ZW-Labs · Penetration testing + 24/7 managed SOC

Offense by day.
Defense all night.

We attack your web apps, APIs, cloud and networks the way a real adversary would — then our SOC watches them around the clock. One team, both sides of the fence.

  • Critical issues raised the day we find them
  • Every fix verified by a retest
  • SOC staffed 24 hours, 7 days a week
Finding ZW-LABS-014critical

Any signed-in customer can read any other customer's invoices

Target
GET /api/v2/invoices/{id}
Score
CVSS 9.1 · Critical
Found
Early in the test
Status
Fixed · retested and closed

Evidence

GET /api/v2/invoices/48213
Authorization: Bearer 
→ 200 OK · invoice belongs to tenant 7731

Fix

Check the invoice's tenant against the caller's on every read, and add a regression test that fails if the check is removed.

FIG. 1 — Sample finding

01

What we test

One standard for every engagement: every finding is reproducible, and every fix is retested.

  • We test the app your customers log in to, across every role, the way someone who wants their data would.

    • Authorisation between roles and between tenants
    • Login, session and password-reset flows
    • Injection of every kind: SQL, template, command, header
    Web applications testing in detail →
    Example findingcritical

    Any signed-in customer can read any other customer's invoices

  • APIs expose your data model directly. We test every endpoint — documented or not — for what it gives away.

    • Object- and function-level authorisation
    • Mass assignment and over-exposed fields
    • Tokens, API keys and OAuth flows
    APIs testing in detail →
    Example findinghigh

    Setting "role": "admin" on a profile update is accepted

  • An LLM feature is a new way into your systems. We test what it can be made to say, reveal and do.

    • Direct and indirect prompt injection
    • System-prompt and data disclosure
    • Other users' data leaking through retrieval
    AI & LLM features testing in detail →
    Example findinghigh

    A shared document makes the assistant email its contents to an outsider

  • Most cloud breaches start with a setting, not an exploit. We find the ones that actually lead somewhere.

    • Over-privileged roles and trust policies
    • Public storage, snapshots and shared links
    • Exposed services and network paths
    Cloud testing in detail →
    Example findingcritical

    A CI role can assume the production admin role

  • A mobile app ships your client code to every attacker who downloads it. We test the app and what it talks to.

    • Data stored on the device
    • Transport security and certificate pinning
    • Hard-coded secrets and reverse engineering
    Mobile testing in detail →
    Example findingmedium

    Session token written to the device log in plain text

  • From the internet we find what's exposed. From inside we show how far one compromised laptop gets.

    • Exposed services and remote-access gateways
    • Segmentation between networks
    • Active Directory attack paths
    Networks testing in detail →
    Example findinghigh

    A backup service account's password is crackable offline

02

How an engagement runs

You always know what is being tested, by whom, and when. Nothing is touched until scope and written authorisation are agreed.

Two people planning at a whiteboard covered in diagrams
FIG. 2 — Scoping session
  1. Before we start

    Scope

    We agree targets, test accounts, timing and rules of engagement. You sign a written authorisation.

  2. During the test

    Test

    Hands-on testing. Anything critical comes to you the day we find it, not in the final report.

  3. When testing ends

    Report

    An executive summary for leadership, and every finding with evidence, severity and a specific fix.

  4. When you're ready

    Retest

    We verify each fix and reissue the report showing what's closed — ready for auditors and customers.

A city skyline at night, lit windows reflected in the water
FIG. 3 — 03:00, somewhere you operate

03 — The night shift

It's 03:14. Someone is watching.

Analysts triage every alert from the tools you already run, around the clock. When it's real, we contain it with you — and explain what happened in plain English.

Explore managed SOC →
SOC / live queueLondon --:--Karachi --:--New York --:--
  • 03:14:07● HighEncoded PowerShell launched by Excel on FIN-LT-022Contained
  • 03:11:52● MedImpossible travel: j.doe signed in from two countries in 9 minInvestigating
  • 02:58:30● LowNew admin added to the AWS organisationConfirmed benign
  • 02:41:09● CritCredential-dump attempt on DC-01Escalated to you
4 alerts triaged · 1 escalated
FIG. 4 — SOC queue

05 — Start

Tell us what needs testing — or watching.

A few lines is enough to scope it. We reply with questions or a written proposal.

Or email [email protected]

Under attack now? Put "INCIDENT" in the subject.

Used only to reply to your request. Privacy policy.