Scope and authorize
We agree builds, platforms, privilege model and test window in writing.
A test of the software you install on other people’s machines — desktop applications, thick clients, browser extensions and endpoint agents — focused on what it lets a local user become, and what its update channel could deliver.
Installed software runs with privileges the user does not have, on machines the attacker may already stand on. A weak file permission, a hijackable library path or an unsigned update can turn your product into the local privilege escalation somebody else was looking for.
We test the application, the service it installs, how the two talk, and how it updates itself.
Typically one to two weeks, depending on components and platforms.
We agree builds, platforms, privilege model and test window in writing.
We watch exactly what the installer creates, with which permissions, and what runs afterwards and as whom.
Everything is tested from the privileges a normal employee has — the position a real attacker starts from.
We check whether an attacker on the network or the machine can influence what your software installs next.
Each finding comes with reproduction steps, followed by a readout and a retest.
Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.
A privileged service writable by any local user
Library loading from a path a standard user controls
Credentials or tokens stored in plain text in the install directory
Update checks that accept an unsigned or downgraded package
Local IPC that performs privileged actions for anyone who asks
Missing something on this list? Bring it to the call — we scope around what you have.
Find and prove the weaknesses in your web applications before attackers do.
Read moreKeep the APIs that connect your products, partners and data from becoming the way in.
Read moreConfidence that one of your customers can never reach another customer’s data.
Read moreKeep your iOS and Android apps — and the services behind them — out of attackers’ hands.
Read moreNot sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.
Free. No obligation.