• Profiling of the target application is performed to understand the core security mechanisms and functionalities employed by the application, interfaces to external or internal applications.
• Run automated scans (i.e. commercial and open-source) to identify application specific vulnerabilities covering all OWASP, WASC and SANS references.
• Complete Manual security testing is performed using various sources and techniques to identify vulnerabilities such as business logic flaws, broken access controls and more that were missed during automated scans.
• All exploitable security vulnerabilities in the target application are reported based on CVSS v3 score. The identified security vulnerabilities are assessed thoroughly and reported along with appropriate recommendation or mitigation measures.
• Assist the client throughout the remediation process and perform re-validation to verify the effectiveness of the application security countermeasures used to mitigate the reported security vulnerabilities.