Application pentest

A penetration test for web applications and/or APIs is primarily focused on the application layer. Since insight into potential vulnerabilities and weaknesses in breadth (over depth) is often desired, it is effectively a vulnerability assessment.

Test activities are performed using a comprehensive methodology with known and relevant attack vectors. Our methodology is based on various (open) standards, including the Penetration Testing Execution Standard (PTES) and includes the following lists of common risks compiled by OWASP:

Top 10 Web Application Security Risks

Top 10 API Security Risks