Application Penetration Testing & Security Validation
Know where
you're exposed.
zBreach provides application penetration testing and security validation designed to identify, validate, prioritize, and document exploitable security weaknesses. Eighteen test modules, one assessment, one report.
You verify ownership of a domain before zBreach tests it.
Find it. Prove it. Fix it. Verify it.
How an assessment runs
One pass over the target, one set of findings, one report. Nothing is queued behind a consultant's calendar.
Find it
Eighteen modules test the target in a single assessment: transport, headers, exposed services, injection, identity, client-side code, and cloud and email exposure.
Prove it
Findings are deduplicated across modules and carry the module that raised them and a confidence level. Where a module confirms the behaviour, the captured evidence and the reproduction steps travel with the finding.
Fix it
Every finding carries a severity, a CVSS v3.1 baseline derived from that severity, the affected location, and remediation guidance an engineer can act on.
Verify it
Schedule the assessment to re-run and compare the exposure score for a target across runs, so a fix is visible rather than asserted.
18 test modules
What zBreach tests
Every module runs against the target you authorised, in one assessment, and reports into the same finding model.
SSL/TLS
TransportCertificate validation and expiry, cipher strength, protocol versions and known transport weaknesses.
Security headers
TransportCSP, HSTS, X-Frame-Options, Referrer-Policy and Permissions-Policy, checked for presence and for weak values.
Ports and services
NetworkOpen ports and the services behind them, so the attack surface reaching the internet is the one you meant to expose.
Injection and traversal
ApplicationSQL injection, cross-site scripting and path traversal across crawled pages and parameters, with reproduction steps.
Technology fingerprinting
ApplicationFrameworks, content management systems, libraries and server software, including versions where they are disclosed.
Authentication and access
IdentitySession and cookie handling, forced browsing, insecure direct object references and privilege boundaries.
API security
ApplicationCORS configuration, authentication bypass, rate limiting and HTTP method handling on REST endpoints.
GraphQL
ApplicationIntrospection exposure, query depth and complexity limits, and authorisation on individual resolvers.
JavaScript assets
ClientEndpoints extracted from bundles, source maps left in production, and credentials embedded in client-side code.
JWT and OAuth
IdentityToken signing and validation, algorithm confusion, and redirect handling in the OAuth flow.
Source code analysis
CodeA connected GitHub repository is checked for committed secrets, vulnerable dependencies and known CVEs in the stack.
Subdomain discovery
SurfaceCertificate-transparency enumeration and DNS resolution, including hosts pointing at a service that no longer claims them.
Exposed secrets
SurfaceEnvironment files, backup archives, open version-control directories and API keys reachable without authentication.
File upload
ApplicationContent-type and extension enforcement, SVG-borne scripting, and whether an uploaded file becomes reachable.
Redirects and SSRF
ApplicationOpen redirect chains and server-side request forgery probes, including analysis of multi-hop chains.
Email security
DomainSPF, DKIM and DMARC policy, MX configuration and opportunistic transport encryption on the domain's mail path.
Cloud exposure
CloudPublicly readable object storage, exposed managed databases and search clusters, and reachable metadata endpoints.
Signature templates
Known issuesCommunity-maintained Nuclei templates for known CVEs and misconfigurations. These are known-signature checks, and the module runs when the Nuclei engine is installed on the host.
Reporting
A report you can hand to someone
The same assessment produces the document an executive reads, the detail an engineer works from, and the data your own systems consume.
- Executive PDF Severity breakdown, exposure score and rating, prioritised remediation, and the control references for every finding. Each download carries a stable report id.
- Technical HTML Every finding in full: location, evidence, reproduction where the module captured it, and remediation guidance.
- JSON The same findings as structured data, for a pipeline that gates a deploy or a dashboard of your own.
- Control-mapping reports One report per framework, as PDF or JSON, listing the findings against the controls they touch. The mapping is automated and labelled as such — it is evidence for a conversation with your assessor, not an audit opinion.
Frameworks referenced
- OWASP Top 102021
- PCI DSSv4.0
- NIST SP 800-53Rev. 5
- ISO/IEC 270012022 Annex A
- SOC 2Trust Services Criteria
Contact
Talk to us first
A question about coverage, a target that needs a scoping conversation, or an invoice that needs a purchase order — send it here and a person answers.
For anything already running, the fastest path is the account you signed up with: open zBreach and use the history for the assessment in question.
Ready
Find out what an attacker would find.
Create an account, verify a domain, and run your first assessment. Results in minutes, not a scheduling call.