THAGHARATVulnerability Hunter
What we do

Testing that goes past the scanner

Automated tools find the obvious. We are hired for everything underneath it: business logic, chained exploits and the misconfigurations no signature catches.

Web Application Penetration Testing

Full-depth assessment of authentication, session handling, access control, injection surfaces and business logic. We chain low-severity issues into the high-impact paths a scanner will never report.

  • OWASP Top 10
  • Business logic
  • Auth bypass
  • eWPT · eWPTX

Network & Infrastructure Testing

External perimeter and internal network assessments, Active Directory attack paths, lateral movement, and privilege escalation to domain compromise, executed safely under agreed rules of engagement.

  • External
  • Internal
  • Active Directory
  • eCPPT

Mobile Application Security

iOS and Android testing across the full stack: local storage, certificate pinning, IPC, reverse engineering resistance and the backend APIs the app depends on.

  • iOS
  • Android
  • OWASP MASVS
  • API layer

API & Cloud Security Assessment

REST and GraphQL testing for broken object-level authorization, mass assignment and rate-limit failures, alongside a review of cloud configuration across identity, storage and network boundaries.

  • REST
  • GraphQL
  • BOLA / IDOR
  • Cloud config

Red Teaming & Social Engineering

Objective-based adversary simulation that tests detection and response, not just vulnerabilities. Phishing campaigns, pretexting and physical access scenarios, scoped to what you actually want measured.

  • Adversary simulation
  • Phishing
  • Detection testing

Compliance & GRC Advisory

Gap assessments and readiness work mapped to the frameworks your regulator audits against. We translate technical findings into control-level evidence your compliance team can file.

  • NCA ECC
  • SAMA CSF
  • PDPL
  • ISO 27001
  • GRCA · GRCP
How we work

A process built for evidence

Every engagement runs the same disciplined path. You always know what stage we are at, what we have found, and what happens next.

  1. 01

    Scoping & rules of engagement

    We agree targets, testing windows, escalation contacts and hard boundaries in writing before a single packet is sent. NDA signed up front.

  2. 02

    Reconnaissance & threat modelling

    Attack surface mapping and threat modelling against your actual business risk, so effort goes where a real attacker would concentrate it.

  3. 03

    Exploitation & manual validation

    Findings are proven, not guessed. Each one is manually exploited and captured with a reproducible proof of concept. No unverified scanner noise reaches your report.

  4. 04

    Reporting & risk rating

    An executive summary your board can read, and a technical section your engineers can act on. CVSS-scored, mapped to remediation steps and framework controls.

  5. 05

    Retest & remediation support

    After you fix, we verify. A retest of all confirmed findings is included, with a clean closure letter you can hand to auditors or clients.

What you receive

Every engagement ends with evidence you can act on

Six deliverables on every engagement, in Arabic and English, for your engineers, your leadership and your auditors.

Executive summary

Your risk in business terms: what is exposed, how serious it is and what to fix first. Written for leadership and the board.

Technical findings report

Every finding with its CVSS rating, affected assets, evidence and step-by-step reproduction, so your engineers can confirm it themselves.

Remediation roadmap

Fixes prioritised by risk and effort, with concrete guidance for your stack rather than generic advice.

Compliance mapping

Each finding mapped to the controls it affects in NCA ECC, SAMA CSF, PDPL, ISO 27001 and PCI DSS, ready to file as audit evidence.

Readout session

A walkthrough of the results with your engineers and leadership, where we answer questions and agree next steps.

Retest & closure letter

Once you have fixed the findings we verify them, then issue a closure letter for auditors, clients or regulators.

Every letter we issue can be verified

Attestation and closure letters carry a unique ID. Your auditor, your client or a regulator can confirm on our site that a letter is genuine.

Verify a letter
Frameworks

Mapped to what your auditor asks for

A penetration test is only half the deliverable. We map every finding to the control it breaks, so the report doubles as compliance evidence.

Saudi Arabia

NCA ECCEssential Cybersecurity Controls

Technical testing aligned to NCA ECC control domains, with findings mapped to the specific controls they affect.

SAMA CSFCyber Security Framework

Assessment support for financial institutions operating under the SAMA framework and its maturity expectations.

PDPLPersonal Data Protection Law

Review of how personal data is stored, transmitted and exposed across your applications and interfaces.

International

ISO 27001Information Security Management

Annex A control testing and evidence packages that fit directly into your ISMS documentation and audit cycle.

PCI DSSPayment Card Industry DSS

Segmentation testing and application assessments meeting Requirement 11 penetration testing obligations.

OWASP / NISTTesting methodologies

Engagements follow OWASP WSTG and MASVS, with reporting structured around the NIST SP 800-115 methodology.

Get started

Tell us what you need tested

Send a short description of your environment and we will come back with a scope, timeline and fixed price. No sales calls, no obligation, and an NDA before any technical detail is shared.

Message us on WhatsApp

Fastest route, usually answered the same day

  • NDA signed before scoping
  • Fixed-price engagements
  • Retest included