THAGHARATVulnerability Hunter
9 years in offensive security

We hunt down the vulnerabilities before attackers do.

Thagharat is a penetration testing practice built on manual, evidence-driven work. We attack your systems the way a real adversary would — then hand you a report your engineers can act on and your auditors will accept.

Certified by eLearnSecurity · INE · OCEG

Sample findingCRITICAL
CVSS 9.1

Authentication bypass via JWT signature confusion

Affected asset
api.client-portal.internal
Status
Reported · PoC verified
Validation
Manually exploited — not scanner output
NCA ECCSAMA CSFPDPLISO 27001PCI DSSOWASP / NISTeWPTXeWPTeCPPTeJPTCAPENGRCPGRCA
9+
Years of hands-on offensive work
7
Professional certifications
24h
Critical findings escalated within
100%
Findings manually validated
What we do

Testing that goes past the scanner

Automated tools find the obvious. We are hired for everything underneath it — business logic, chained exploits, and the misconfigurations no signature catches.

Web Application Penetration Testing

Full-depth assessment of authentication, session handling, access control, injection surfaces and business logic. We chain low-severity issues into the high-impact paths a scanner will never report.

  • OWASP Top 10
  • Business logic
  • Auth bypass
  • eWPT · eWPTX

Network & Infrastructure Testing

External perimeter and internal network assessments, Active Directory attack paths, lateral movement, and privilege escalation to domain compromise — executed safely, under agreed rules of engagement.

  • External
  • Internal
  • Active Directory
  • eCPPT

Mobile Application Security

iOS and Android testing across the full stack: local storage, certificate pinning, IPC, reverse engineering resistance and the backend APIs the app depends on.

  • iOS
  • Android
  • OWASP MASVS
  • API layer

API & Cloud Security Assessment

REST and GraphQL testing for broken object-level authorization, mass assignment and rate-limit failures — alongside cloud configuration review across identity, storage and network boundaries.

  • REST
  • GraphQL
  • BOLA / IDOR
  • Cloud config

Red Teaming & Social Engineering

Objective-based adversary simulation that tests detection and response, not just vulnerabilities. Phishing campaigns, pretexting and physical access scenarios, scoped to what you actually want measured.

  • Adversary simulation
  • Phishing
  • Detection testing

Compliance & GRC Advisory

Gap assessments and readiness work mapped to the frameworks your regulator audits against. We translate technical findings into control-level evidence your compliance team can file.

  • NCA ECC
  • SAMA CSF
  • PDPL
  • ISO 27001
  • GRCA · GRCP
How we work

A process built for evidence

Every engagement runs the same disciplined path. You always know what stage we are at, what we have found, and what happens next.

  1. 01

    Scoping & rules of engagement

    We agree targets, testing windows, escalation contacts and hard boundaries in writing before a single packet is sent. NDA signed up front.

  2. 02

    Reconnaissance & threat modelling

    Attack surface mapping and threat modelling against your actual business risk — so effort goes where a real attacker would concentrate it.

  3. 03

    Exploitation & manual validation

    Findings are proven, not guessed. Each one is manually exploited and captured with a reproducible proof of concept. No unverified scanner noise reaches your report.

  4. 04

    Reporting & risk rating

    An executive summary your board can read, and a technical section your engineers can act on. CVSS-scored, mapped to remediation steps and framework controls.

  5. 05

    Retest & remediation support

    After you fix, we verify. A retest of all confirmed findings is included, with a clean closure letter you can hand to auditors or clients.

Why Thagharat

What you actually get

Manual-first, always

Tooling accelerates discovery; it never replaces judgement. The findings that matter come from a human reading your application logic.

Zero false positives

If we report it, we exploited it. Every finding ships with reproduction steps and evidence, so your team never wastes a sprint chasing a phantom.

Bilingual reporting

Full deliverables in Arabic and English. The same report satisfies a local regulator and an international parent company.

Retest included

Remediation verification is part of the engagement, not a change order. You get a closure letter when the findings are confirmed fixed.

24-hour critical escalation

Anything critical is escalated the moment it is confirmed. You do not wait for the final report to learn your perimeter is open.

Safe by construction

Destructive techniques stay out of scope unless you explicitly authorise them. Production testing follows agreed windows and abort conditions.

Credentials

Certified across offence and governance

Nine years of hands-on offensive security, backed by certifications on both sides of the table — the people who break systems, and the people who audit them.

Offensive security

eWPTX
Web Application Penetration Tester eXtreme
eLearnSecurity / INE
eWPT
Web Application Penetration Tester
eLearnSecurity / INE
eCPPT
Certified Professional Penetration Tester
eLearnSecurity / INE
eJPT
Junior Penetration Tester
eLearnSecurity / INE
CAPEN
Certified Associate Penetration Tester
SecOps Group

Governance & audit

GRCP
Governance, Risk & Compliance Professional
OCEG
GRCA
Governance, Risk & Compliance Auditor
OCEG
Frameworks

Mapped to what your auditor asks for

A penetration test is only half the deliverable. We map every finding to the control it breaks, so the report doubles as compliance evidence.

Saudi Arabia

NCA ECCEssential Cybersecurity Controls

Technical testing aligned to NCA ECC control domains, with findings mapped to the specific controls they affect.

SAMA CSFCyber Security Framework

Assessment support for financial institutions operating under the SAMA framework and its maturity expectations.

PDPLPersonal Data Protection Law

Review of how personal data is stored, transmitted and exposed across your applications and interfaces.

International

ISO 27001Information Security Management

Annex A control testing and evidence packages that fit directly into your ISMS documentation and audit cycle.

PCI DSSPayment Card Industry DSS

Segmentation testing and application assessments meeting Requirement 11 penetration testing obligations.

OWASP / NISTTesting methodologies

Engagements follow OWASP WSTG and MASVS, with reporting structured around the NIST SP 800-115 methodology.

Questions

Before you get in touch

How long does a penetration test take?
Most web application engagements run one to three weeks from kickoff to report, depending on the number of roles, endpoints and business flows in scope. Network and red team engagements typically run longer. We give you a fixed timeline with the scope document — no open-ended billing.
Will testing disrupt our production systems?
Disruption is designed out. We agree testing windows, rate limits, abort conditions and an escalation contact before starting. Destructive techniques such as denial of service are excluded unless you explicitly request and authorise them in writing.
What do we receive at the end?
An executive summary written for non-technical leadership, a technical findings report with CVSS ratings and reproduction steps, a remediation roadmap prioritised by risk, and a framework mapping section. All deliverables are available in Arabic and English.
Do you sign an NDA?
Always, and before any technical discussion of your environment. We can work under your NDA template or provide ours. All engagement data is handled under agreed retention terms and destroyed on request after closure.
Is retesting included?
Yes. Verification of your fixes is part of the engagement, not a separate purchase. Once findings are confirmed remediated, you receive a closure letter suitable for auditors, clients or regulators.
Do you test against Saudi regulatory requirements?
Yes. Engagements can be scoped and reported against NCA ECC, SAMA CSF and PDPL, as well as international standards such as ISO 27001 and PCI DSS. Findings are mapped to specific controls so the report works as audit evidence.
Get started

Tell us what you need tested

Send a short description of your environment and we will come back with a scope, timeline and fixed price. No sales calls, no obligation, and an NDA before any technical detail is shared.

Message us on WhatsApp

Fastest route — usually answered same day

  • NDA signed before scoping
  • Fixed-price engagements
  • Retest included