Local storage and configuration
Sensitive records, credentials, or security settings exposed in files or application configuration.
Utilities Studio / Cybersecurity
Find out whether changing the desktop client can bypass your controls.
Assess desktop applications for exposed secrets, insecure local data, and trust in client-side controls. Test the client and agreed backend interfaces.
Your desktop application stores sensitive records or connects to internal services. A finding needs to distinguish local behavior from a permission the server should enforce. We assess the installed client and agreed backend interfaces, with evidence that helps your engineers identify the component responsible.
The assessment
Thick-client penetration testing examines a desktop application and the services it communicates with. We assess local data handling and the controls implemented in the client, then investigate whether manipulating the client affects server-side access or behavior. The scope identifies the supported operating system, application build, and backend coverage.
Sensitive records, credentials, or security settings exposed in files or application configuration.
Business rules and access decisions that depend on behavior inside the desktop application.
The requests and data exchanged with the server, including authentication and authorization in scope.
The effect of a modified or unexpected client interaction on protected data and operations.
Working with your team
Confirm the assets, permissions, and production limits. Name the contacts and record the dates, reporting format, support arrangements, and retest terms.
Investigate the agreed attack paths and validate findings. Keep your team updated and escalate critical issues immediately through the agreed channel.
Walk your engineers through the report and remediation priorities. Carry out the agreed retesting and document which fixes worked and what remains unresolved.
Application architecture, operating systems, local components, user roles, and backend access affect the effort. Installation requirements and test-environment setup are established before quoting.
The schedule includes access to a working installation and representative backend services. We agree the build and operating environment before assessment begins.
Pentest delivery
We share validated findings during the test through the agreed secure channel. Critical issues go to your nominated contact immediately. Progress updates cover completed work, blockers, and what comes next.
Your engineers get affected assets, reproduction steps, evidence, and remediation guidance. We explain severity using the demonstrated impact. An executive summary sets out the business risk and the limits of the assessment.
A technical findings review lets your engineers discuss the evidence and recommended fixes with us. We name the technical contact and agree the support period and response arrangements before testing.
Retesting checks fixes to the original findings and records the result. Before booking, we specify the findings covered, retest rounds, time window, and any charges. New features or changed environments need a scope review.
We agree the findings format and handover method with your team. If you use Jira, Linear, or GitHub, we scope the export or ticket handover, required access, and treatment of sensitive evidence before testing.
Your proposal sets the start date, testing window, and report delivery date after we review scope and access. Bring your audit or release deadline so remediation and retesting can be planned around it.
Delivery references: NIST SP 800-115 and CREST's penetration testing programme guide.
The practitioner behind the work
Sheeraz Ali is our Head of Cybersecurity. His work spans application, cloud, network, and AI assessments. His personal track record includes leading pentests at Cobalt and building the internal pentest programme at SolarWinds.
Read Sheeraz's security backgroundSheeraz's personal track record
His website lists OSCP, CRTP, CRTE, CREST CRT and CPSA, CBBH, and CKA.
At SolarWinds, he delivered 120+ internal pentests. As CTO at Pwned Labs, he built a platform serving 40,000+ practitioners. He co-developed Mobexler, selected for Black Hat Arsenal, and presented research at Nullcon and c0c0n.
Explore his career timelineFAQ
A thick client is an application installed on a user device that performs substantial work locally, often while communicating with backend services. Desktop business applications are a common example.
No. A desktop assessment includes the installed client and its local data or behavior. It may also include backend testing, but that coverage must be agreed explicitly.
A user controls the machine running the client. Testing investigates whether changing local behavior can bypass a business rule or gain access that the server should independently restrict.
Bring the previous report and a list of changes to your code, permissions, or infrastructure. We can use those to scope the next assessment. Check which earlier findings were fixed and which fixes were verified; the date on the old report does not answer those questions.
Assess API authentication, object-level authorization, role boundaries, and sensitive data exposure. Get evidence your developers can reproduce.
Assess internal and external networks for exploitable services, access weaknesses, and routes to sensitive systems. Get evidence and remediation priorities.
Manual penetration testing for your applications, cloud, and networks. Get validated findings with reproduction steps, business impact, and guidance for your engineers.
Tell us what your team needs to resolve, which systems are involved, and any deadline. We will work through the scope and reporting needs with you.