TESTING METHODOLOGIES
Testing methodologies
Every Haxoris engagement follows a published methodology. That is what makes a test repeatable, comparable year on year, and defensible to an auditor — rather than dependent on which tester you happened to get.
These are the standards we work to, and what each one is actually for.
TESTING METHODOLOGIES
Why methodology matters
Two testers given the same application and no methodology will produce two different reports, and neither can tell you what was not checked. A published standard fixes the coverage, so a finding of "nothing here" means something.
It also makes your reports comparable across years and across suppliers — which is exactly what a certification auditor or a customer security questionnaire asks you to demonstrate.
The standards we work to
OWASP Top 10
The ten most critical web application risk categories, revised in 2025. The baseline every web test covers.
OWASP WSTG
The Web Security Testing Guide — the detailed, test-by-test procedure behind a thorough web application assessment.
OWASP ASVS
The Application Security Verification Standard: measurable requirements at three assurance levels, so coverage is a number and not an opinion.
OWASP MASVS & MASTG
The mobile equivalents of ASVS and WSTG, used on every iOS and Android engagement.
MITRE ATT&CK
The adversary tactic and technique catalogue we map red team activity to, so you can see which techniques your controls actually detected.
PTES and NIST SP 800-115
Execution standards covering the shape of an engagement end to end — scoping, intelligence gathering, exploitation, post-exploitation and reporting.
Which methodology applies to your test
| If you are testing… | We work to | You can also read |
|---|---|---|
| A web application or API | OWASP Top 10:2025, WSTG, ASVS | OWASP · WSTG · ASVS |
| A mobile app | OWASP MASVS and MASTG | Mobile penetration testing |
| Internal network or Active Directory | PTES, NIST SP 800-115, MITRE ATT&CK | Active Directory wiki |
| Cloud infrastructure | CIS Benchmarks, provider well-architected guidance | Cloud vulnerabilities wiki |
| An LLM or AI integration | OWASP Top 10 for LLM Applications | LLM Top 10 wiki |
Methodologies — common questions
01 Which methodology will you use on our test?
It depends what we are testing. Web and API work follows OWASP Top 10:2025, WSTG and ASVS; mobile follows MASVS and MASTG; infrastructure and red team work follows PTES and NIST SP 800-115 with findings mapped to MITRE ATT&CK. We state the methodology in the scope document before we start.
02 Can you test against a specific standard we need?
Yes. If your auditor, your customer or your regulator has named a standard, tell us and we will scope to it explicitly and report against its structure.
03 Do you use automated scanners?
As one input, never as the test. Scanners are useful for coverage and for finding known-vulnerable components, but every finding we report is manually verified — we do not forward scanner output as a result.
04 Will the report show what was not tested?
Yes, explicitly. A report that only lists findings tells you nothing about coverage. Ours states the methodology, the scope and anything excluded, so you know what the absence of a finding actually means.
Not sure which methodology fits?
Tell us what you need tested and we will tell you which standard applies and what coverage looks like.
Book a free scoping call