THAGHARATVulnerability Hunter
9 years in offensive security

We hunt down the vulnerabilities before attackers do.

Thagharat is a penetration testing practice built on manual, evidence-driven work. We attack your systems the way a real adversary would — then hand you a report your engineers can act on and your auditors will accept.

Certified by eLearnSecurity · INE · OCEG

Sample findingCRITICAL
CVSS 9.1

Authentication bypass via JWT signature confusion

Affected asset
api.client-portal.internal
Status
Reported · PoC verified
Validation
Manually exploited — not scanner output
NCA ECCSAMA CSFPDPLISO 27001PCI DSSOWASP / NISTeWPTXeWPTeCPPTeJPTCAPENGRCPGRCA
9+
Years of hands-on offensive work
7
Professional certifications
24h
Critical findings escalated within
100%
Findings manually validated
What we do

Testing that goes past the scanner

Automated tools find the obvious. We are hired for everything underneath it — business logic, chained exploits, and the misconfigurations no signature catches.

Web Application Penetration Testing

Full-depth assessment of authentication, session handling, access control, injection surfaces and business logic. We chain low-severity issues into the high-impact paths a scanner will never report.

  • OWASP Top 10
  • Business logic
  • Auth bypass
  • eWPT · eWPTX

Network & Infrastructure Testing

External perimeter and internal network assessments, Active Directory attack paths, lateral movement, and privilege escalation to domain compromise — executed safely, under agreed rules of engagement.

  • External
  • Internal
  • Active Directory
  • eCPPT

Mobile Application Security

iOS and Android testing across the full stack: local storage, certificate pinning, IPC, reverse engineering resistance and the backend APIs the app depends on.

  • iOS
  • Android
  • OWASP MASVS
  • API layer

API & Cloud Security Assessment

REST and GraphQL testing for broken object-level authorization, mass assignment and rate-limit failures — alongside cloud configuration review across identity, storage and network boundaries.

  • REST
  • GraphQL
  • BOLA / IDOR
  • Cloud config

Red Teaming & Social Engineering

Objective-based adversary simulation that tests detection and response, not just vulnerabilities. Phishing campaigns, pretexting and physical access scenarios, scoped to what you actually want measured.

  • Adversary simulation
  • Phishing
  • Detection testing

Compliance & GRC Advisory

Gap assessments and readiness work mapped to the frameworks your regulator audits against. We translate technical findings into control-level evidence your compliance team can file.

  • NCA ECC
  • SAMA CSF
  • PDPL
  • ISO 27001
  • GRCA · GRCP
How we work

A process built for evidence

Every engagement runs the same disciplined path. You always know what stage we are at, what we have found, and what happens next.

  1. 01

    Scoping & rules of engagement

    We agree targets, testing windows, escalation contacts and hard boundaries in writing before a single packet is sent. NDA signed up front.

  2. 02

    Reconnaissance & threat modelling

    Attack surface mapping and threat modelling against your actual business risk — so effort goes where a real attacker would concentrate it.

  3. 03

    Exploitation & manual validation

    Findings are proven, not guessed. Each one is manually exploited and captured with a reproducible proof of concept. No unverified scanner noise reaches your report.

  4. 04

    Reporting & risk rating

    An executive summary your board can read, and a technical section your engineers can act on. CVSS-scored, mapped to remediation steps and framework controls.

  5. 05

    Retest & remediation support

    After you fix, we verify. A retest of all confirmed findings is included, with a clean closure letter you can hand to auditors or clients.

What you receive

Every engagement ends with evidence you can act on

The same six deliverables on every engagement, in Arabic and English — for the engineers who fix, the leaders who decide and the auditors who check.

Executive summary

Your risk in business terms: what is exposed, how serious it is and what to fix first. Written for leadership and the board.

Technical findings report

Every finding with its CVSS rating, affected assets, evidence and step-by-step reproduction, so your engineers can confirm it themselves.

Remediation roadmap

Fixes prioritised by risk and effort, with concrete guidance for your stack rather than generic advice.

Compliance mapping

Each finding mapped to the controls it affects in NCA ECC, SAMA CSF, PDPL, ISO 27001 and PCI DSS — ready to file as audit evidence.

Readout session

A walkthrough of the results with your engineers and leadership, where we answer questions and agree next steps.

Retest & closure letter

Once you have fixed the findings we verify them, then issue a closure letter for auditors, clients or regulators.

Every letter we issue can be verified

Attestation and closure letters carry a unique ID. Anyone — your auditor, your client, a regulator — can confirm on our site that a letter is genuine.

Verify a letter
Why Thagharat

What you actually get

Manual-first, always

Tooling accelerates discovery; it never replaces judgement. The findings that matter come from a human reading your application logic.

Zero false positives

If we report it, we exploited it. Every finding ships with reproduction steps and evidence, so your team never wastes a sprint chasing a phantom.

Bilingual reporting

Full deliverables in Arabic and English. The same report satisfies a local regulator and an international parent company.

Retest included

Remediation verification is part of the engagement, not a change order. You get a closure letter when the findings are confirmed fixed.

24-hour critical escalation

Anything critical is escalated the moment it is confirmed. You do not wait for the final report to learn your perimeter is open.

Safe by construction

Destructive techniques stay out of scope unless you explicitly authorise them. Production testing follows agreed windows and abort conditions.

