06 / 11

Desktop Application Penetration Testing (Electron)

We test desktop and thick-client applications, including Electron builds, for renderer sandbox escapes, IPC boundary flaws, insecure local credential storage, and privilege boundaries a local attacker can cross.

Desktop Application Penetration Testing (Electron) illustration

What is desktop application penetration testing?

Desktop application penetration testing examines a packaged application running on a user workstation, rather than a website served to a browser. That includes Electron and other thick-client applications, and it covers the parts a web test cannot reach: inter-process communication boundaries, the renderer and its sandbox, how the application stores credentials and tokens on disk, how it authenticates and validates its own update channel, and what a user with local access can reach or modify. If your desktop application talks to the same backend as your web application, a web pentest covers that shared backend but not the shipped binary, its local storage or its runtime.

Testing Checklist

Every engagement covers these critical security areas.

Node integration and contextIsolation posture
Renderer sandboxing and process isolation
IPC message validation and privilege escalation paths
DevTools exposure in production builds
Remote content loading and navigation controls
Local token, credential, and session persistence
Configuration and secrets stored on disk
Tamper resistance of on-device state
Client-side business logic and validation bypass
Auto-update channel and code-signing integrity
Third-party dependency and framework versions
Local privilege boundaries and host configuration

Testing Methodology

A structured, repeatable process that ensures thorough coverage and actionable results.

STEP 01

Build and Configuration Review

Inspect the packaged application for Node integration exposure, contextIsolation and sandbox settings, DevTools accessibility, and whether the renderer loads remote content in production builds.

STEP 02

IPC Boundary Testing

Map the inter-process communication surface between renderer and main process, then test whether the renderer can invoke privileged operations it should not reach.

STEP 03

Local Storage and Credential Handling

Examine how authentication tokens, session state, and configuration are persisted on disk, and whether they survive tampering by a local user.

STEP 04

Privilege Boundary Assessment

Establish what a low-privilege local account can read, modify, or exfiltrate, including host configuration relevant to a user with console or shell access.

STEP 05

Client-Side Logic Review

Test validation, state machines, and decision logic that runs on the device rather than server-side, where a determined user controls the runtime.

STEP 06

Reporting and Remediation

Deliver findings tagged with CWE identifiers and scored with CVSS v3.1, mapped to DASVS (AFINE) verification requirements, with reproduction steps and fixes specific to the framework in use.

Want to scope your desktop application pentest engagement? Both founders take the discovery call.

What you get with Desktop Application Pentest at each tier

Tier Includes Price
Startup 1 scope, 5 business days, 6 hours founder-led consulting, 1 free retest within one month of the v1.0 report. INR 74,999
Growth 2 scopes, 10 business days, SOC 2 and ISO 27001 control mapping per finding, a signed Letter of Attestation, 12 hours founder-led consulting, 1 free retest. INR 1,79,999

What counts as one scope: One desktop application, one production build, for one platform: Windows or macOS. Includes its Electron or thick-client runtime. The same app built for the second platform is a second scope.

Each additional scope adds 5 business days, so 3 scopes is 15 and 4 is 20. All prices exclude taxes. See every scope definition.

All prices exclude taxes. International engagements invoiced in local currency at snapshot FX.

Framework Alignment

These are the standards that apply to this scope type. Which of them we run on your engagement depends on what you are buying: a checklist-style assessment covers the baseline categories set out in the standards listed here, while audit-evidence work adds systematic test-case coverage and control verification. We scope that with you before the engagement rather than applying every framework by default.

DASVS (AFINE)OWASP Desktop App Security Top 10PTESCWECVSS v3.1 + v4.0

Compliance Coverage

ISO
ISO 27001:2022
A.8.8 management of technical vulnerabilities, A.8.26 application security requirements, A.8.28 secure coding, A.8.29 security testing in development and acceptance
SOC
SOC 2
CC7.1: Vulnerability detection and monitoring. CC6.1: Logical and physical access controls

Deliverables

What you walk away with at the end of every engagement.

01

Executive summary with desktop-specific risk overview

02

Technical findings with reproduction steps, CWE identifiers, and CVSS v3.1 ratings

03

IPC and privilege boundary assessment

04

Local storage and credential handling review

05

Remediation guidance specific to your desktop framework

06

1 free retest within one month of the v1.0 report, returned as v2.0

07

Letter of Attestation signed by the lead pentester (Growth plan)

Frequently Asked Questions

Does a web application pentest cover our Electron desktop app?

It covers the shared backend and that work genuinely transfers, so you are not paying twice for the same API testing. It does not cover the desktop application itself. A web pentest runs against a server you control, inside a browser sandbox you did not write. A desktop application ships to a machine the attacker may already own, carries its own runtime, writes its own files, and often has privileges a browser tab never has. The realistic questions are whether contextIsolation and nodeIntegration are configured safely, whether an IPC message from the renderer can reach a privileged main-process handler, whether a renderer sandbox escape is possible, and what is sitting in local storage unencrypted.

What counts as one desktop application scope?

One desktop application, one production build, for one platform: Windows or macOS. The same application built for the second platform is a second scope, because the packaging, the storage locations, the platform APIs and the signing and update mechanics all differ, and the findings genuinely differ with them. The Electron or thick-client runtime the application ships with is included in the scope rather than counted separately.

How much does a desktop application pentest cost and how long does it take?

One desktop application scope is INR 74,999 plus taxes under the Startup Pentest plan, tested over 5 business days from kickoff to the v1.0 report. Testing the same application on both Windows and macOS is two scopes at INR 1,79,999 plus taxes under the Growth Pentest plan over 10 business days, and that plan adds SOC 2 and ISO 27001 control mapping per finding plus a signed Letter of Attestation. Business days are Monday to Friday. Both plans include founder-led consulting hours and one full retest within one month of the v1.0 report. We need a signed, installable production build, not a development build, because signing and packaging are part of what gets tested.

What evidence does a desktop application pentest produce for an auditor?

A technical report with reproduction steps, CVSS severity and remediation guidance for every finding, plus a two-page executive summary. On the Growth plan each finding is mapped to the control it evidences: ISO 27001:2022 A.8.8 management of technical vulnerabilities and A.8.29 security testing in development and acceptance, and SOC 2 CC7.1 vulnerability detection and monitoring. A pentest report does not evidence A.8.25 secure development life cycle, which is evidenced by your development process, and we do not claim it. The retest produces a v2.0 report showing which findings were verified fixed.

Ready to secure your desktop application?

Pentest packages from INR 74,999 (~$790 / ~€680, indicative as at August 2026). Includes consulting hours + 1 free retest within one month. Both founders on every engagement: Rathnakara (OSCP) leads testing, Ashok handles delivery + compliance.