Skip to content

Penetration Testing

Thick Client Penetration Testing

Thick client applications run logic locally, on the device, which means the trust boundary attackers care about isn't just the network, it's the application itself. Client-side validation, embedded credentials, and local storage can all be inspected, reverse-engineered, and manipulated in ways a web application's server-side controls would normally prevent.

The risk

Why it matters

Thick clients are often built with the assumption that the client side is safe territory, controlled by the organization rather than the end user. That assumption breaks down the moment the application is in the hands of anyone with the right tools. Testing at this level catches vulnerabilities that server-side testing alone will never surface.

Our approach

Testing combines static and dynamic analysis of the client application with attacker-driven testing of its communication and storage layers.

What's covered

Scope & deliverables

Assessment Scope

  • Client application binary & logic
  • Local storage, configuration & credential handling
  • Client-to-server communication protocols
  • Authentication & session management
  • Server-side validation & trust assumptions
  • Local file system and registry security (where applicable)

Deliverables

  • Executive summary
  • Technical report with CVSS-rated findings
  • Proof-of-concept evidence, where applicable
  • Remediation guidance mapped to each finding
  • Optional: One round of post-remediation retesting

Questions

Frequently asked questions

How is Thick Client Penetration Testing different from Web Application Penetration Testing?

Web Application Penetration Testing focuses on browser-based applications and server-side functionality. Thick Client Penetration Testing evaluates desktop applications, including local application logic, stored data, client-to-server communication, and reverse engineering risks. Organizations using desktop software often benefit from both assessments.

What platforms do you support for thick client testing?

Windows, macOS, and Linux desktop applications, along with custom or proprietary client software.

Do you need source code access to test our application?

No. Testing can be performed as a black-box assessment, though source code access can improve depth and efficiency where available.

Is testing conducted on a live environment?

Testing is typically conducted against a staging or test environment, minimizing any risk to production systems.

Do you provide a compliance-ready report?

Yes. Reports can be structured to support PCI-DSS, SOC 2, ISO 27001, and other frameworks based on your industry.

Request a consultation

Tell us what you need assessed and we'll scope an engagement around it — timelines, safeguards, and deliverables agreed before any testing begins.

Request a Consultation