Penetration Testing
Penetration Testing

Test uw beveiliging zoals een echte aanvaller dat zou doen.

Test your security the way a real attacker would.

Met Penetration Testing van OranjeRaksha testen we uw webapplicaties, API’s, mobiele apps, thick clients, netwerken, Active Directory, cloud en identity-omgeving binnen duidelijke spelregels.

We combineren geautomatiseerde tooling met handmatig onderzoek, exploitatie binnen afgesproken grenzen en realistische aanvalspaden. Het resultaat is niet alleen een lijst kwetsbaarheden, maar bewijs van impact, prioriteit en concrete herstelacties.

With Penetration Testing from OranjeRaksha, we test your web applications, APIs, mobile apps, thick clients, networks, Active Directory, cloud and identity environment within clear rules of engagement.

We combine automated tooling with manual analysis, controlled exploitation and realistic attack paths. The result is not just a list of vulnerabilities, but evidence of impact, priority and concrete remediation actions.

Web & API pentesting Mobile & thick clients Netwerk, AD & cloud OWASP · NIS2 · ISO 27001 Web & API pentesting Mobile & thick clients Network, AD & cloud OWASP · NIS2 · ISO 27001

Wat is Penetration Testing?

What is Penetration Testing?

Penetration Testing is een gecontroleerde, geautoriseerde aanvalssimulatie waarmee we toetsen of kwetsbaarheden daadwerkelijk misbruikbaar zijn.

Penetration Testing is a controlled, authorised attack simulation that verifies whether weaknesses are actually exploitable.

Waar een Vulnerability Assessment vooral kwetsbaarheden identificeert en prioriteert, gaat een Penetration Test verder: we onderzoeken welke bevindingen kunnen worden benut, welke aanvalspaden mogelijk zijn en welke business-impact daaruit ontstaat.

Where a Vulnerability Assessment mainly identifies and prioritises weaknesses, a Penetration Test goes further: we examine which findings can be exploited, which attack paths are possible and what business impact they create.

Alles gebeurt binnen vooraf afgesproken spelregels: scope, testvensters, contactpersonen, veiligheidsgrenzen en communicatieafspraken worden vóór de test vastgelegd.

Everything is performed within agreed rules of engagement: scope, test windows, contact points, safety limits and communication procedures are defined before testing starts.

Waarom is het belangrijk?

Why does it matter?

Beleid, tooling en controles zijn pas echt waardevol als ze ook standhouden tegen realistische aanvalsscenario’s.

Policies, tooling and controls are only truly valuable when they withstand realistic attack scenarios.

Penetration Testing maakt zichtbaar welke zwakke plekken direct leiden tot datalekken, account-takeover, privilege escalation, laterale beweging of verstoring van kritieke processen.

Penetration Testing shows which weaknesses can directly lead to data exposure, account takeover, privilege escalation, lateral movement or disruption of critical processes.

Voor veel organisaties is een pentest ook belangrijk bewijs voor NIS2, ISO 27001, klantcontracten, secure development, cloudmigraties, change management en periodieke security assurance.

For many organisations, a pentest also provides important evidence for NIS2, ISO 27001, customer contracts, secure development, cloud migrations, change management and periodic security assurance.

Voor wie
Who Is This For?

Voor wie is dit?

Who is this for?

Penetration Testing is relevant voor organisaties die willen weten of hun digitale omgeving niet alleen kwetsbaar is, maar ook daadwerkelijk misbruikbaar.

Penetration Testing is relevant for organisations that want to know not only whether their environment is vulnerable, but whether it is actually exploitable.

🛡️
CISO / Security Manager
CISO / Security Manager

Wil aanvalspaden, impact en prioriteiten objectief onderbouwen.

Wants objective evidence of attack paths, impact and priorities.

💻
IT & Cloud Teams
IT & Cloud Teams

Wil misconfiguraties, identity-risico’s en segmentatieproblemen vinden.

Wants to find misconfigurations, identity risks and segmentation issues.

🧪
Development Teams
Development Teams

Wil web-, API-, mobile- en thick-client risico’s vóór release oplossen.

Wants to resolve web, API, mobile and thick-client risks before release.

📋
Compliance Officer
Compliance Officer

Heeft auditwaardig bewijs nodig voor NIS2, ISO 27001 of klantvereisten.

