Skip to content
Ambara Digital Nusantara

Penetration testing

Penetration testing and vulnerability assessment

Find and close security gaps before they are exploited. Our testing is done manually by practitioners and focuses on real business risk, not just scanner output.

FrameworksOWASP WSTGOWASP MASVSOWASP API Top 10PTESMITRE ATT&CKCVSS v3.1/v4.0
Web appOWASPAPIOWASPNetworkOWASPFindings by severity (example report)CriticalHighMediumLowFinding: broken object-level authorisationCVSS 8.1GET /api/invoices/1043 → 200 (another customer’s data)Retest: fixed and confirmed
Illustrative report: findings ranked by severity, each with evidence, a fix and a retest.

01

Types of testing

Automated scanners miss business logic flaws. We add manual exploitation so findings reflect the real risk.

01

Web applications

In-depth testing of web portals, ERP and SaaS applications, including authentication, authorisation and business logic.

02

Android apps

Static and dynamic analysis of the APK: data storage, communication, authentication and protection bypass, to OWASP MASVS.

03

iOS apps

Testing of iPhone and iPad apps: keychain use, jailbreak detection, certificate pinning and client-side logic.

04

Desktop applications

Windows and thick-client apps: server communication, stored credentials, DLL handling and reverse engineering.

05

APIs

Making sure API endpoints are safe from data manipulation, injection and unauthorised access.

06

Network infrastructure

Simulated attacks on servers, routers and firewalls from inside and outside.

07

VPN and remote access

VPN gateways, RDP and other remote access: configuration, authentication, MFA and the lateral-movement risk once connected.

08

Social engineering

Phishing simulations to measure staff security awareness, with written approval.

02

Methodology

  1. Reconnaissance

    Map the attack surface within the agreed scope.

  2. Vulnerability analysis

    An initial scan followed by manual verification.

  3. Exploitation

    Controlled, realistic attack simulation without damaging production systems.

  4. Reporting and debrief

    Executive and technical reports, then a walkthrough with your team.

  5. Retest

    Fixed findings are tested again and their status confirmed in writing.

03

What you receive

  • An executive summary management can follow
  • Technical findings with CVSS scores, evidence and reproduction steps
  • Remediation guidance your developers can act on
  • A retest letter after remediation
  • Evidence that supports ISO/IEC 27001 audits and UU PDP obligations

04

Secure your applications and infrastructure

Tell us which systems you want tested, the environment (production or staging) and your deadline. We will propose a scope and schedule.

Discuss your pentest