About us

A Saudi penetration testing company, built by practitioners

Thagharat — صائد الثغرات, “the vulnerability hunter” — is a penetration testing company based in Riyadh. It was founded by offensive security practitioners with more than nine years of hands-on experience testing web applications, networks and mobile apps.

We keep the practice deliberately focused: manual testing, proof for every finding, and reports that work for engineers, auditors and regulators alike — in Arabic and English.

Office
Riyadh
Saudi Arabia
Registered name
شركة صائد الثغرات
01

Offense is our background

We test the way attackers operate because that is the work we come from — not a checklist exercise.

02

Built for Saudi requirements

Findings mapped to NCA ECC, SAMA CSF and PDPL, with deliverables your regulator and your engineers can both use.

03

Discreet by default

An NDA before any technical detail, minimal data access during testing, and engagement data destroyed on request.

Credentials

Certified across offence and governance

Nine years of hands-on offensive security, backed by certifications on both sides of the table — the people who break systems, and the people who audit them.

Offensive security

eWPTX
Web Application Penetration Tester eXtreme
eLearnSecurity / INE
eWPT
Web Application Penetration Tester
eLearnSecurity / INE
eCPPT
Certified Professional Penetration Tester
eLearnSecurity / INE
eJPT
Junior Penetration Tester
eLearnSecurity / INE
CAPEN
Certified Associate Penetration Tester
SecOps Group

Governance & audit

GRCP
Governance, Risk & Compliance Professional
OCEG
GRCA
Governance, Risk & Compliance Auditor
OCEG
Frameworks

Mapped to what your auditor asks for

A penetration test is only half the deliverable. We map every finding to the control it breaks, so the report doubles as compliance evidence.

Saudi Arabia

NCA ECCEssential Cybersecurity Controls

Technical testing aligned to NCA ECC control domains, with findings mapped to the specific controls they affect.

SAMA CSFCyber Security Framework

Assessment support for financial institutions operating under the SAMA framework and its maturity expectations.

PDPLPersonal Data Protection Law

Review of how personal data is stored, transmitted and exposed across your applications and interfaces.

International

ISO 27001Information Security Management

Annex A control testing and evidence packages that fit directly into your ISMS documentation and audit cycle.

PCI DSSPayment Card Industry DSS

Segmentation testing and application assessments meeting Requirement 11 penetration testing obligations.

OWASP / NISTTesting methodologies

Engagements follow OWASP WSTG and MASVS, with reporting structured around the NIST SP 800-115 methodology.

Pricing

Priced by scope. Fixed before we start.

We don't bill by the hour. Tell us about your environment and we come back with a fixed price for the agreed scope, a timeline and a statement of work — no open-ended billing.

What shapes the price

  1. 01
    Size of the target

    How many applications, domains, IP addresses or hosts are in scope.

  2. 02
    Depth of testing

    The user roles, API endpoints and business flows that need to be exercised.

  3. 03
    Testing approach

    Black-box, grey-box with credentials, or white-box with access to source code.

  4. 04
    Environment

    Production or staging, and any testing windows your operations require.

  5. 05
    Compliance reporting

    Whether findings must be mapped to NCA ECC, SAMA CSF, PDPL, ISO 27001 or PCI DSS.

  6. 06
    Timeline

    Standard scheduling, or an expedited start when a deadline is close.

Every quote includes

  • NDA signed before scoping
  • Report in Arabic and English
  • Readout session with your team
  • Retest of all confirmed findings
  • Closure letter with a verifiable ID
Request a scope

Free scoping · no obligation

Prefer email? contactus@thagharat.com

Questions

Before you get in touch

How long does a penetration test take?
Most web application engagements run one to three weeks from kickoff to report, depending on the number of roles, endpoints and business flows in scope. Network and red team engagements typically run longer. We give you a fixed timeline with the scope document — no open-ended billing.
How much does a penetration test cost?
It depends on the scope: how many applications or hosts are involved, the roles and endpoints to test, the testing approach and the environment. Once we understand your environment we send a fixed price for the agreed scope and a timeline. There is no hourly billing, and the retest is included.
Will testing disrupt our production systems?
Disruption is designed out. We agree testing windows, rate limits, abort conditions and an escalation contact before starting. Destructive techniques such as denial of service are excluded unless you explicitly request and authorise them in writing.
What do we receive at the end?
An executive summary written for non-technical leadership, a technical findings report with CVSS ratings and reproduction steps, a remediation roadmap prioritised by risk, and a framework mapping section. All deliverables are available in Arabic and English.
Do you sign an NDA?
Always, and before any technical discussion of your environment. We can work under your NDA template or provide ours. All engagement data is handled under agreed retention terms and destroyed on request after closure.
Is retesting included?
Yes. Verification of your fixes is part of the engagement, not a separate purchase. Once findings are confirmed remediated, you receive a closure letter suitable for auditors, clients or regulators.
Do you test against Saudi regulatory requirements?
Yes. Engagements can be scoped and reported against NCA ECC, SAMA CSF and PDPL, as well as international standards such as ISO 27001 and PCI DSS. Findings are mapped to specific controls so the report works as audit evidence.
Get started

Tell us what you need tested

Send a short description of your environment and we will come back with a scope, timeline and fixed price. No sales calls, no obligation, and an NDA before any technical detail is shared.

Message us on WhatsApp

Fastest route — usually answered same day

  • NDA signed before scoping
  • Fixed-price engagements
  • Retest included