Needs audit-grade evidence for NIS2, ISO 27001 or customer requirements.

🚀
Product Owners
Product Owners

Wil zekerheid vóór lancering, migratie of grote wijziging.

Wants assurance before launch, migration or major change.

🏢
Management & Risk
Management & Risk

Wil technische bevindingen vertaald naar bedrijfsrisico en actie.

Wants technical findings translated into business risk and action.


Praktijkvoorbeelden
Real-world Cases

Praktijkvoorbeelden uit pentests

Real-world pentest scenarios

Onderstaande geanonimiseerde scenario’s laten zien hoe kleine fouten kunnen uitgroeien tot serieuze risico’s wanneer ze worden gecombineerd.

The anonymised scenarios below show how small weaknesses can become serious risks when they are chained together.

Scenario 1 – Webapplicatie & API
Scenario 1 – Web application & API
Van IDOR naar account-takeover
From IDOR to account takeover

Een klantportaal had een API-endpoint waarbij autorisatie onvoldoende werd afgedwongen. Door object-ID’s te manipuleren kon een tester gegevens van andere klanten benaderen en uiteindelijk een account-takeover pad aantonen.

A customer portal had an API endpoint where authorisation was not enforced correctly. By manipulating object IDs, a tester could access other customers’ data and ultimately demonstrate an account takeover path.

De pentest leverde concreet bewijs, reproduceerbare stappen en gerichte fixes op voor autorisatie, logging, rate limiting en secure coding checks.

The pentest delivered concrete evidence, reproducible steps and targeted fixes for authorisation, logging, rate limiting and secure coding checks.

Scenario 2 – Thick client & productie-API
Scenario 2 – Thick client & production API
Hardcoded secrets in desktopapplicatie
Hardcoded secrets in a desktop application

Een interne desktopapplicatie bevatte hardcoded API-keys. Na analyse van de client kon de tester rechtstreeks communiceren met een productie-API en acties uitvoeren buiten de normale gebruikersinterface.

An internal desktop application contained hardcoded API keys. After analysing the client, the tester could communicate directly with a production API and perform actions outside the normal user interface.

De organisatie verving statische secrets door token-gebaseerde toegang, beperkte API-rechten en verbeterde monitoring op afwijkend API-gebruik.

The organisation replaced static secrets with token-based access, reduced API privileges and improved monitoring for abnormal API usage.

Scope & Dekking
Scope & Coverage

Wat is typisch in scope?

What is typically in scope?

Scope wordt altijd vooraf vastgelegd in rules of engagement. Onderstaand overzicht toont wat vaak wel en niet onderdeel is van een standaard pentest.

Scope is always defined upfront in rules of engagement. The overview below shows what is usually included and excluded in a standard pentest.

Typisch in scope
Typically in scope
Webapplicaties, API’s en klantportalenWeb applications, APIs and customer portals
Mobiele apps en thick clientsMobile apps and thick clients
Externe en interne netwerkenExternal and internal networks
Active Directory, identity en privilege escalationActive Directory, identity and privilege escalation
Cloudconfiguratie, IAM en storage exposureCloud configuration, IAM and storage exposure
Gecontroleerde exploitatie en attack-path validatieControlled exploitation and attack-path validation
Rapportage, debrief en optionele her-testReporting, debrief and optional retest
Typisch buiten scope
Typically out of scope
Destructieve acties, dataverwijdering of sabotageDestructive actions, data deletion or sabotage
DDoS- of stresstesten tenzij expliciet afgesprokenDDoS or stress testing unless explicitly agreed
Social engineering of phishing tenzij apart afgesprokenSocial engineering or phishing unless separately agreed
Fysieke toegangstesten tenzij apart afgesprokenPhysical access testing unless separately agreed
OT/SCADA-systemen – zie OT Security AuditOT/SCADA systems – see OT Security Audit
Systemen buiten de schriftelijk overeengekomen scopeSystems outside the written agreed scope

Testdomeinen
Testing Domains

Scope van Penetration Testing

Scope of Penetration Testing

De test wordt afgestemd op uw omgeving, risico’s en volwassenheid. We gebruiken relevante best practices uit OWASP, NIST, ISO 27001 en cloud security guidance.

