Application security
Application Penetration Testing
Test the application as a system of users, roles, data flows and business rules, not as a list of endpoints.
The engagement
Test business logic, identity and access
The most serious application weaknesses often sit between features. A user changes roles, an API trusts a client-side decision, a workflow can be repeated out of sequence or one tenant can reach another tenant's data.
GDF tests the application manually and with selected tools, using the documentation, accounts and source context authorized for the engagement. Each finding includes the request or action that produced it, the observed impact, the affected role or data and a clear path for remediation and retesting.
Scope
Web applications
Authenticated and unauthenticated testing of supported browser applications and their server-side behavior.
APIs
Testing of authorization, object access, input handling, rate controls, data exposure and workflow enforcement.
Authentication and sessions
Review of login, recovery, multifactor flows, tokens, cookies, logout and session invalidation.
Authorization and tenancy
Testing of role boundaries, object-level access, administrative functions and separation between customers or business units.
Business logic
Manual testing of sequence, state, pricing, approval and other rules that automated scanners usually cannot understand.
Supported mobile clients
Assessment of the client, local storage, transport and API interaction where mobile testing is included in scope.
Methodology
How the test runs
-
Model
Map users, roles, data, workflows, trust boundaries and prohibited test actions.
-
Test
Combine manual analysis with selected tools across the authorized application and API surface.
-
Validate
Reproduce each material finding and confirm the observed impact without exceeding authorization.
-
Retest
Verify fixes against the original evidence and related variants that could leave the path open.
Evidence commonly examined
Evidence reviewed
- Application inventory and architecture
- Test accounts and role matrix
- Requests, responses and session records
- API specifications and client behavior
- Screenshots and reproducible test steps
- Remediation builds and retest evidence
What you can expect
What you receive
- Application attack-path summary
- Reproducible technical findings
- Role and data-impact mapping
- Remediation guidance and retest record
Frequently asked
Common questions
Do you test APIs separately from the web interface?
Yes. APIs often expose authorization and workflow behavior that cannot be assessed through the interface alone.
Do you need source code?
Not for a black-box or gray-box test. Source access can support a separate white-box review when the engagement calls for deeper code context.
Can testing be performed before release?
Yes. A stable staging environment is often useful, followed by a focused production verification when that is authorized and safe.
Related capabilities
Related services
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189