Our Methodology

How We Find Vulnerabilities

Our pentesting methodology is based on OWASP standards, refined through real-world engagements with startups. Every assessment follows five structured phases to ensure comprehensive coverage with zero false positives.

OWASP Top 10 Aligned Zero False Positives Actionable Reports

Five-Phase Assessment Process

01

Reconnaissance & Scoping

Understanding your attack surface

1-2 hours

Before testing anything, we map your entire attack surface. This phase is about understanding your application architecture, identifying all entry points, and building a threat model specific to your stack.

Technology Fingerprinting: Identify frameworks (Next.js, React, Vue), BaaS (Supabase, Firebase), hosting, CDN, and third-party services.
Attack Surface Mapping: Enumerate all endpoints, subdomains, APIs, webhooks, and exposed services.
OSINT Gathering: Search for leaked credentials, exposed configs, GitHub repos, and public information that attackers would find.
Threat Modeling: Identify the most likely attack vectors based on your specific stack and business context.
ShodanSubfinderhttpxnucleiCustom OSINT scripts
02

Automated Scanning

100+ security checks at scale

2-4 hours

We run our automated scanning pipeline against your application to identify common vulnerabilities quickly. This catches the low-hanging fruit that automated attackers and bots exploit.

Security Headers Analysis: Check CSP, HSTS, X-Frame-Options, X-Content-Type-Options, and all HTTP security headers.
Secrets Detection: Scan for exposed API keys, tokens, database credentials, and over 100 secret patterns in client-side code.
CORS Misconfiguration: Test Cross-Origin Resource Sharing policies for overly permissive configurations.
SSL/TLS Analysis: Verify certificate configuration, protocol versions, cipher suites, and certificate chain.
NucleitruffleHogSSL LabsSecurityHeaders.comCustom scanners
03

Manual Testing

Expert analysis of business logic

4-8 hours

This is where SableOffensive differs from automated scanners. Our security researchers manually test your application for complex vulnerabilities that tools cannot find -- business logic flaws, authorization bypass, and chained attack vectors.

OWASP Top 10 Testing: Comprehensive testing against all OWASP Top 10 2025 categories: injection, broken auth, XSS, SSRF, misconfigurations.
BOLA/IDOR Testing: Test every API endpoint for Broken Object Level Authorization -- can user A access user B's data by changing an ID?
Authentication & Session: JWT validation, session fixation, password reset flows, OAuth implementation, MFA bypass attempts.
BaaS Security Review: For Supabase: RLS policy testing, service key exposure, direct table access. For Firebase: security rules audit, Firestore access patterns.
API Security Testing: Rate limiting, mass assignment, excessive data exposure, improper error handling, GraphQL introspection.
AI-Specific Testing: Prompt injection in LLM integrations, AI-generated code patterns, exposed model endpoints, data leakage through AI features.
Burp SuitePostmanCustom scriptsBrowser DevToolsManual review
04

Exploitation & Validation

Proving real impact safely

1-2 hours

Every finding is manually verified through safe exploitation. We prove impact without causing damage. This ensures zero false positives -- if we report it, it is real and exploitable.

Safe Exploitation: Demonstrate each vulnerability with proof-of-concept that shows real impact without damaging your system or data.
Impact Assessment: Determine the real-world impact: data breach potential, account takeover risk, financial exposure, and regulatory implications.
Attack Chain Analysis: Identify how multiple lower-severity findings can be chained together for higher impact attacks.
False Positive Elimination: Every automated finding is manually verified. If we cannot reproduce it, we do not report it.
Custom exploit scriptsBurp SuiteManual verification
05

Reporting & Remediation

Actionable fixes your devs can follow

Delivered in 24-48h

You receive a professional PDF report designed for both technical and non-technical stakeholders. Every finding includes severity rating, reproduction steps, and specific code-level fix recommendations.

Executive Summary: High-level overview for founders and decision-makers. Risk score, key findings, and strategic recommendations.
Detailed Findings: Each vulnerability documented with: description, severity (CVSS), reproduction steps, screenshots/evidence, and specific remediation.
Remediation Guidance: Code-level fix recommendations tailored to your stack. Not generic advice -- specific implementations your developers can copy-paste.
Debrief Call (Founder Shield+): 30-minute video call to walk through findings, answer questions, and prioritize fixes based on your roadmap.
Custom reporting platformCVSS calculatorProfessional templates

OWASP Top 10 Coverage

Every SableOffensive assessment includes testing against the complete OWASP Top 10 2025. Here is what we test and why it matters for your startup.

A01

Broken Access Control

IDOR, privilege escalation, missing authorization checks

A02

Cryptographic Failures

Weak encryption, exposed secrets, insecure transport

A03

Injection

SQL injection, XSS, NoSQL injection, command injection

A04

Insecure Design

Business logic flaws, missing threat modeling

A05

Security Misconfiguration

Default creds, verbose errors, missing hardening

A06

Vulnerable Components

Outdated libraries, known CVEs in dependencies

A07

Auth Failures

Broken auth, session management, credential stuffing

A08

Data Integrity Failures

Insecure deserialization, CI/CD pipeline attacks

A09

Logging Failures

Missing audit trails, insufficient monitoring

A10

SSRF

Server-Side Request Forgery, internal network access

Why Our Approach Works for Startups

Manual Testing, Not Just Scanners

Automated scanners miss business logic flaws, IDOR, and auth bypass. Our researchers manually test every endpoint that matters.

Stack-Specific Expertise

We specialize in modern startup stacks: Next.js, Supabase, Firebase, AI integrations. We know where the vulnerabilities hide.

Zero False Positives

Every finding is manually verified through safe exploitation. If we report it, it is real and exploitable.

Developer-Friendly Reports

Specific code-level fixes, not generic recommendations. Your developers can implement remediation immediately.

Ready for a Professional Security Assessment?

Get the same methodology used on 7+ startups. Reports delivered in 24-48 hours.