De test wordt afgestemd op uw omgeving, risico’s en volwassenheid. We gebruiken relevante best practices uit OWASP, NIST, ISO 27001 en cloud security guidance.
Testing is tailored to your environment, risks and maturity. We use relevant best practices from OWASP, NIST, ISO 27001 and cloud security guidance.
1. Webapplicaties & API’s
1. Web applications & APIs
We testen authenticatie, autorisatie, inputvalidatie, business logic en API-misbruik.
We test authentication, authorisation, input validation, business logic and API abuse.
- OWASP Top 10 en API Security Top 10.
- IDOR/BOLA, sessiebeheer en access-control fouten.
- Injection, SSRF, deserialisatie en logica-misbruik.
- OWASP Top 10 and API Security Top 10.
- IDOR/BOLA, session management and access-control flaws.
- Injection, SSRF, deserialisation and logic abuse.
2. Externe perimeter & netwerk
2. External perimeter & network
We beoordelen internet-facing systemen zoals VPN, firewalls, portals en servers.
We assess internet-facing systems such as VPNs, firewalls, portals and servers.
- Exposed services, versies en configuraties.
- Bekende kwetsbaarheden en misconfiguraties.
- TLS, authenticatie en remote access risico’s.
- Exposed services, versions and configurations.
- Known vulnerabilities and misconfigurations.
- TLS, authentication and remote access risks.
3. Interne netwerken & Active Directory
3. Internal networks & Active Directory
We simuleren wat mogelijk is na initiële toegang tot het interne netwerk.
We simulate what is possible after initial access to the internal network.
- Privilege escalation en laterale beweging.
- AD-misconfiguraties, trust-relaties en credential exposure.
- Segmentatie, shares, legacy protocollen en logging.
- Privilege escalation and lateral movement.
- AD misconfigurations, trusts and credential exposure.
- Segmentation, shares, legacy protocols and logging.
4. Mobile apps
4. Mobile apps
We testen iOS- en Android-apps inclusief lokale opslag, API-verkeer en reverse engineering risico’s.
We test iOS and Android apps including local storage, API traffic and reverse engineering risks.
- Tokens, credentials en PII op het device.
- TLS, certificaatvalidatie en backend-API beveiliging.
- Tampering, jailbreak/root detectie en secrets.
- Tokens, credentials and PII on the device.
- TLS, certificate validation and backend API security.
- Tampering, jailbreak/root detection and secrets.
5. Thick clients & desktopapplicaties
5. Thick clients & desktop applications
We analyseren lokale applicaties op secrets, lokale opslag, communicatie en privilege-risico’s.
We analyse local applications for secrets, local storage, communication and privilege risks.
- Hardcoded credentials, API-keys en endpoints.
- Insecure DLL loading en lokale privilege escalation.
- Bescherming van configuratie-, licentie- en logbestanden.
- Hardcoded credentials, API keys and endpoints.
- Insecure DLL loading and local privilege escalation.
- Protection of configuration, licence and log files.
6. Cloud & identity
6. Cloud & identity
We beoordelen cloudrechten, IAM, storage, secrets en koppelingen met on-premise omgevingen.
We assess cloud permissions, IAM, storage, secrets and integrations with on-prem environments.
- IAM-rollen, policies en privilege escalation paden.
- Storage buckets, secrets, logs en beheerinterfaces.
- Tenantconfiguratie, conditional access en identity governance.
- IAM roles, policies and privilege escalation paths.
- Storage buckets, secrets, logs and management interfaces.
- Tenant configuration, conditional access and identity governance.