Thick Client Pentest Checklist
The thick-client (desktop app) checklist turned into a how-to-test field guide for .NET, Java, native and Electron apps: architect…
Checklist → All Checklist articles
The thick-client (desktop app) checklist turned into a how-to-test field guide for .NET, Java, native and Electron apps: architect…
A Wi-Fi-focused wireless pentest checklist turned into a how-to-test field guide: survey and recon, WEP, WPA2-PSK (4-way handshake…
The container and Kubernetes checklist turned into a how-to-test field guide: image security and secrets in layers, Dockerfile/bui…
A configuration / CIS hardening review turned into a how-to-check field guide: approach and benchmarking, accounts and authenticat…
A proper firewall review, item by item: scope and config collection, rule-base review (any-any, shadowed/redundant/unused rules), …
The OWASP LLM Top 10 (2025) turned into a how-to-test field guide for chatbots, RAG assistants and AI agents: prompt injection (di…
The OWASP API Top 10 turned into a how-to-test field guide: for every item — BOLA/BFLA, broken authentication and JWT, excessive d…
The cloud-config checklist turned into a how-to-test field guide for AWS, GCP, Azure and OCI: recon, IAM, compute and instance-met…
The OWASP MASVS/MASTG checklist turned into a how-to-test field guide for Android and iOS: static prep, insecure storage, cryptogr…
The internal + external network checklist turned into a how-to-test field guide: scoping and recon, host discovery, port scanning,…