Service

Penetration testing for web applications and APIs

Reliable security assessments for business-critical web applications and APIs.

When this service fits

When web applications or APIs are business-critical, automated scanning is rarely enough. From an attacker’s perspective, I check which vulnerabilities can actually be exploited and what impact they would have on systems, data or processes.

Mobile applications and selected infrastructure are also checked according to scope and project requirements.

What I assess

The focus is on web applications and APIs. To do this, I particularly examine authentication and authorizations, session and data flows, business logic, input validation, configurations and sensible attack chains. Automated tools support testing; the assessment and verification are carried out manually.

What you get

You will receive a comprehensible report with reproducible findings, management-friendly risk classification and concrete measures. Depending on the scope, the test is based on established standards such as OWASP WSTG, OWASP MSTG, PTES and NIST SP 800-115.

  • Management summary with the most important business risks
  • technical findings with evidence, impact and reproduction steps
  • prioritized, actionable recommendations
  • Results discussion with management and technical team
  • upon request, a focused retest of agreed findings

The full synthetic sample report gives an impression of the structure and level of detail.

Typical process

  1. In the initial consultation we clarify the goal, systems, type of test and relevant dates.
  2. The scope records goals, boundaries, test accounts, permitted procedures and emergency contacts.
  3. I check within the agreed time frame and report critical findings immediately.
  4. You receive the report; We then classify risks and measures together.
  5. A retest can be scheduled separately after the fix.

Prerequisites

A written assignment, clearly stated target systems and contact persons are required. Depending on the test, I need test access, role models, API documentation, build files or secure access to the test environment. Productive tests only take place after explicit coordination and with a defined escalation path.

Typical timeframe

Typical total effort: around five to ten project days including testing, evaluation and reporting – depending on roles, interfaces and scope. Complex platforms and multiple roles require more time. You will receive a reliable estimate after the scope has been clarified.

Not included

This does not include unannounced social engineering attacks, denial of service tests, persistent monitoring, full source code audits or tests outside of the approved scope. A test is a time-related sample and is not a guarantee that there are no vulnerabilities at all.

← All services