Applications

API & web services pentest

A test of the APIs behind your products and integrations — REST, GraphQL and the endpoints nobody documented — focused on the authorization and rate-limit failures that make an API far easier to abuse than the app in front of it.

9
areas covered
5
stages, scoping to retest
In-house
testers, never subcontracted
portal.cyberlysecure.com/acme-health/coverage
Acme Health — Test coverage4 practices · 15 services · one team
In-house
Web app
API
SaaS
Mobile
Client-side
External
Internal
Segment test
Wireless
Cloud config
Hardware & IoT
AI & LLM
Social eng.
Physical
Red team
ApplicationsNetworkCloud & devicesPeople & premises
6 in scope · one team · one report
In-house testers 0 subcontracted
Every surface one team
What this is

What the test covers.

An API has no interface to hide behind. Every endpoint is reachable, every parameter is editable, and the checks a web front end performs for convenience mean nothing to a client the attacker writes themselves.

We test your API as its own attack surface: what each token can reach, what happens when an identifier is changed, and what an automated caller can do before anything stops them.

OWASP API Security Top 10 OWASP Web Security Testing Guide OWASP ASVS

What we test

  • Object-level authorization — changing an id to reach data that belongs to somebody else
  • Authentication and token handling: JWT validation, OAuth flows, refresh, revocation and expiry
  • Property-level authorization and mass assignment on create and update calls
  • Rate limiting, pagination abuse and unrestricted resource consumption
  • Input validation and injection across every parameter, header and body field
  • GraphQL introspection, query depth, aliasing and batching abuse
  • Server-side request forgery and outbound fetches
  • Undocumented, deprecated and older-version endpoints still answering in production
  • Webhook and callback handling, including signature verification
How it runs

From scoping call to retest, here’s what happens.

Typically one to two weeks, depending on how many endpoints and roles are in scope.

1

Scope and authorize

We agree the endpoints, environments and test windows in writing, and note anything that must not be touched.

2

Build the map

From your specification, traffic capture or the client itself, we enumerate every endpoint — including the ones the documentation forgot.

3

Test authorization first

Every endpoint is exercised with each token type, then with the wrong token, then with no token at all.

4

Push the limits

We test what an automated caller can extract, trigger or exhaust, and what your logging and rate limits do about it.

5

Report, readout and retest

Findings arrive with the exact request that proves them, and we retest your fixes once they ship.

What it surfaces

The kind of thing this test tends to find.

Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.

One customer’s token retrieving another customer’s records by id

Fields accepted on update that were never meant to be client-controlled — roles, balances, flags

Tokens that stay valid after logout, password change or user deactivation

Old API versions still live and still vulnerable long after the new one shipped

Endpoints an automated client can call without limit, in cost or in volume

Getting started

What you get, and what we need from you.

What you get

  • Technical report — Every finding, the evidence behind it and clear guidance your engineers can act on.
  • Executive summary — Your risk explained in plain language for leadership and the board.
  • Attestation letter — Signed confirmation of testing to hand your auditors.
  • Readout call — A walkthrough with the people who tested your systems.
  • Retest — Confirmation your fixes worked, documented for whoever needs to see it.

What we need from you

  • A base URL and an environment that mirrors production
  • Credentials or tokens for each role and, where tenancy matters, two separate accounts
  • An OpenAPI or GraphQL schema, or a traffic capture, if you have one
  • One named contact for the duration of the test

Missing something on this list? Bring it to the call — we scope around what you have.

Free attack-surface snapshot

Give us a domain. See what an attacker sees.

Not sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.

  • Internet-facing hosts
  • Exposed services
  • Leaked credentials
  • TLS certificate hygiene

Request your snapshot

Free. No obligation.

We only ever test assets you own, with your written authorization.