SERVICES / PENETRATION TESTING
Penetration testing, done by hand.
We break into systems for a living — with written permission, a defined scope, and a report your engineers will actually use. Web, mobile, API, and network testing from our team in Beirut, for companies in Lebanon and across MENA.
Engagement details
What we test
- Web applications.Authentication and session flows, access control, business logic, injection — the bugs scanners flag, and the ones they can't.
- Mobile apps.Android and iOS clients plus the APIs behind them: local storage, certificate pinning, backend authorization.
- APIs.REST and GraphQL. Broken object-level authorization, mass assignment, rate limiting, key handling.
- Networks.External perimeter and internal Active Directory: what an attacker reaches from the internet, and how far they get from one foothold inside.
Every finding is real
We don't paste scanner output into a PDF. Every finding in a Hash report was exploited by a person on our team, comes with reproduction steps, and is ranked by the damage it can actually do — not by a CVSS number alone. If it's in the report, it's real. That's what "zero false positives" means here.
How an engagement runs
- Scope.A call where we agree on targets, test windows, and rules of engagement. You get it in writing.
- Test.Manual-first testing during the agreed window. Production stays safe: destructive checks only ever run with explicit sign-off.
- Report.An executive summary your management can read, and technical detail your developers can act on — finding, impact, reproduction, fix.
- Debrief and retest.A walkthrough call with your team, and when you've fixed the findings, we verify the fixes. The retest is included, not an add-on.
For audits and compliance
Our reports are written to hold up in front of auditors — VAPT evidence for ISO 27001, PCI-DSS, and SOC 2. If your auditor asks for something specific, we've probably formatted it before.
Why Hash
The people testing your systems hunt vulnerabilities in the wild — Hash researchers have been acknowledged for responsibly disclosed vulnerabilities by Microsoft, Google, OpenAI, PayPal, NASA, Duolingo, and Île-de-France Mobilités — and teach offensive security to hundreds of students across Lebanese universities. We're based in Beirut: on-site anywhere in Lebanon, remote across the region.
Common questions
- How long does a penetration test take?
Most engagements run one to three weeks depending on scope — a single web app sits at the short end, a full external and internal network at the long end. You'll have a date for the report before we start.
- Will testing break production?
No. Testing is scoped and rate-limited, and anything potentially disruptive is agreed with you in advance or run against staging.
- What do you need from us to start?
A scoping call, a signed authorization, and access details for the agreed targets. For web and API tests, a test account per role helps us cover authorization properly.
- What's the difference between this and a vulnerability scan?
A scan is software listing potential issues, most of which turn out to be noise. A penetration test is people proving what's actually exploitable and how deep it goes. You need the second one for real assurance — and usually for your audit.
- Is the retest included after we fix the findings?
Yes. Fix the findings, tell us, and we verify them at no extra cost. The engagement isn't done until the report reflects your fixed state.
- How much does it cost?
Scope decides. Tell us what you need tested and we'll quote it after the scoping call — the scoping call is free.
Web, mobile, API, and network. Every finding exploited by hand, retest included.
Get a scope and a quote.
Tell us what you're running — we'll come back within two business days.
Request a briefing