Red Team · engagement type

Web application testing.

OWASP Top 10 walkthrough on customer-facing sites. Manual testing on top of Burp Suite. Injection (SQL, NoSQL, command, template), broken auth, exposed admin, IDOR, CSRF, XSS, file upload, business-logic abuse. Each finding is captured with proof-of-concept evidence preserved in the report appendix.

OWASP Top 10 coverage

How we test

What's in scope vs. not

In scope: the specific URLs, hostnames, and authenticated user accounts named in the Rules of Engagement document. Read-only verification by default; controlled exploitation only when ROE explicitly authorizes it for a specific finding.
Not in scope: DDoS, brute-force credential spraying, mass scanning of customer data (we don't extract, even if we can), social engineering of your staff (separate engagement type).

Pricing

Single web app: from $1,800. One customer-facing site (5-50 pages of authenticated surface). 1-2 weeks. Report + debrief.
Multi-app suite: from $4,500. 2-4 sites that share auth or backend. 2-3 weeks.
API-only test (no browser UI): from $2,200. Useful for partners shipping a customer-data API.