Application security and penetration testing
Assess applications and APIs for vulnerabilities through manual expertise and appropriate tooling. Testing can cover web applications, APIs, mobile applications and thick-client applications.
Application security activities can also include static application security testing (SAST), dynamic application security testing (DAST) and software composition analysis (SCA), examining source code, running applications and third-party dependencies respectively.
Engagements can include technical findings, executive summaries, remediation guidance and revalidation, as agreed in scope.