Testing is tailored to your environment, risks and maturity. We use relevant best practices from OWASP, NIST, ISO 27001 and cloud security guidance.

1. Webapplicaties & API’s

1. Web applications & APIs

We testen authenticatie, autorisatie, inputvalidatie, business logic en API-misbruik.

We test authentication, authorisation, input validation, business logic and API abuse.

  • OWASP Top 10 en API Security Top 10.
  • IDOR/BOLA, sessiebeheer en access-control fouten.
  • Injection, SSRF, deserialisatie en logica-misbruik.
  • OWASP Top 10 and API Security Top 10.
  • IDOR/BOLA, session management and access-control flaws.
  • Injection, SSRF, deserialisation and logic abuse.

2. Externe perimeter & netwerk

2. External perimeter & network

We beoordelen internet-facing systemen zoals VPN, firewalls, portals en servers.

We assess internet-facing systems such as VPNs, firewalls, portals and servers.

  • Exposed services, versies en configuraties.
  • Bekende kwetsbaarheden en misconfiguraties.
  • TLS, authenticatie en remote access risico’s.
  • Exposed services, versions and configurations.
  • Known vulnerabilities and misconfigurations.
  • TLS, authentication and remote access risks.

3. Interne netwerken & Active Directory

3. Internal networks & Active Directory

We simuleren wat mogelijk is na initiële toegang tot het interne netwerk.

We simulate what is possible after initial access to the internal network.

  • Privilege escalation en laterale beweging.
  • AD-misconfiguraties, trust-relaties en credential exposure.
  • Segmentatie, shares, legacy protocollen en logging.
  • Privilege escalation and lateral movement.
  • AD misconfigurations, trusts and credential exposure.
  • Segmentation, shares, legacy protocols and logging.

4. Mobile apps

4. Mobile apps

We testen iOS- en Android-apps inclusief lokale opslag, API-verkeer en reverse engineering risico’s.

We test iOS and Android apps including local storage, API traffic and reverse engineering risks.

  • Tokens, credentials en PII op het device.
  • TLS, certificaatvalidatie en backend-API beveiliging.
  • Tampering, jailbreak/root detectie en secrets.
  • Tokens, credentials and PII on the device.
  • TLS, certificate validation and backend API security.
  • Tampering, jailbreak/root detection and secrets.

5. Thick clients & desktopapplicaties

5. Thick clients & desktop applications

We analyseren lokale applicaties op secrets, lokale opslag, communicatie en privilege-risico’s.

We analyse local applications for secrets, local storage, communication and privilege risks.

  • Hardcoded credentials, API-keys en endpoints.
  • Insecure DLL loading en lokale privilege escalation.
  • Bescherming van configuratie-, licentie- en logbestanden.
  • Hardcoded credentials, API keys and endpoints.
  • Insecure DLL loading and local privilege escalation.
  • Protection of configuration, licence and log files.

6. Cloud & identity

6. Cloud & identity

We beoordelen cloudrechten, IAM, storage, secrets en koppelingen met on-premise omgevingen.

We assess cloud permissions, IAM, storage, secrets and integrations with on-prem environments.

  • IAM-rollen, policies en privilege escalation paden.
  • Storage buckets, secrets, logs en beheerinterfaces.
  • Tenantconfiguratie, conditional access en identity governance.
  • IAM roles, policies and privilege escalation paths.
  • Storage buckets, secrets, logs and management interfaces.
  • Tenant configuration, conditional access and identity governance.

Onze aanpak
Our Approach

Onze aanpak

Our approach

Onze aanpak is praktisch, gecontroleerd en transparant. We zorgen dat technische diepgang wordt vertaald naar bruikbare prioriteiten voor IT, development, security, audit en management.

Our approach is practical, controlled and transparent. We translate technical depth into useful priorities for IT, development, security, audit and management.

1
Stap 1
Step 1
Scoping & rules of engagement
Scoping & rules of engagement

We bepalen doelen, systemen, accounts, testvensters, toegestane technieken en escalatiecontacten.

We define objectives, systems, accounts, test windows, permitted techniques and escalation contacts.

