Ethical Hacking & Penetration Testing
Professional security testing designed to identify exploitable weaknesses in websites, web applications, APIs and other in-scope assets — only after the system owner or authorized representative provides written permission and the testing scope is agreed.
Testing Services
Web Application Pentest
Manual and tool-assisted testing of authentication, authorization, sessions, input handling, business logic and common web security weaknesses.
API Security Testing
Assessment of API authentication, authorization, input validation, access controls, rate limiting and sensitive-data exposure.
Website / CMS Testing
Security assessment of authorized websites and CMS deployments, including configuration and exposure checks.
Network / Infrastructure Testing
Only where explicitly included in the signed scope, with agreed targets, testing windows and safe-testing constraints.
Authenticated Testing
Testing with client-provided test accounts or credentials specifically created and approved for the engagement.
Retesting
Follow-up validation of agreed remediation items, with findings mapped back to the original report.
How an Authorized Engagement Works
1. Scope
Client identifies assets, domains, IPs, applications, environments, accounts and testing window.
2. Written Authorization
Client confirms ownership or authority and signs the testing authorization before active testing begins.
3. Rules of Engagement
Allowed techniques, exclusions, rate limits, emergency contacts, stop conditions and evidence handling are agreed.
4. Testing & Reporting
Testing is performed within scope. Findings are documented with evidence, impact, remediation guidance and limitations.
Typical Scope
| Area | Examples |
|---|---|
| Applications | Web applications, APIs, authorized mobile/API backends, staging environments. |
| Security controls | Authentication, authorization, session management, input validation, access control and security configuration. |
| Evidence | Minimal necessary screenshots, request/response evidence, timestamps and reproducible technical observations. |
| Deliverables | Executive summary, scope, methodology, findings, risk description, evidence, remediation guidance and retest status where applicable. |
Explicit Exclusions Unless Separately Authorized
- Denial-of-service or distributed denial-of-service testing.
- Destructive actions, data deletion or intentional service disruption.
- Testing of third-party systems, customer systems or infrastructure outside the approved scope.
- Social engineering, phishing, physical intrusion or credential harvesting unless specifically contracted and legally authorized.
- Persistence, backdoors, malware deployment or covert access mechanisms.
- Accessing, copying or exposing unnecessary personal, financial or confidential data.
Standards & Methodology
Where appropriate, the engagement methodology may reference OWASP testing guidance, applicable ISO/IEC security practices, relevant CERT-In guidance and other agreed security-testing methodologies. The exact methodology and scope will be documented for each engagement. A website page should not represent 8X Securities as CERT-In empanelled unless that status is actually held.
