Software Application Security Assessment

As a CERT-India Empanelled auditor, we are proud to help secure websites for the Government of Punjab and Gujarat among others.

To get more information on Security Brigade's Professional Services, Contact Us.

Introduction

Security Brigade's Software Application Security Assessment service proactively attempts to validate the security controls in your software applications. It is a highly versatile service that utilizes in-house research and development along with out-of-box thinking to not only identify known flaws but also discover unknown flaws within your software applications.

  • Advanced Security Analysis identifies unknown vulnerabilities in applications and networks before they are exploited.
  • Detailed Recommendations focusing on mitigating immediate threats and suggesting best-practice recommendations to prevent future events.
  • Proactively Identifies your Business Exposure to tomorrow's risks by identifying security issues before it impacts your business.
  • Rapid Security Review of your organization's network perimeter, application infrastructure, internal private network and mobile users.
  • Template Driven methodology to ensure compatibility with industry recognized guidelines such as: OSSTMM, OWASP, PCI, NSE, RBI, etc.
Some of Our Unique Value Propositions
Experience
Consultants are certified with industry recognized IS Certifications (eg: eCPPT, SANS, CISSP).
Free Re-Testing
Ensures vulnerabilities are completely closed.
Customized Reports
With source-code examples in your development language along with patch and configuration details.
Hybrid Approach
Delivering experienced consultants coupled with ground-breaking automated processes.
Identifying the "True Impact"
Get a real-world perspective on your threat assessment.
Enhanced Remediation
Solutions specific to your operational and development environments.

Approach

Security Brigade's Software Application Security Assessment approach is based on best practices and well-developed methodologies while incorporating sophisticated testing software, methodology and experienced consultants - A blend of best practices and proprietary process. In-addition, our continual innovation through research & development ensures a thorough check of your system and application infrastructure.

Our Approach

Our Software Application Security Assessment methodology is an in-depth process that has been built through experience and thorough understanding of customer requirements.

[+] Read More

  • Pre-Assessment Analysis
  • Information Gathering
  • Enumeration
  • Social Engineering
  • Business Logic Analysis and Mapping
  • Threat Profiling & Risk Identification
  • Application Reverse Engineering and Analysis
  • Application Vulnerability Assessment
  • Exploit Research & Development
  • Exploitation
  • Privilege Escalation
  • Retaining Access
  • Network Propagation
  • Engagement Analysis
  • Mitigation Strategies
  • Report Generation
  • Support

Technical Experience

Security Brigade has had the privilege of working with a large number of customers with varied operational environments. As a result, our consultants have broad technical experience and some of the environments we have worked with are listed below.

[+] Read More

Operating Systems: Windows Server 2000, 2003, 2008, Redhat Linux, Sun Solaris, HP-UX, IBM AIX, Open VMS, Novell Netware, Open Enterprise Server, Suse Linux, IBM OS/2, Win NT, SCO Unix, SCO OpenServer, IRIX, FreeBSD, OpenBSD, NetBSD, OpenSolaris.
Databases: Oracle, SQL Server, IBM DB2, MySQL, PostgreSQL, Sybase, Access, SAP DB, Interbase, Ingres, Informix.
Applications: ASP, .NET, PHP, Ruby, Perl, Python, C#, Java, C/C++, Delphi.
Others: Microsoft Sharepoint, SAP, Active Directory, ISA Proxy, Squid Proxy.


In-House Tools for Software Application Security Assessment

One of our core strengths has been our ability to adapt to challenging customer environments and requirements. We have been able to consistently meet these challenges through a strong process of research and development. Some of the many tools we have developed over the years are given below.

