Where applicable, volume discount applied at checkout. Login for reseller pricing.
An Application Penetration Test is an ethical attack simulation that is intended to expose the effectiveness of an application's security controls by highlighting risks posed by actual exploitable vulnerabilities. The pentest model is built around a manual testing process. This process is intended to go much further than the generic responses, false positive findings, and lack of depth provided by automated application assessment tools.
Using our methods, Trustwave is able to demonstrate actual exploitable vulnerabilities within an application. The testing results provide a detailed deliverable with both tactical and strategic recommendations that are both actionable and advisory in nature. This practice aids clients in pinpointing flaws and mitigating the risk of compromise. The results of every Application Penetration Test include complete details on application security issues, exploitation results, and both tactical and strategic recommendations.
The increased use of varied Web applications to handle confidential data is a concern for many organizations. While the comfortable interface of a Web-based application is certainly convenient, it is accompanied by an increase risk. Using Trustwave to conduct application penetration testing on Web-based applications provides clients with a comprehensive pentest of the entire Web application and application environment. These applications can be both internally and externally facing requiring both onsite and offsite (remote) testing by our team of application security experts.
While Web-based applications garner much more of the security industry's attention, thin client application security is no less important. Using Trustwave to conduct testing of thin client applications provides clients with a comprehensive test and exposes risks associated with these types of applications.
Just as thin clients are often overlooked, thick client applications are often ignored during security testing. Limited or no reliance on a server does not eliminate risk of data compromise. Trustwave is available to conduct thick client application security testing.
Internal developers creating applications are not always aware of current security risks, vulnerabilities or exploits. As a supplement to performing code review, Trustwave provides a customized training class to an organization's developers based upon industry best practices and the results of the actual reviews performed. This service has been found to be more effective in mitigating future secure coding errors by developers because they are trained on examples taken from their applications.