Solutions / What we cover

Test what happens after login.

Casco signs in with test accounts, uses the workflows in scope, and records the pages, endpoints, WebSockets, and requests it encounters. It then checks whether a user can cross a role or tenant boundary, change data they should not control, or abuse an application-specific workflow.

Testing workflowApproved scope only
  1. 01Approved scopeDomains, accounts, roles, and limits
  2. 02Use the applicationSign in and record application traffic
  3. 03Security testsChange roles, objects, inputs, and request order
  4. 04Report and retestAffected resource, impact, fix, and retest
Pages, requests, roles, and resultsApproved scope only

What is web application pentesting?

Web application pentesting checks a running product for vulnerabilities that can be reached through the browser or the services it calls. Casco tests only the approved domains, accounts, roles, and workflows. Confirmed findings include the affected resource, impact, fix guidance, and steps an engineer can rerun.

How Casco tests

How Casco tests a web application.

Scroll through the four parts of the test. The diagram shows what Casco has at each point, what it checks next, and what it records.

Test contextStep 01 / 04
Domains
Rules
Test roles
Application
StageScope
Scope recorded
01

Set the scope

List the approved domains, environments, accounts, roles, and actions Casco must avoid. Add source code or infrastructure access only if it is part of the test.

02

Use the application

Casco signs in with the provided accounts and records pages, endpoints, WebSockets, screenshots, DOM state, cookies, console output, and network requests.

03

Test access and business rules

Casco changes roles, object references, inputs, and request sequences to check authorization, tenant isolation, session handling, file processing, and business logic.

04

Write and retest findings

Each confirmed issue can include the affected resource, impact, fix guidance, a runnable reproduction notebook, execution output, and captured requests when request tracking is available.

Pentest deliverables

What the final report contains.

The report states what Casco tested, how the test was run, what was confirmed, and what engineers need to fix.

  • Executive summary and prioritized findings by severity
  • Approved scope, test limits, and methodology
  • Detailed findings with severity, CVSS, affected resources, description, and impact
  • Fix guidance and supporting requests or execution output when available

Checks included when applicable

What Casco checks for.

Casco reports an issue only after it confirms the behavior. The exact finding includes the affected resource, impact, fix guidance, and available reproduction material.

Broken access control and cross-tenant data exposure
Authentication, session, and token failures
Unsigned or unverified webhooks
API and WebSocket authorization flaws
Injection and unsafe file handling
Business logic and workflow abuse

Frequently asked questions

Web application pentesting questions, answered.

What is AI web application pentesting?+

AI web application pentesting uses software agents to operate a web application and choose the next security test from what they observe. Casco signs in with approved test accounts, uses the application, changes requests and inputs, and reports vulnerabilities it can reproduce.

How is Casco different from a web vulnerability scanner?+

A scanner runs a catalogue of checks and often reports possible issues. Casco uses the application, follows logged-in workflows, changes its tests based on the responses, and reports issues it can confirm.

Does Casco test authenticated web applications?+

Yes. Provide test accounts for each role or tenant boundary you want included. Casco uses those accounts only within the approved scope.

Can Casco test business logic and multi-tenant authorization?+

Yes. Casco can compare roles and tenant accounts and test application-specific workflows when the required accounts and objects are available.

What access does Casco need to test a web application?+

Casco needs the approved domains, rules of engagement, and test accounts for logged-in coverage. Some environments also need Casco IP addresses on an allowlist. Documentation, source code, and infrastructure access are optional unless the scope requires them.

What does Casco observe during web application reconnaissance?+

Casco can record pages, endpoints, WebSockets, screenshots, DOM state, cookies, console output, network requests, and the user flows it followed.

What comes with a confirmed web application finding?+

A finding can include severity, the affected resource, impact, fix guidance, a runnable reproduction notebook, execution output, and captured requests when request tracking is available.

Does Casco retest web application findings?+

Yes. Casco records whether a finding is still exploitable, being retested, fixed, or accepted as risk.

Scope a pentest for this system.

Book a demo