This is a genuine web-application penetration test we ran for a client — the same report they received — with everything that identifies them removed so it can be public. It shows what the agent actually finds and how it proves each finding: the vulnerabilities, their severities, the endpoint and parameter behind each, and the steps to reproduce (evidence is redacted).
What we kept, and what we removed
Kept — every finding, its severity and vulnerability class, the endpoint and method, reproduction steps, remediation, and the structure of a real deliverable: the scope table, the coverage matrix, and the controls that were tested and held.
Removed — the client's name, their hostnames (shown as example.test), the test credentials, and the raw HTTP request/response appendix.
Web application · redacted engagement · PDF
Read the report (PDF) →