Application Security

Web application pentest, run by an adversary.

Hybrid manual and tooled testing of your web apps, APIs, and auth flows. OWASP WSTG v4.2 is the floor, the depth comes from operator-built business-logic abuse cases that no standard covers.

Hands-on, not scanner dumpsReproducible findingsFree retestUnder NDA
operator@overwatch

What we test

Every layer of the application.

Coverage maps to OWASP WSTG v4.2, ASVS v4.0.3, the API Security Top 10, and the CWE Top 25, then goes further by hand. Authorization and business logic get the deepest push, because that's where the real breaches live.

01

Information Gathering

Subdomain enumeration, CT-log review, exposed dev branches, GitHub/GitLab secret leakage, and framework version fingerprinting.

02

Configuration & Deployment

Security headers, CSP and CORS, TLS and cipher posture, backup files, exposed .git, and forgotten debug endpoints.

03

Identity & Authentication

Login, registration, MFA, SSO and OAuth flows, password reset, plus username enumeration and timing attacks on auth endpoints.

04

Authorization

Deepest push

IDOR/BOLA across every role pair, horizontal and vertical privilege escalation, forced-browse enumeration, and cross-tenant exposure on multi-tenant SaaS.

05

Session Management

Cookie attributes (SameSite, HttpOnly, Secure), JWT algorithm confusion and alg:none, token entropy, and logout invalidation across devices.

06

Input Validation

SQLi, NoSQLi, LDAP, command and template injection; SSRF including blind and cloud-metadata abuse; XXE, deserialization, and prototype pollution.

07

Error Handling

Stack-trace leakage, verbose ORM errors, debug pages, and error responses that leak state as an oracle.

08

Cryptography

JWT algorithm substitution, padding oracles, weak randomness, and key storage, KMS usage, and rotation.

09

Business Logic

Deepest push

Workflow bypass and skip-step abuse, race conditions on coupon/refund/withdraw endpoints, TOCTOU, and multi-step privilege chains.

10

Client-Side

DOM XSS, postMessage abuse, CSP bypass, prototype pollution, and client-side template injection.

11

API Testing

REST, GraphQL, and gRPC. Mass assignment, BOLA/BOPLA, rate-limit bypass, GraphQL introspection, alias abuse, and query-depth DoS.

How it works

Manual-led, evidence-first.

Tools find the obvious. Operators find the rest. Every engagement runs the same disciplined path, and everything is triaged by hand.

01

Recon & mapping

We enumerate the real attack surface, subdomains, endpoints, roles, and APIs, so testing is driven by how the app actually works, not a generic checklist.

02

Manual + tooled testing

Burp, Semgrep, and hand testing across all WSTG phases. Authorization and business logic get the deepest push, with abuse cases built for your specific workflows.

03

Exploit & prove

Every finding is reproduced and shipped with a curl or Burp project you can replay in minutes, never a raw scanner claim you have to take on faith.

04

Report & retest

WSTG-mapped findings with clear remediation guidance, then a retest to confirm the fixes actually hold, signed off by the named operator who tested.

What you get

Deliverables you can act on.

description

Executive Summary

Board-ready PDF: risk register, trend, and the headline finding, in plain language.

article

Technical Report

Full WSTG-mapped findings with reproduction steps and operator notes.

build

Remediation Pack

JIRA-ready CSV with CVSS, CWE, and suggested fix snippets.

radar

Detection Recipes

Sigma and Splunk rules for every exploit chain we landed.

forum

Live Findings Stream

A shared Slack channel, findings posted as we land them, not weeks after.

verified

Retest Letter

Signed letter confirming fixes verified by the named operator who tested.

FAQ

Questions, answered.

What's in scope for an application test?
Your web applications, the REST, GraphQL, or gRPC APIs behind them, and the authentication and authorization flows that tie them together. We agree the exact hosts, roles, and endpoints in the scoping call so there's no ambiguity once testing starts.
Do you test against production or staging?
Either, we prefer a staging environment that mirrors production so we can push hard on business logic without risk to live data. When you need production coverage, we agree the blast radius and rate limits up front and test non-destructively.
Do you need credentials or test accounts?
Yes, for anything past the login wall. We ask for at least two accounts per role so we can prove IDOR, privilege escalation, and cross-tenant issues, the authorization flaws that unauthenticated scanning never reaches.
Which standards do you follow?
Coverage maps to OWASP WSTG v4.2 and ASVS v4.0.3, plus the API Security Top 10 and CWE Top 25. Those are the floor, the depth comes from operator-built abuse cases for your specific workflows, which no checklist covers.
Is a retest included?
Yes. Once you've remediated, we re-test every finding and confirm it's closed, then issue a signed retest letter from the operator who tested. It's part of the engagement, never a separate upsell.

Brief us on the application.

Tell us what you need tested. An operator replies within one business day.