Skip to main content

Security Assessment Checklists

Pick a module to start assessing. Progress and notes are saved in your browser; export the full assessment any time.

1792checks
413technologies
121categories
23live platforms
Overall progress0 / 1792 (0%)
Web ApplicationAssess modern web apps end to end
299 checks

A practical checklist for authentication, sessions, access control, injection, business logic, and configuration testing of web applications.

0/299 (0%)
APIREST & GraphQL, OWASP API Top 10
75 checks

Checks aligned to the OWASP API Security Top 10 (2023): object- and function-level authorization, authentication, resource consumption, SSRF, and inventory management.

0/75 (0%)
MobileiOS & Android, OWASP MASVS
53 checks

Checks aligned to the OWASP MASVS / Mobile Top 10: insecure storage, transport security, secrets, platform interaction, and reverse-engineering resilience.

0/53 (0%)
Thick ClientDesktop & native applications
68 checks

Thick client assessment: local data storage, inter-process communication, traffic interception, DLL/binary protections, and privilege handling.

0/68 (0%)
Secure Code ReviewSource-level vulnerability discovery
89 checks

Manual and assisted source code review: dangerous sinks, injection patterns, authn/authz flaws, secrets, and insecure dependencies across major languages.

0/89 (0%)
CloudAWS, Azure, GCP misconfiguration
68 checks

Cloud assessment checks: identity and access management, exposed storage, instance metadata SSRF, logging, and common misconfigurations across providers.

0/68 (0%)
DevSecOpsSecurity across the SDLC
60 checks

Embedding security into the software lifecycle: SAST/DAST/SCA gates, secrets management, supply-chain controls, and policy-as-code.

0/60 (0%)
NetworkInfrastructure & service testing
72 checks

Network and infrastructure assessment: host discovery, service enumeration, exposed management interfaces, and transport hardening.

0/72 (0%)
Wi-FiWireless network assessment
67 checks

Wireless assessment: encryption and authentication (WPA2/WPA3), rogue/evil-twin access points, PMKID/handshake attacks, and client isolation.

0/67 (0%)
FirewallPerimeter & ruleset testing
56 checks

Firewall and perimeter testing: ruleset review, egress filtering, segmentation validation, and evasion of filtering controls.

0/56 (0%)
Active DirectoryDomain enumeration to DA
126 checks

Active Directory assessment: enumeration, Kerberos attacks (Kerberoasting, AS-REP), ACL abuse, delegation, lateral movement, and privilege escalation to domain dominance.

0/126 (0%)
InfrastructureHosts, services & hardening
51 checks

Infrastructure security assessment: host and OS hardening, patch posture, exposed services, build review, and configuration baselines.

0/51 (0%)
MCP SecurityModel Context Protocol servers/tools
68 checks

Security assessment of Model Context Protocol servers and tools: tool-poisoning, prompt injection via tool output, authz scoping, and unsafe capability exposure.

0/68 (0%)
LLM SecurityOWASP LLM Top 10
65 checks

LLM application assessment aligned to the OWASP LLM Top 10: prompt injection, insecure output handling, data leakage, excessive agency, and model DoS.

0/65 (0%)
Threat ModelingSTRIDE, attack trees, trust boundaries
58 checks

Structured threat modeling: asset and trust-boundary mapping, STRIDE/attack-tree analysis, abuse cases, and mitigation tracking.

0/58 (0%)
Configuration ReviewHardening & baseline review
67 checks

Configuration and hardening review against CIS-style baselines: services, permissions, logging, secrets handling, and default-credential exposure.

0/67 (0%)
Containers & KubernetesImages, runtime & cluster security
64 checks

Container and Kubernetes assessment: image hygiene, privileged containers and escapes, RBAC, network policies, secrets, and admission control.

0/64 (0%)
CI/CDPipeline & supply-chain attacks
58 checks

CI/CD pipeline assessment: poisoned pipeline execution, secret exfiltration, runner compromise, dependency confusion, and artifact integrity.

0/58 (0%)
IoTDevice, firmware & radio
68 checks

IoT assessment: firmware extraction and analysis, hardware/UART/JTAG interfaces, insecure protocols, and cloud/companion-app integration.

0/68 (0%)
BlockchainSmart contracts & Web3
55 checks

Blockchain and smart-contract assessment: reentrancy, access control, oracle and arithmetic flaws, signature replay, and Web3 front-end risks.

0/55 (0%)
Phishing AssessmentSocial-engineering campaigns
66 checks

Phishing and social-engineering assessment: pretext and infrastructure setup, payload and landing-page design, evasion, and reporting metrics.

0/66 (0%)
OSINTOpen-source intelligence gathering
60 checks

Open-source intelligence: domain and infrastructure footprinting, employee and credential exposure, code and document leakage, and exposed assets.

0/60 (0%)
ForensicsEvidence acquisition & analysis
79 checks

Digital forensics and incident response: sound evidence acquisition, disk/memory/network analysis, timeline reconstruction, and chain of custody.

0/79 (0%)