Manual testing by experienced pentesters finds vulnerabilities that automated scanners systematically miss. Where a scanner works based on known patterns, a pentester can understand logic, interpret context and construct creative exploit chains. This is the core of why DongIT performs every pentest manually, with automated tools only as an initial supporting step.
What manual testing finds that scanners miss
1. Business logic flaws
Scanners do not understand business logic. They do not know that a user with the role "customer" should not be able to view another customer's orders (IDOR), that a discount code should not be usable multiple times, or that an approval workflow should not be bypassable by navigating directly to a later step. This type of vulnerability arises from human design choices and requires human understanding to find.
2. Complex exploit chains
A single vulnerability may seem harmless. A combination of three subtle issues can lead to full compromise. For example: information disclosure (version number), combined with a deserialization flaw in that specific version, plus insufficient sandboxing of the deserializer. Scanners report these separately as low-risk findings. Our pentesters recognize the complete attack path and escalate the risk classification.
3. Context-dependent vulnerabilities
Multi-tenant SaaS platforms with tenant isolation require deep verification: can one tenant see another tenant's data via a shared cache, an API endpoint or a misconfiguration in row-level security? Race conditions in financial transactions, TOCTOU flaws (Time of Check, Time of Use) and subtle authorization bypasses all require manual verification in the specific context of your application.
4. False positive verification
Scanners regularly report vulnerabilities that pose no actual risk because the context makes them non-exploitable. Our pentesters validate each finding with actual exploitation verification: is this pattern actually exploitable in your specific setup? This prevents you from spending remediation time on findings without real risk.
5. New attack patterns
Attackers publish new techniques weekly. Automated scanners must be updated with these patterns before they can detect them. Our pentesters follow threat intelligence from NCSC-NL and MITRE ATT&CK and apply recently published techniques directly during the pentest, without waiting for scanner updates.
How DongIT approaches manual testing
Our pentesters are certified with OSCP, OSWE, OSEP, OSED, CRTO, CISSP and CISA. Every pentest follows a structured methodology in which automated scanners are used as a first step for complete visibility of all services and versions, followed by manual verification and deeper investigation. Every finding is reviewed by a second senior ethical hacker (four-eyes principle).
The extent of manual testing varies per pentest package, indicated by stars on our packages page. Learn more? Read the FAQ on why choose DongIT, or contact us for a complimentary scoping conversation.
Nederlands