24/7 SOC monitoring & incident responsesales@bugfoe.com
BestPentestingby BugFoe
Penetration Testing

Thick Client Penetration Testing

Desktop and client-server applications run on machines attackers can control. We test the client, its local storage and its communication with backend services.

Attack path focus LIVE

  • Windows, macOS & Java clients
  • Traffic interception & tampering
  • Local storage & memory analysis
  • Backend server testing

Overview

Thick client applications — trading terminals, ERP clients, healthcare systems, point-of-sale and internal tools — often hold sensitive data and talk directly to databases or backend services. Because they run on the user's machine, attackers can inspect, modify and replay everything the client does.

Our testers analyse the application binary and its local files, intercept and manipulate traffic (including non-HTTP protocols), inspect memory for secrets, test for DLL hijacking and insecure update mechanisms, and attack the backend services the client depends on.

The most serious issues are usually trust problems: business rules enforced only in the client, credentials or connection strings stored locally, and servers that accept whatever the client sends.

What's included

Static analysisDecompilation, hard-coded secrets and insecure configurations.
Local storageFiles, registry, logs and caches holding sensitive data.
Memory analysisCredentials and sensitive data exposed in memory.
Traffic analysisInterception and tampering of HTTP and proprietary protocols.
Client-side controlsBypass of client-enforced authorization and validation.
Binary & update securityDLL hijacking, code signing and update integrity.

Our approach

  1. UnderstandArchitecture, roles and backend dependencies.
  2. AnalyseStatic and dynamic analysis of the client.
  3. InterceptTraffic interception and manipulation.
  4. Attack backendTest servers and databases the client uses.
  5. Report & retestFindings with fixes for client and server teams.

What you receive

  • Client and server findings
  • Proof-of-concept evidence
  • Architecture-level recommendations
  • Retest report
  • Attestation letter

Standards & frameworks

  • OWASP Desktop App Security Top 10
  • OWASP ASVS
  • CWE
  • PTES

Frequently asked questions

What is a thick client?

A desktop application that performs significant processing locally and communicates with backend servers, as opposed to a browser-based thin client.

Do you need a test environment?

Yes, ideally a test instance of the client and backend with test accounts for each role.

Can you test proprietary protocols?

Yes. We analyse and manipulate non-HTTP traffic where needed.

Engagement timeline

What working with us looks like

Typical timeline for Thick Client Penetration Testing — we confirm exact dates in your proposal.

01Day 0ScopeCall, scope and fixed-price proposal
02Week 1Kick-offAccess, accounts and rules of engagement
03Week 1–2TestingManual testing with real-time critical alerts
04Week 2–3ReportExecutive + technical report and debrief
05+30 daysRetestFix verification and attestation letter
Sample report

Reports engineers can fix from and auditors accept

  • Executive summary in business language
  • Risk-rated findings with reproduction steps
  • Developer-ready remediation guidance
  • Retest results and attestation letter
Request a sample report

Ready to find your risks before attackers do?

Tell us what you need tested or monitored. A senior consultant replies within one business day with a scoped, fixed-price proposal.

  • Fixed-price proposal
  • Reply within 1 business day
  • NDA on request