[+] Read More

sdFinder - Identifies internal hosts on non-contiguous IP ranges. It allows us to detect sensitive information about our clients commercial, intranet and extranet networks.
webDiscovery - Identifies as many applications as possible on Client web-servers. The applications discovered through webDiscovery allow us to provide a superior web application security testing service than competitive services and products. It allows us to increase the scope of the audit and cover more areas that could be attacked by malicious users; that would not be covered by a traditional audit.
networkMapper - Network Mapper uses proprietary technology to be able to identify alternative network routes to bypass security mechanisms such as IDS/IPS/Firewall etc. It allows our experts to bypass existing security implementations and gain direct access to the systems behind them.
webTester - Utilizes our Benchmark Development System to ensure that we can identify maximum vulnerabilities in applications through automated mechanisms. Along with flaws that are known, it uses in-house research to test for vulnerabilities that are not in the public domain. It allows us to automate the process of identifying and testing known and unknown vulnerabilities in web-applications and strike a cost-effective time to effort ratio.
VA Framework - Integrated solution developed by our security experts that have an expertise in the vulnerability assessment domain. It allows us to integrate the manual and automated testing processes with commercial and open-source software. Our Integrated Reporting Engine allows us to cross-reference information from all the different components and generate a report based on our Client's requirements.
PT Framework - Integrated solution developed by our security experts that have an expertise in the penetration testing domain. It allows us to integrate the manual and automated testing processes with commercial and open-source software. Our Integrated Reporting Engine allows us to cross-reference information from all the different components and generate a report based on our Client's requirements.
webSpider - Uses advanced HTML, Java Script, Ajax, Flash and XML parsing engines to identify and map as much of the client applications as possible. This not only assists our automated webTester engine, but also assists in carrying out the manual testing process in an efficient manner. It allows us to attain a cost-effective balance between thorough testing and time required.
sapScan - Security and Configuration Assistant for SAP Security Audits.
riskReview - General Risk Assessment Tool.
erpInterrogate - ERP Security and Configuration Assessment and Control Tool.
Windows Batch Scripts - Windows batch scripts to automate routine server hardening functions and processes.
Linux Bash Scripts - Linux Bash scripts to automate routine server hardening functions and processes.
Oracle Security Assessment Scripts - Oracle Security Assessment Scripts to automate routine hardening functions and processes.
MSSQL Security Assessment Scripts - MSSQL Security Assessment Scripts to automate routine hardening functions and processes.
Internal Vulnerability Database - Automated vulnerability database that is updated every 15 minutes from over 100 public and 20 private feeds.
SQL Explorer: identifies vulnerabilities in and retrieves data from MSSQL, MySQL, Oracle, PostgreSQL, MS Access etc database servers.

Case-Studies

Software Application Security Assessment for a Regulatory Authority


Security Brigade conducted a Software Application Security Assessment for a Government Regulatory Authority appointed to manage and regulate the development of an industry with revenue exceeding 250,000 crore. This case study highlights the techniques and processes implemented to meet the Client's key business goals while helping them achieve security compliance and regulatory requirements.

Download PDF

Software Application Security Assessment for a Stock Exchange


Security Brigade conducted a Software Application Security Assessment for a Stock Exchange Body with over 4000 listed Companies and a equity market capitilization more than USD 1 Trillion. This case study highlights the techniques and processes implemented to meet the Client's key business goals while helping them achieve security compliance and regulatory requirements.

Download PDF

Software Application Security Assessment for a Commodities Exchange


Security Brigade conducted a Software Application Security Assessment for a Commodities Exchange that ranks in the Top 3 Private Sector Financial Services and Banking Companies. This case study highlights the techniques and processes implemented to meet the Client's key business goals while helping them achieve security compliance and regulatory requirements.

Download PDF

Deliverables

Security Brigade's reporting process is industry-unique and aims to deliver maximum value to your organization and the administrations / developers directly interacting with the security audit. Each report is customer-specific and contains detailed information, proof of concepts, source code examples and configuration details with the aim of educating your IT teams for the long-term. The following are some of the deliverables you will receive on completion of a Software Application Security Assessment.

Executive Presentation


Provides a holistic overview of the entire engagement, detailing the issues from an impact and business risk perspective. The presentation is aimed at helping senior management quantify risks and take an informed decision while aligning security with business objectives.

Download PDF

Executive Report


Provides a high-level summary of the applications covered, vulnerabilities discovered and the recommendations made to mitigate the threats identified through the engagement.

Download PDF

Technical Report


Provides comprehensive information about all the threats discovered on the applications. It will include proof-of-concepts, technical explanations, remediation recommendations, screenshots, exploits, etc.

Download PDF

Project Summary Report


Provides a detailed summary of the engagement, the vulnerabilities identified, recommendations made and current status of the identified issues.

Download PDF

Excel Vulnerability Tracker


Simple and comprehensive vulnerability tracker aimed at helping the IT asset owner keep track of the vulnerabilities, remediation status, action items, etc.

Download PDF

Request a Call

Telephone: +91-022-23532909 | Contact Us | Twitter | Linked In
Security Consulting | Penetration Testing | Web Application Security | CERT-IN Empanelled | Privacy Policy
Copyright © 2007-2013 by Security Brigade InfoSec Pvt. Ltd. All rights reserved.