04 · Manual · Chain · Prove
Web Application Pen Testing
OWASP-plus testing for modern web + API stacks.
Deep manual testing of your web application, its APIs, and the infrastructure behind them — the full OWASP WSTG, plus the business-logic and auth-chain flaws scanners systematically miss. We cover the modern edge cases too: SPA hydration, streaming SSR/RSC, edge runtimes. AI clears the coverage floor; operators find the bugs that end careers.
Outcomes
- +Full OWASP ASVS 4.0 Level 2 or 3 coverage report
- +Business-logic flaw enumeration — the category scanners can't see
- +A working exploit chain for every high/critical finding
- +Detection guidance for your WAF and application logs
01Scope
What we cover
In scope
- +Public application + every authenticated role + admin panel
- +REST / GraphQL / gRPC / WebSocket APIs
- +Authentication, session management, MFA, and SSO flows
- +Business-logic testing — race conditions, coupon abuse, workflow bypass
- +Modern-framework edge cases (SSR/RSC hydration, streaming, edge runtime)
- +Client-side SPA flaws (DOM XSS, prototype pollution)
Out of scope
- −Infrastructure-level testing (see Network Pen Testing)
- −Denial-of-service testing (opt-in only)
- −Third-party SaaS integrations owned by external vendors
02Approach
How the engagement runs
Reconnaissance + mapping
Full route discovery, endpoint enumeration, tech-stack fingerprinting. A complete target model before a single test fires.
Enumeration
Every role mapped independently; the trust boundaries between them drawn. Role escalation and IDOR hide right here.
Vulnerability Analysis
Authenticated + unauthenticated passes; AI-assisted coverage across the WSTG; candidate findings confirmed by hand.
Exploitation — business logic + chains
Race conditions, checkout tampering, workflow bypass. Individual bugs are often low severity; chained, they're catastrophic. We build the chain and show the blast.
Post-exploitation
What the chain reaches — data, adjacent tenants, backend systems.
Report + WAF guidance
Findings + reproduction (PoC / Burp files) + WAF and log-detection rules.
03Deliverables
What you receive
Every artifact is defensible under external audit and actionable for engineering.
- 01WAPT Report (executive + technical + appendices)
- 02OWASP ASVS 4.0 coverage matrix (Level 2 or 3)
- 03Working PoC scripts / Burp files for every critical finding
- 04WAF + logging detection rule recommendations
- 05One free retest of critical + high findings within 90 days
04Frameworks
Regulator-defensible mapping
05Timeline
Typical engagement pace
Scoping
1 week
Testing
3–5 weeks
Reporting
1 week
Retest
3 days
06FAQ
Common questions
Different question? Raise it on a scoping call — we'd rather flag surprises early.
How is this different from a plain pen test?+
WAPT goes deep on the web + API surface. If your risk spans network + web + AI, the umbrella Penetration Testing engagement is the better fit. If the crown jewels live in the app, this is the sharp instrument.
Do you test staging or production?+
Both, with different rules of engagement per environment. Production tests use rate limits and non-destructive payloads.
Can you test against our WAF?+
Yes — with and without WAF paths. We report which rules blocked which attacks, and exactly where the WAF was bypassed.
Ship secure by default.
Scoping call, engagement letter, kickoff — typically all inside 3 weeks. Report within 6–8 weeks of kickoff.
Book a scoping call