or hosted.
- Service and version exposure
- Credential and lateral paths
- Segmentation checks
Cloud configuration
AWS, Azure and GCP account review.
- IAM privilege escalation
- Public storage and secrets
- Logging and guardrails
Social engineering
Phishing and pretext campaigns with consent.
- Targeted phishing waves
- MFA fatigue attempts
- Awareness reporting
Red teaming
Full adversary simulation testing detection, response and resilience.
- Multi-stage attack chains
- Detection and response gaps
- MITRE ATT&CK mapping
