Client-Side Application Security Testing tests “thick” applications that are run and/or installed on an endpoint (workstation, server, etc.).  It is typical to perform this in conjunction with Web Application Security Testing when the application is an “agent” running on the endpoint and interacting with a webservice/API.

Testing involves automated and manual evaluations of one or more applications to ensure they provide protection against abuse of your data. We use industry standard tools to carry out automated scans looking for well known vulnerabilities, and we also conduct manual testing to find vulnerabilities and attack vectors not otherwise detectable by automated tools.

This is more than a simple vulnerability assessment. We actively attempt to circumvent security controls by carrying out exploits that take advantage of discovered vulnerabilities, revealing what an adversary would be able to do. During testing, we look for any method that can violate the CIA Triad security model (confidentiality, integrity, availability).

  • Confidentiality is limiting information to only the authorized person(s) who should have access to it.
  • Integrity is ensuring data/communication at rest or in transit can only originate from, be sent to, or be modified by an authorized person(s).
  • Availability is the ability for an authorized person(s) to access the resources when needed.

The purpose of testing is to enumerate your exposure (within the given time constraints), identify and verify as many vulnerabilities as possible, ensure the security of your application is strong, and then provide actionable solutions to help you protect against attack/compromise. For example, we use industry standard tools to scan for and verify well known/unpatched vulnerabilities that allow an attacker to carry out remote code execution, privilege escalation, circumventing intended controls, gain access to sensitive data, etc. In most cases, we will leverage the discovered vulnerabilities to (1) verify it is exploitable and (2) determine the exposure, should it be breached.

The testing is largely centered around static code analysis, fuzzing, and manual analysis using our internal/proprietary methodologies.

View our Sample Findings and Recommendations Report to see the level of detail PEN Consultants provides in our report.

Sample Pricing
  • Micro: Plugins, extremely basic applications – $4,000
  • Small: Single binary, basic/common functionality – $6,000
  • Medium: Multiple binaries or intermediate functionality – $10,000
  • Large: Multiple binaries, intermediate/advanced functionality, and unique –  $15,000
  • xLarge: Many binaries, advanced functionality, and unique – Varies
Add-On Services

In order to keep our testing prices low, we’ve removed certain services that not every client requests.  You only pay for the following services you need:

  • post-testing briefings – executive level and/or technical level
    • Micro: $275 each, Small: $350 each, Medium: $450 each, Large: $525 each, xLarge: varies
  • remediation testing
    • Micro: $450, Small: $525, Medium: $625, Large: $700, xLarge: varies
  • assist technical support staff with mitigations
    • $700 per 5-hr block of consultant time
  • assist SOC staff in building detections
    • $700 per 5-hr block of consultant time
  • on-site supplemental testing and/or visits:
    • mileage fee of $3 per mile from 78006
    • plus, $250-400 per day for most visits


DISCLAIMER: Sample pricing listed is not actual pricing.  These dollar amounts are estimates based on the number of hours required for engagements of similar size and assumes white box testing and at least a 60-day lead time..  They are provided to give you a ballpark idea of the cost for the service.  The total cost will be based on the estimated number of hours to perform the requested service and our hourly rate.  Black box testing, specific complexities, and other non-standard situations will increase costs.  Additionally, sample pricing does not include travel or other non-standard expenses (specialized equipment, materials, etc.). Final pricing is determined during the no-obligation scoping phase (before testing starts).

DISCLAIMER: Other than Wireless Testing, all testing is remote-only unless otherwise noted.  Sample prices and prices quoted are for remote-only and do not include travel.  See the On-site Supplemental Testing add-on for more information.


© PEN Consultants, LLC 2013 -