VAPT Services
We test the way a real attacker would, by hand and with intent, not by handing you a scanner printout. You get findings we have proven, ranked by the damage they do, with a fix you can act on and a retest that confirms it is closed.
How We Work
VAPT with SecureRoot is people-led work backed by good tooling. We scope tightly with you, map the attack surface, then chase the flaws that actually chain into impact, from web and mobile apps to APIs, thick clients, networks, IoT devices and cloud accounts. Every finding carries a proof of concept, a business-language explanation and clear remediation, and we retest the fixes so you can show they hold.
Jump to the 7 ServicesServices in VAPT
Manual, Exploit-Driven Penetration Testing Across 7 Surfaces
7 services in this practice area
- 01Web ApplicationManual testing of your web apps against the OWASP WSTG
- 02Mobile ApplicationAndroid and iOS app testing against the OWASP MASVS
- 03APIREST, GraphQL and SOAP testing against the OWASP API Top 10
- 04Thick Client ApplicationDesktop app testing across binary, traffic and backend
- 05Network InfrastructureExternal and internal network testing with lateral movement
- 06IoT and EmbeddedDevice testing across firmware, hardware and radio
- 07CloudConfiguration and IAM testing across AWS, Azure and GCP
Measured Against
PTESOWASPOWASPOWASPOSSTMMISECOMCISWhat We Run
How We Rank What We Find
Whichever surface the test covers, the findings land in the same queue and are ranked by whether they are being exploited in the wild.
Worked example
A vulnerability management product view. Illustrative snapshot of a typical programme, not a named client. Headline figures for the quarter across 1,340 in-scope assets and 40 web applications: 4,812 open findings, of which 288 are past their internal SLA; 37 critical findings open; blended mean time to remediate 84 days, computed from the 3,371 closures this quarter, 24 critical at 21 days each, 391 high at 38, 2,100 medium at 74 and 856 low at 130, which is 282,042 finding-days over 3,371 closures; SLA compliance 68 percent, 2,292 of 3,371 closures within SLA. Open findings by CVSS v3.1 band: Critical 37, which is 0.8 percent; High 412, 8.6 percent; Medium 1,954, 40.6 percent; Low 2,409, 50.1 percent. A further 1,106 informational findings are excluded from that total. 19 open findings are listed on the CISA Known Exploited Vulnerabilities catalogue and 4 of those are past their CISA BOD 22-01 due date. Findings over 13 weeks: 2,993 new against 3,371 remediated, so the open backlog fell from 5,190 to 4,812, with a spike of 402 new findings in week 6 when the quarterly authenticated scan ran. Mean time to remediate by severity against target: Critical 21 days against a 15-day target, High 38 against 30, Medium 74 against 90, Low 130 against 180. The table lists 13 representative findings ranked by exploitability, led by CVE-2024-3400, GlobalProtect OS command injection, CVSS 10.0, EPSS 0.944, on KEV, 13 days old and open; CVE-2023-4966, NetScaler session token leak, CVSS 9.4, on KEV, 41 days old and in progress; and CVE-2021-44228, Log4j2 JNDI remote code execution on a legacy build host, CVSS 10.0, on KEV, 402 days old and still open.
4,812
Open
288 past SLA
37
Critical
19 on KEV
84d
MTTR
3,371 closed
68%
Within SLA
2,292 of 3,371
By Severity, 4,812 Open
19 on CISA KEV, 4 past their CISA due date.
Illustrative snapshot of a typical programme, not a named client.
4,812
Open Findings
288 past SLA
37
Critical Open
19 on CISA KEV
84d
Mean Time To Remediate
3,371 closed this quarter
68%
SLA Compliance
2,292 of 3,371 within SLA
Open Vs Closed, 13 Weeks
Open Findings By Severity
4,812 open. 1,106 informational excluded. 19 on CISA KEV, 4 past their CISA due date.
Top Findings, Ranked By Exploitability
13 shown of 4,812 open
| Finding | EPSS | KEV | Asset | Status | |||
|---|---|---|---|---|---|---|---|
| Critical | CVE-2021-44228Log4j2 JNDI remote code execution | 10.0 | 0.944 | KEV | build-07 | 402d | Open |
| Critical | CVE-2023-4966NetScaler session token leak | 9.4 | 0.941 | KEV | ns-gw-02 | 41d | In Progress |
| Critical | CVE-2024-3400GlobalProtect OS command injection | 10.0 | 0.944 | KEV | fw-edge-01 | 13d | Open |
| Critical | CVE-2023-34362MOVEit Transfer SQL injection | 9.8 | 0.943 | KEV | mft-01 | 9d | Closed |
| High | CVE-2022-42252Tomcat request smuggling | 7.5 | 0.021 | Not on CISA KEV | tc-prod-02 | 81d | Closed |
| High | CVE-2023-44487HTTP/2 Rapid Reset denial of service | 7.5 | 0.734 | KEV | lb-prod-01 | 66d | In Progress |
| High | CVE-2023-24998Commons FileUpload denial of service | 7.5 | 0.079 | Not on CISA KEV | app-jvm-03 | 58d | Open |
| High | CVE-2024-6387OpenSSH regreSSHion race condition | 8.1 | 0.412 | Not on CISA KEV | app-lnx-14 | 24d | Open |
| Medium | CVE-2018-15473OpenSSH username enumeration | 5.3 | 0.182 | Not on CISA KEV | bastion-02 | 132d | In Progress |
| Medium | CVE-2021-3449OpenSSL TLS renegotiation crash | 5.9 | 0.046 | Not on CISA KEV | web-02 | 97d | Open |
| Medium | CVE-2023-48795Terrapin SSH prefix truncation | 5.9 | 0.011 | Not on CISA KEV | jump-01 | 74d | Open |
| Low | CVE-2019-1552OpenSSL insecure install path | 3.3 | 0.002 | Not on CISA KEV | win-svc-09 | 156d | Open |
| Low | CVE-2019-1563OpenSSL CMS padding oracle | 3.7 | 0.006 | Not on CISA KEV | web-04 | 121d | Open |
Illustrative snapshot of a typical programme, not a named client. EPSS scores are indicative.
Every one of these is scoped, run and reported by the same team. See All Practice Areas
Not Sure Which of These You Need?
Tell us what you are being asked to prove, or what you are worried about. We will point you at the right piece of work, even when it is smaller than you expected.
Elsewhere
Other Practice Areas
- ComplianceCertifications and Privacy Programmes Across 13 Frameworks
- Secure Code Review (SCR)Manual, line-by-line review of your most sensitive code paths, backed by SAST triage.
- Software Composition Analysis (SCA)Know every third-party and open-source dependency you ship, and every risk it carries.
- Hardening and Configuration ReviewBenchmark-Based Configuration Hardening Across Cloud, OS, Network and Data Tiers
- Managed ServicesOngoing Offensive, Defensive and Advisory Security Run by Our Team