Thick Client Security Evaluation
Reverse-engineering, tamper-resistance and secure update checks for desktop and heavy-client apps.
Why companies need thick-client evaluation
Who should get this
Key benefits
Identify secrets embedded in binaries and unsafe local storage
Detect insecure IPC that leaks data to other processes
Check update mechanisms for tamper and supply-chain risks
Provide hardening guidance to resist reverse-engineering
Scope — What we test
Methodology
- Collect binaries and environment setup
- Static binary analysis and dependency review
- Dynamic runtime testing including tamper attempts
- Reverse-engineer critical modules and inspect keys
- Report with PoC, mitigations and hardening steps
Deliverables
Timeline & pricing guide
Example (anonymized)
Frequently asked questions
Common questions we hear before starting an assessment — click a question to reveal a short, clear answer.
Small apps: 1–5 days. Medium: 5–10 days. Complex systems: custom timeline.
We avoid destructive checks in production and schedule high-risk tests in staging when possible.
No — blackbox tests work. Source access enables deeper code review.
Yes — PoCs, prioritized fixes and developer-focused guidance are included.
Yes — retest packages validate fixes.
Executive summary, prioritized findings, PoCs and workshop walkthroughs.
Yes — mutual NDAs and secure report distribution are standard.
Windows, macOS, Linux and cross-platform frameworks like Electron and .NET.
Yes — we look for bypassable licensing and recommend robust implementation patterns.
We follow strict NDAs and treat all code and findings as highly confidential.
