Test d'intrusion d'application webWeb application penetration test
Prestation principaleCore service
Votre application est attaquée comme le ferait un adversaire réel, dans un périmètre convenu à l'avance. Chaque vulnérabilité est démontrée, cotée selon sa criticité et accompagnée de sa correction. Your application is attacked the way a real adversary would, within a scope agreed in advance. Every vulnerability is demonstrated, rated by severity and paired with its fix.
- Boîte noire ou grise, selon l'OWASP WSTGBlack-box or grey-box, following OWASP WSTG
- Authentification, sessions, contrôle d'accèsAuthentication, sessions, access control
- Injections, logique métier, configurationInjections, business logic, configuration
- Rapport avec cotation CVSS et preuvesReport with CVSS ratings and evidence
- Restitution aux équipes techniquesWalkthrough with your technical team
- Contre-vérification après correctionRetest once fixes are deployed