Services

Thick Client Pen Testing

We tear into your desktop application — decompiling binaries, intercepting client-server traffic, and manipulating it at runtime to surface flaws web testing never reaches.

Custom engagement

Scoped by quote, priced fixed

Tell us about your environment and we’ll propose the approach, the timeline, and a fixed price — typically within 48 hours.

Request a quote

Why thick client testing matters

Thick clients process significant business logic locally, store data on the machine, communicate over custom protocols, and often run with elevated privileges, creating a unique and expanded attack surface that web-focused testing misses.

From trading platforms and healthcare records systems to ERP and engineering tools, thick client vulnerabilities can lead to privilege escalation, data theft, backend compromise, and regulatory violations. Our methodology covers every layer of the architecture.

Application and communication testing

Desktop application testing reviews installer behavior and permissions, credential storage and session handling, role-based access control, input validation for injection, error handling, and cryptographic implementation.

Client-server testing reverse-engineers proprietary protocols, intercepts and modifies traffic to test server-side validation, evaluates certificate pinning, calls backend APIs directly to bypass client-side controls, and tests for replay and insecure deserialization.

Local storage, DLL, and memory attacks

We examine local databases, configuration files, registry keys, temporary files, and logs for hardcoded secrets, tokens, and sensitive remnants.

DLL attacks cover search-order hijacking, side-loading, injection, COM object hijacking, and import table manipulation, while memory analysis covers credential scraping, buffer overflow testing, runtime debugging, and anti-tampering evasion.

Reverse engineering and platforms

We decompile .NET and Java assemblies and analyze native binaries to assess obfuscation, uncover hardcoded secrets, evaluate licensing and DRM, and identify silently patched vulnerabilities through patch diffing.

We test Windows, macOS, Linux, and cross-platform clients across frameworks such as WPF, WinForms, Electron, Java, .NET, and C/C++. The engagement is scoped as a custom project with a fixed price, and every finding is tracked from discovery through a verified retest to a certificate.

Frequently asked questions

How is the engagement priced?

It is scoped as a custom engagement with a fixed price after you describe the application and we propose the approach and timeline.

Which platforms and frameworks do you cover?

Windows, macOS, Linux, and cross-platform clients built with WPF, WinForms, Electron, Java, .NET, C/C++, and similar frameworks.

Why not just run a web application test?

Thick clients carry local business logic, storage, DLL, and memory risks that web-focused testing does not reach, so they need a dedicated methodology.

What do the deliverables include?

Each finding ships with severity, a proof of concept, and remediation guidance, tracked from discovery through a verified retest to a certificate.