Application Penetration Testing & Security Validation

Know where
you're exposed.

zBreach provides application penetration testing and security validation designed to identify, validate, prioritize, and document exploitable security weaknesses. Eighteen test modules, one assessment, one report.

You verify ownership of a domain before zBreach tests it.

Assessment report · findings
High Missing Content-Security-Policy
Automated · security headers · confidence high
OWASP A05 · ISO/IEC 27001 A.8.9 · SOC 2 CC6.6
Critical Secret exposed in JavaScript bundle
Automated · JS asset analysis · confidence high
Evidence and reproduction captured
Medium TLS certificate expires in 12 days
Automated · SSL/TLS · confidence high
Remediation included
18
Test modules
Transport, application, identity, code and cloud exposure
5
Control frameworks referenced
OWASP, PCI DSS, NIST 800-53, ISO/IEC 27001, SOC 2
3
Report formats
Executive PDF, technical HTML, machine-readable JSON

Find it. Prove it. Fix it. Verify it.

How an assessment runs

One pass over the target, one set of findings, one report. Nothing is queued behind a consultant's calendar.

Find it

Eighteen modules test the target in a single assessment: transport, headers, exposed services, injection, identity, client-side code, and cloud and email exposure.

Prove it

Findings are deduplicated across modules and carry the module that raised them and a confidence level. Where a module confirms the behaviour, the captured evidence and the reproduction steps travel with the finding.

Fix it

Every finding carries a severity, a CVSS v3.1 baseline derived from that severity, the affected location, and remediation guidance an engineer can act on.

Verify it

Schedule the assessment to re-run and compare the exposure score for a target across runs, so a fix is visible rather than asserted.

18 test modules

What zBreach tests

Every module runs against the target you authorised, in one assessment, and reports into the same finding model.

SSL/TLS

Transport

Certificate validation and expiry, cipher strength, protocol versions and known transport weaknesses.

Security headers

Transport

CSP, HSTS, X-Frame-Options, Referrer-Policy and Permissions-Policy, checked for presence and for weak values.

Ports and services

Network

Open ports and the services behind them, so the attack surface reaching the internet is the one you meant to expose.

Injection and traversal

Application

SQL injection, cross-site scripting and path traversal across crawled pages and parameters, with reproduction steps.

Technology fingerprinting

Application

Frameworks, content management systems, libraries and server software, including versions where they are disclosed.

Authentication and access

Identity

Session and cookie handling, forced browsing, insecure direct object references and privilege boundaries.

API security

Application

CORS configuration, authentication bypass, rate limiting and HTTP method handling on REST endpoints.

GraphQL

Application

Introspection exposure, query depth and complexity limits, and authorisation on individual resolvers.

JavaScript assets

Client

Endpoints extracted from bundles, source maps left in production, and credentials embedded in client-side code.

JWT and OAuth

Identity

Token signing and validation, algorithm confusion, and redirect handling in the OAuth flow.

Source code analysis

Code

A connected GitHub repository is checked for committed secrets, vulnerable dependencies and known CVEs in the stack.

Subdomain discovery

Surface

Certificate-transparency enumeration and DNS resolution, including hosts pointing at a service that no longer claims them.

Exposed secrets

Surface

Environment files, backup archives, open version-control directories and API keys reachable without authentication.

File upload

Application

Content-type and extension enforcement, SVG-borne scripting, and whether an uploaded file becomes reachable.

Redirects and SSRF

Application

Open redirect chains and server-side request forgery probes, including analysis of multi-hop chains.

Email security

Domain

SPF, DKIM and DMARC policy, MX configuration and opportunistic transport encryption on the domain's mail path.

Cloud exposure

Cloud

Publicly readable object storage, exposed managed databases and search clusters, and reachable metadata endpoints.

Signature templates

Known issues

Community-maintained Nuclei templates for known CVEs and misconfigurations. These are known-signature checks, and the module runs when the Nuclei engine is installed on the host.

Reporting

A report you can hand to someone

The same assessment produces the document an executive reads, the detail an engineer works from, and the data your own systems consume.

  • Executive PDF Severity breakdown, exposure score and rating, prioritised remediation, and the control references for every finding. Each download carries a stable report id.
  • Technical HTML Every finding in full: location, evidence, reproduction where the module captured it, and remediation guidance.
  • JSON The same findings as structured data, for a pipeline that gates a deploy or a dashboard of your own.
  • Control-mapping reports One report per framework, as PDF or JSON, listing the findings against the controls they touch. The mapping is automated and labelled as such — it is evidence for a conversation with your assessor, not an audit opinion.
  • OWASP Top 102021
  • PCI DSSv4.0
  • NIST SP 800-53Rev. 5
  • ISO/IEC 270012022 Annex A
  • SOC 2Trust Services Criteria

Authorised testing

zBreach only tests what you own

Penetration testing without the owner's permission is not a feature. The product is built so that permission is a precondition, not a checkbox.

Ownership is verified first

A domain is proved by a DNS TXT record, a file at a well-known path, or a code sent to an address at the domain, before an assessment runs against it.

Internal hosts are out of reach

Every target is resolved and checked before a request leaves the host. Private, loopback, link-local and cloud metadata addresses are refused.

Assessments identify themselves

Requests carry a zBreach User-Agent, so whoever runs the target can recognise authorised testing in their logs and correlate it with your assessment.

Contact

Talk to us first

A question about coverage, a target that needs a scoping conversation, or an invoice that needs a purchase order — send it here and a person answers.

For anything already running, the fastest path is the account you signed up with: open zBreach and use the history for the assessment in question.

We use what you send here to answer you. Nothing on this form starts an assessment.

Ready

Find out what an attacker would find.

Create an account, verify a domain, and run your first assessment. Results in minutes, not a scheduling call.