Over the last few years, Cigniti has built up a repository of hundreds of security test cases and developed capabilities using both open source and proprietary security testing tools.
Security Testing Techniques: We implement best-of-breed techniques to check for SQL injection, Cross-Site Scripting, Cross Site Request Forgery (CSRF) (including the top ten OWASP), and zero-day vulnerabilities along with vulnerabilities discovered by our R&D team through CoE. Our methodology consists of test techniques that are manually executed, for example, domain/business logic-driven tests which are then translated into manually-crafted payload to assess the vulnerabilities and showcase steps that can exploit any weakness in the Information/Network system.
Testlets for various types of Security Testing: Cigniti has collated Test-lets based on various security test types that are employed for Security testing. The tests include testing for vulnerabilities such as SQL Injection, Cross-Site Scripting, Broken Authentication and Session Management, Unsecure Direct Object Reference, Cross-Site Request Forgery, Security Misconfiguration, Unsecure Cryptographic Usage, Failure to Restrict URL Access, Insufficient Transport Layer Protection, and Invalidated Redirects and Forwards.