ScopeSafetyContacts
2
Stap 2
Step 2
Reconnaissance & threat modelling
Reconnaissance & threat modelling

We verzamelen informatie over technologie, endpoints, rollen, afhankelijkheden en mogelijke aanvalspaden.

We gather information about technology, endpoints, roles, dependencies and possible attack paths.

Attack surfaceThreats
3
Stap 3
Step 3
Exploitation & chaining
Exploitation & chaining

We testen gecontroleerd of kwetsbaarheden misbruikbaar zijn en combineren bevindingen tot realistische aanvalspaden.

We test whether weaknesses are exploitable and chain findings into realistic attack paths.

ExploitabilityAttack paths
4
Stap 4
Step 4
Impactvalidatie
Impact validation

Waar toegestaan tonen we de echte impact aan: data-exposure, privilege escalation, laterale beweging of misbruik van functies.

Where allowed, we demonstrate real impact: data exposure, privilege escalation, lateral movement or abuse of functionality.

ImpactEvidence
5
Stap 5
Step 5
Rapportage & prioritering
Reporting & prioritisation

U ontvangt een auditwaardig rapport met managementsamenvatting, technische details, bewijs, risico-inschatting en hersteladvies.

You receive an audit-grade report with executive summary, technical details, evidence, risk rating and remediation advice.

NIS2ISO 27001OWASP
6
Stap 6
Step 6
Debrief, begeleiding & her-test
Debrief, guidance & retest

We lichten bevindingen toe aan uw teams en kunnen na herstel een her-test uitvoeren om fixes te valideren.

We explain findings to your teams and can perform a retest after remediation to validate fixes.

DebriefHer-test optioneelDebriefRetest optional

Gevoelige informatie wordt met de grootst mogelijke zorgvuldigheid behandeld en veilig vernietigd na de retentieperiode.

Sensitive information is handled with utmost care during the assessment and securely destroyed after the retention period.

Wat u ontvangt
What You Receive

Wat ontvangt u?

What you receive

Elke Penetration Test levert een duidelijk, auditwaardig pakket op dat bruikbaar is voor technische teams én besluitvorming.

Every Penetration Test delivers a clear, audit-grade package usable by technical teams and decision makers.

📄
Managementsamenvatting
Executive Summary

Heldere uitleg van risico’s, impact en prioriteiten voor management en risk teams.

Clear explanation of risks, impact and priorities for management and risk teams.

🧪
Technisch bevindingsrapport
Technical Findings Report

Per bevinding: bewijs, stappen, impact, risico en hersteladvies.

For each finding: evidence, steps, impact, risk and remediation advice.

🧭
Attack-path analyse
Attack-path analysis

Inzicht in hoe kwetsbaarheden gecombineerd kunnen worden tot echte aanvalspaden.

Insight into how weaknesses can be combined into real attack paths.

🗺️
Herstelroadmap
Remediation Roadmap

Prioriteitenlijst met quick wins, structurele verbeteringen en eigenaarschap.

Prioritised list with quick wins, structural improvements and ownership.

🤝
Debrief & teamsessie
Debrief & Team Session

Live toelichting voor IT, security, development, cloud en management.

Live walkthrough for IT, security, development, cloud and management.

🔁
Optionele her-test
Optional Retest

Validatie van opgeloste bevindingen met aanvullend bewijs voor audit en compliance.

Validation of resolved findings with additional evidence for audit and compliance.

Wilt u weten welke kwetsbaarheden in uw omgeving écht misbruikbaar zijn? Deel kort uw applicaties, netwerken of cloudomgeving en wij helpen u de juiste pentest-scope te bepalen.

Want to know which weaknesses in your environment are truly exploitable? Share a short overview of your applications, networks or cloud environment and we will help define the right pentest scope.

Vraag uw Penetration Test aanRequest Your Penetration Test

Geen verplichtingen. Wij reageren doorgaans binnen 1 werkdag.No commitment. We typically respond within 1 business day.


Veelgestelde vragen
Frequently Asked Questions

Veelgestelde vragen

Frequently Asked Questions


Gerelateerde diensten
Related Services

Heeft u ook dit nodig?

You might also need

Penetration Testing werkt het best als onderdeel van een bredere security-aanpak. Deze diensten sluiten goed aan.

Penetration Testing works best as part of a broader security approach. These services complement it well.