PENETRATION TESTING

OVERVIEW
TYPES OF PENETRATION TESTING SERVICES
The Web Application Penetration Testing simulates a malicious application user that attacks the application in scope – assuming knowledge of credentials by attempting to circumvent the application’s logic or by taking advantage of potential application’s security weaknesses in order to obtain unauthorized access to the data served by the application with respect to the confidentiality, integrity and availability of the latter.
More specifically, the attack vectors within the context of the testing will evaluate the ability of a malicious user to:
- Obtain unauthorized access to sensitive data
- Modify, corrupt or destroy data
- Attack application’s users
- Perturb the application and its components
- Change or introduce software, malicious or otherwise
The objective of the testing is (a) to discover – in depth – and exploit any security weaknesses on the application, (b) to identify the level of risk associated with these weaknesses and (c) to recommend countermeasures to mitigate the associated risk.
In-depth, fully OWASP compliant manual assessment on every area of interest i.e. Authentication, Session Management, Access controls, Input validation, Business Logic, is performed by Labs’ highly skilled and certified Penetration Testers. Exploitation upon authorization is included in order to identify synergies among identified vulnerabilities.
The testing is conducted by combining industry leading automated testing tools, along with Obrela Labs’ manual testing methods that aim to identify and exploit vulnerabilities according to the OWASP framework


OUR METHODOLOGY | OWASP FRAMEWORK
In-depth, fully OWASP compliant manual assessment on every area of interest i.e. Authentication, Session Management, Access controls, Input validation, Business Logic, is performed by Obrela Labs’ highly skilled and certified Penetration Testers. Exploitation upon authorization is included in order to identify synergies among identified vulnerabilities.
The penetration testing service is conducted by combining industry leading automated testing tools, along with Obrela Labs’ manual testing methods that aim to identify and exploit vulnerabilities according to the OWASP framework.
A CREST CERTIFIED COMPANY
ABOUT CREST
CREST Certification: A Global Benchmark
CREST certification is recognized internationally as a benchmark of excellence in cybersecurity. It signifies that Obrela Labs has met stringent criteria for technical expertise, ethical conduct, and a commitment to ongoing professional development.Expertise and Cutting-Edge Knowledge
By achieving CREST certification, Obrela Labs showcases its exceptional expertise in areas such as penetration testing and simulated target attack and response (STAR) penetration testing. This certification is a testament to the team's advanced knowledge of the latest tools, tactics, and procedures in the ever-evolving cybersecurity landscape.Client Confidence and Assurance
For clients, Obrela Labs' CREST certification provides peace of mind. It assures them that they are partnering with a trusted organization that adheres to the highest industry standards. With this certification, clients can trust that their cybersecurity needs are in the hands of true professionals who are committed to delivering the best possible service.Continued Commitment to Excellence
Obrela Labs' pursuit of CREST certification exemplifies its ongoing dedication to excellence in the field of cybersecurity. It is a commitment to continuously enhancing its capabilities, staying up-to-date with emerging threats, and ensuring that clients receive the most effective and reliable cybersecurity solutions available.
ACCREDITATIONS







