Haxact

Engagement report

A redacted report from a real engagement

Pentest quality is hard to judge from a pitch, so here is a redacted report from a real web-application engagement, to give you an idea of what you can expect.

This is a genuine web-application penetration test we ran for a client — the same report they received — with everything that identifies them removed so it can be public. It shows what the agent actually finds and how it proves each finding: the vulnerabilities, their severities, the endpoint and parameter behind each, and the steps to reproduce (evidence is redacted).

What we kept, and what we removed

Kept — every finding, its severity and vulnerability class, the endpoint and method, reproduction steps, remediation, and the structure of a real deliverable: the scope table, the coverage matrix, and the controls that were tested and held.

Removed — the client's name, their hostnames (shown as example.test), the test credentials, and the raw HTTP request/response appendix.

Web application · redacted engagement · PDF

Read the report (PDF) →

See how it works →