I will conduct comprehensive vulnerability assessment and penetration testing
Cyber Security Consultant, Vulnerability Assessment, Penetration Testing
About this Gig
Protect your digital assets before hackers exploit them.
With 23 years of experience in the IT industry, I am a cybersecurity specialist providing professional Vulnerability Assessment and Penetration Testing (VAPT) services. I follow industry standards to identify critical flaws and secure your infrastructure.
What I Offer:
- Basic (VA): Scan + manual verification for 1 target (Web/API/IP) to remove false positives.
- Standard (Pentest): Deep manual pentest for Web/API (OWASP Top 10) including active exploitation.
- Premium (Mobile Pentest): Advanced manual security testing for Android & iOS apps (OWASP MASVS).
Methodology:
- Reconnaissance & Info Gathering
- Vulnerability Scanning & Manual Verification
- Active Exploitation & Proof of Concept (PoC)
- Comprehensive Reporting
Deliverables (PDF Report):
- Executive Summary for stakeholders
- Categorized flaws (High/Med/Low via CVSS)
- Proof of Concept (PoC) screenshots
- Step-by-step remediation guidance
Please contact me before ordering to discuss your project scope.
Testing application:
Other
Device:
PC
•
iPhone
•
Android mobile phone
My Portfolio
FAQ
Does your pricing cover both Black-box and Grey-box testing?
Yes, the price includes both. Black-box simulates an external hacker with zero knowledge. Grey-box uses partial access (like test accounts or API docs) for deeper logic and authorization checks. You can choose the method that best fits your project needs.
What do I need to provide to start the penetration test?
For Black-box, I only need the target URL, IPs, or mobile app files (.apk/.ipa). For Grey-box, please also provide low-privilege test credentials and any available API documentation (Swagger/Postman) so I can thoroughly assess the backend architecture.
Will this penetration test cause downtime to my live system?
I use controlled exploitation techniques to minimize risks. However, aggressive scans can stress networks. To ensure zero disruption to live users, providing a staging, development, or pre-production environment for the assessment is highly recommended.
What deliverables are included in the final delivery?
You will receive a professional PDF report containing an Executive Summary, CVSS 3.1 severity ratings, precise bug locations (endpoints/parameters), step-by-step Proof of Concepts (PoCs) with screenshots, and actionable remediation guidelines for your developers.
Can we sign an NDA before sharing project details?
Absolutely. Confidentiality is mandatory in cybersecurity. I am fully prepared to sign a standard Non-Disclosure Agreement (NDA) to protect your proprietary data, credentials, and infrastructure blueprints before you share any assets or scope details.
Do you offer re-testing after my team fixes the vulnerabilities?
Yes, the price includes one free re-test (patch verification) to ensure your fixes are robust. Once your development team completes the remediation, contact me to set up a timeline for the verification scan.
What does the Basic package cover?
Covers 1 target: choose 1 Web, 1 API, or 1 Network IP. Best for small scopes (up to 5 endpoints) or initial checks. Includes automated vulnerability scanning and basic manual verification with a professional report.
What does the Standard package cover?
Covers 1 target: choose 1 Web, 1 API, or 1 Network IP. Ideal for complex systems (up to 20 endpoints/login areas). Includes deep manual penetration testing to find advanced business logic flaws and vulnerabilities.
What does the Premium package cover?
Dedicated to mobile security. Covers 1 target: choose 1 Android or 1 iOS app. Includes static and dynamic analysis (SAST/DAST), reverse engineering, and security testing of its connected backend APIs.
What do I need to provide for a Greybox API penetration test?
Please provide the API documentation (OpenAPI schema, Swagger, or Postman collection) and active test accounts or API authentication tokens/keys. This allows me to simulate an authenticated user and thoroughly test the business logic of your endpoints.

