Offensive security assessments

Thick Client Application Security Testing

Thick client applications are any that are installed locally on a user's desktop/laptop. These applications are full-featured and can run independently without being connected to the Internet, unlike web applications, which need to be connected to the Internet all the time. Some…

Why it matters

Thick client applications are any that are installed locally on a user's desktop/laptop. These applications are full-featured and can run independently without being connected to the Internet, unlike web applications, which need to be connected to the Internet all the time. Some examples of thick client applications are: 1. Computer games like Call of Duty, Uncharted, etc. 2. Web browsers 3. Music players 4. Video and chat tools like Teams, Zoom, Slack, etc. Thick client applications come in two flavors

How we test it

Our operators follow a structured checklist for this topic, adapted to your API surface and authentication model.

Testing approach

  • Structured validation of Thick Client Application Security Testing during scoped assessment.
  • Evidence captured with reproducible steps for your engineering team.

What we look for

  • Misconfigurations and control gaps related to Thick Client Application Security Testing.
  • Exploitable paths that could affect confidentiality, integrity, or availability.

Related topics

TopicSummary
ASSEMBLY TESTINGWe validate this area during scoped assessments, documenting impact and remediation guidance.
COMMON VULNERABILITIES TESTINGWe validate this area during scoped assessments, documenting impact and remediation guidance.
FILE TESTINGWe validate this area during scoped assessments, documenting impact and remediation guidance.
GUI TESTINGWe validate this area during scoped assessments, documenting impact and remediation guidance.
INFORMATION GATHERINGWe validate this area during scoped assessments, documenting impact and remediation guidance.
MEMORY TESTINGWe validate this area during scoped assessments, documenting impact and remediation guidance.