SanadSquad

Service

Penetration testing

Simulated real-world attacks against web applications, APIs, blockchain infrastructures, SDKs, and web3 off-chain components.

What we test

Different software requires different methods. We cover the following systems.

Infrastructures

Blockchain infrastructure, node and validator setups, SDKs, and Layer 1 systems.

Web3 applications

The off-chain half of an on-chain system: wallets, bridge SDKs, and key management services.

Web and mobile applications

Web and mobile applications, checking DoS attacks, broken authorization, phishing surface.

How an engagement runs

Four stages from the first read and understanding of the project, ending with a final detailed report about the engagement.

  1. Scoping

    We read the codebase, its architecture, the docs, and any previous reports before quoting. You get confirmation of what is in scope, the fixed price, the duration, and the number of researchers who will be on it.

  2. Scanning and discovery

    Automated and AI-assisted scanners map the system: every flow, every entry point, and any already-known issue in the stack you depend on are getting caught at this stage.

  3. Exploitation

    Researchers work through the codebase and attack it with different attack surface including denial of service, broken authorization, data exfiltration by simulating a real adversary.

  4. Mitigation and ongoing support

    You implement the fix for each issue, we review each one. Not only that the original issue is solved, but that the fix has not opened a new issue somewhere else.

Tell us what you are building.

Send the repo, the spec, or a paragraph describing the system. We reply with scope, timeline, and a fixed price.