Desktop Application Penetration Testing (Electron)
We test desktop and thick-client applications, including Electron builds, for renderer sandbox escapes, IPC boundary flaws, insecure local credential storage, and privilege boundaries a local attacker can cross.
What is desktop application penetration testing?
Desktop application penetration testing examines a packaged application running on a user workstation, rather than a website served to a browser. That includes Electron and other thick-client applications, and it covers the parts a web test cannot reach: inter-process communication boundaries, the renderer and its sandbox, how the application stores credentials and tokens on disk, how it authenticates and validates its own update channel, and what a user with local access can reach or modify. If your desktop application talks to the same backend as your web application, a web pentest covers that shared backend but not the shipped binary, its local storage or its runtime.
Testing Checklist
Every engagement covers these critical security areas.
Testing Methodology
A structured, repeatable process that ensures thorough coverage and actionable results.
Build and Configuration Review
Inspect the packaged application for Node integration exposure, contextIsolation and sandbox settings, DevTools accessibility, and whether the renderer loads remote content in production builds.
IPC Boundary Testing
Map the inter-process communication surface between renderer and main process, then test whether the renderer can invoke privileged operations it should not reach.
Local Storage and Credential Handling
Examine how authentication tokens, session state, and configuration are persisted on disk, and whether they survive tampering by a local user.
Privilege Boundary Assessment
Establish what a low-privilege local account can read, modify, or exfiltrate, including host configuration relevant to a user with console or shell access.
Client-Side Logic Review
Test validation, state machines, and decision logic that runs on the device rather than server-side, where a determined user controls the runtime.
Reporting and Remediation
Deliver findings tagged with CWE identifiers and scored with CVSS v3.1, mapped to DASVS (AFINE) verification requirements, with reproduction steps and fixes specific to the framework in use.
Want to scope your desktop application pentest engagement? Both founders take the discovery call.
What you get with Desktop Application Pentest at each tier
| Tier | Includes | Price |
|---|---|---|
| Startup | 1 scope, 5 business days, 6 hours founder-led consulting, 1 free retest within one month of the v1.0 report. | INR 74,999 |
| Growth | 2 scopes, 10 business days, SOC 2 and ISO 27001 control mapping per finding, a signed Letter of Attestation, 12 hours founder-led consulting, 1 free retest. | INR 1,79,999 |
What counts as one scope: One desktop application, one production build, for one platform: Windows or macOS. Includes its Electron or thick-client runtime. The same app built for the second platform is a second scope.
Each additional scope adds 5 business days, so 3 scopes is 15 and 4 is 20. All prices exclude taxes. See every scope definition.
All prices exclude taxes. International engagements invoiced in local currency at snapshot FX.
Framework Alignment
These are the standards that apply to this scope type. Which of them we run on your engagement depends on what you are buying: a checklist-style assessment covers the baseline categories set out in the standards listed here, while audit-evidence work adds systematic test-case coverage and control verification. We scope that with you before the engagement rather than applying every framework by default.
Compliance Coverage
Deliverables
What you walk away with at the end of every engagement.
Executive summary with desktop-specific risk overview
Technical findings with reproduction steps, CWE identifiers, and CVSS v3.1 ratings
IPC and privilege boundary assessment
Local storage and credential handling review
Remediation guidance specific to your desktop framework
1 free retest within one month of the v1.0 report, returned as v2.0
Letter of Attestation signed by the lead pentester (Growth plan)
Frequently Asked Questions
Does a web application pentest cover our Electron desktop app?
It covers the shared backend and that work genuinely transfers, so you are not paying twice for the same API testing. It does not cover the desktop application itself. A web pentest runs against a server you control, inside a browser sandbox you did not write. A desktop application ships to a machine the attacker may already own, carries its own runtime, writes its own files, and often has privileges a browser tab never has. The realistic questions are whether contextIsolation and nodeIntegration are configured safely, whether an IPC message from the renderer can reach a privileged main-process handler, whether a renderer sandbox escape is possible, and what is sitting in local storage unencrypted.
What counts as one desktop application scope?
One desktop application, one production build, for one platform: Windows or macOS. The same application built for the second platform is a second scope, because the packaging, the storage locations, the platform APIs and the signing and update mechanics all differ, and the findings genuinely differ with them. The Electron or thick-client runtime the application ships with is included in the scope rather than counted separately.
How much does a desktop application pentest cost and how long does it take?
One desktop application scope is INR 74,999 plus taxes under the Startup Pentest plan, tested over 5 business days from kickoff to the v1.0 report. Testing the same application on both Windows and macOS is two scopes at INR 1,79,999 plus taxes under the Growth Pentest plan over 10 business days, and that plan adds SOC 2 and ISO 27001 control mapping per finding plus a signed Letter of Attestation. Business days are Monday to Friday. Both plans include founder-led consulting hours and one full retest within one month of the v1.0 report. We need a signed, installable production build, not a development build, because signing and packaging are part of what gets tested.
What evidence does a desktop application pentest produce for an auditor?
A technical report with reproduction steps, CVSS severity and remediation guidance for every finding, plus a two-page executive summary. On the Growth plan each finding is mapped to the control it evidences: ISO 27001:2022 A.8.8 management of technical vulnerabilities and A.8.29 security testing in development and acceptance, and SOC 2 CC7.1 vulnerability detection and monitoring. A pentest report does not evidence A.8.25 secure development life cycle, which is evidenced by your development process, and we do not claim it. The retest produces a v2.0 report showing which findings were verified fixed.
Not ready for a full engagement yet?
Two lower-friction ways to start: run a free self-serve scan, or see the exact report you would receive.
OpenEASD
Open source external attack surface scanner. Run it yourself against your domain. No signup, no data leaves your network.
Get the toolSee a Sample Report
The exact redacted pentest report your engineering team, auditor, and investor receive, including findings, fix guidance, and compliance mapping.
View sample reportReady to secure your desktop application?
Pentest packages from INR 74,999 (~$790 / ~€680, indicative as at August 2026). Includes consulting hours + 1 free retest within one month. Both founders on every engagement: Rathnakara (OSCP) leads testing, Ashok handles delivery + compliance.