Case studies · Four engagements
What the work looks like.
Four engagements, described the way they ran: what was scoped, how it was approached, what classes of finding came out, and what changed afterwards. Clients are named only where the work is already public, and findings are described by class rather than by reproduction detail.
Engagements
One engagement across six banking asset classes
A commercial bank tested across internet banking, APIs, the Android app, ATM and CDM terminals, servers and desktop applications in a single consolidated engagement.
Logistics and mobilityCustomer data exposure on a UAE logistics platform
Penetration testing of a UAE logistics and delivery platform, where authorisation gaps exposed customer information across account boundaries.
SaaSAuthentication bypass in an internal SaaS platform
Penetration testing of an internal management platform that surfaced critical authentication bypass and access-control flaws reachable by any authenticated user.
Fintech and paymentsEnd-to-end VAPT for a payments platform
Application, API and infrastructure assessment for a Saudi payments platform, focused on transaction logic, race conditions and the boundaries between customers.
Attack scenarios
Alongside the engagements above we publish a page per vulnerability class: how the attack unfolds, what it costs, how a tester confirms it and the control that holds.
SQL injection in e-commerce
SQL injection, or SQLi, can turn one unparameterised product filter into a read of every customer name, address, order and password hash. How to test for it.
High to Critical · HealthcareStored XSS account takeover
Stored XSS: text saved in a patient message field runs inside the clinician console, drives the staff session and reads every record that account can reach.
Critical · InsuranceServer-side request forgery
Server-side request forgery (SSRF) can turn a URL field into theft of a server's cloud credentials, and then every file in storage. How we test for it.
High to Critical · HR and payroll softwareGraphQL introspection and batching
Introspection maps the GraphQL schema, a missing field authorisation check opens the records, and alias batching reads thousands of them in one POST.
Critical · Travel and hospitalityOAuth account takeover
A loose redirect_uri check leaks an OAuth code, letting an attacker take over an SSO account and reach the loyalty balance and passport data inside it.
Critical · ManufacturingKerberoasting to Domain Admin
Kerberoasting lets any authenticated domain user crack a service account password offline and reach Domain Admin, with no failed logons and no lockouts.
Critical (conditional) · Government and public sectorDependency confusion
Dependency confusion lets an attacker register your internal package name on npm or PyPI, so the next build installs theirs and runs it on the build agent.
Wider sample
A non-exhaustive list of delivered engagement types, described by sector and scope.
| Sector | Scope | Outcome |
|---|---|---|
| Banking | Internet banking web apps, banking APIs, Android app, ATM & CDM, servers and network | Full VAPT with R&D phase and consolidated reporting |
| Aviation | Global private-jet charter booking platform | Vulnerability assessment across the booking and account surface |
| Logistics · UAE | Luggage pickup and airport drop platform | Customer information exposure identified and remediated |
| SaaS | Internal workforce management application | Critical authentication bypass and access-control flaws |
| Mobile · SAST | Consumer mobile application source code | Manual static review with source-aware remediation guidance |
| Web | Consumer web platform | Authentication, authorisation and user-data protection assessment |
| Insurance | Insurer digital forensics engagement | Disk imaging, registry analysis and deleted-file recovery |
| Fintech · KSA | Payments platform, API and infrastructure | End-to-end VAPT engagement |
Want the full sample report?
A redacted sample report showing the structure, the severity language and the evidence format is available on request under NDA.