Skip to content

Cost guide

Thick Client Penetration Testing Cost

Thick client penetration testing starts at $6,000 for one desktop application, fixed in writing before work begins. It covers local storage and secrets, DLL hijacking, file permissions, traffic interception, and the back-end API the client calls, with a full report and a free retest of every fix.

Thick ClientFixed price

Small

One desktop application on one operating system, built in .NET, Java, or Electron, with up to 2 user roles, a standard HTTPS back end, and no obfuscation.

$6,000

Medium

A custom or binary protocol, IPC or a local service running as SYSTEM, an auto-updater, several roles, or Windows plus macOS. Also Citrix or RDS published-app breakout.

$9,200

Large

Native C++ or Delphi that needs disassembly, obfuscation or anti-tamper, protocol fuzzing, several platforms, or a large back-end API tested in depth.

On request
Free retest includedFrom $6,000

What moves the number

What drives the cost of thick client penetration testing

01

Language and build

.NET, Java, and Electron apps decompile cleanly, which keeps analysis quick. Native C++ or Delphi needs disassembly, and obfuscation or anti-tamper controls add time to defeat before testing starts.

02

Local attack surface

A local service running as SYSTEM, named pipes, COM objects, and an auto-updater each open privilege-escalation paths. The more the client does on the machine, the more there is to test.

03

Network protocol

A client that talks HTTPS to a standard API is intercepted quickly. A custom or binary protocol has to be reverse-engineered before it can be tested, which moves the scope up a tier.

04

Platforms

One application on Windows is the Small tier. The same client on Windows and macOS is two sets of local checks, and a published app on Citrix or RDS adds breakout testing.

05

Back-end API size

The API the client calls is tested with it. A standard back end fits the base price. A large API tested in depth is Large-tier work, or can be scoped as its own API test.

In the price

What every thick client penetration testing price includes

  • ✓Local storage and secrets testing across config files, the registry, local databases, and memory
  • ✓DLL search-order hijacking, insecure file and install-path permissions, and local privilege escalation where a service runs with high privilege
  • ✓Traffic interception, TLS pinning bypass, client-side authorization bypass, and the back-end API the client calls
  • ✓A fixed price agreed in writing before work begins, with no hourly billing
  • ✓An executive summary for leadership and a full technical report with reproduction steps (see a sample penetration testing report)
  • ✓A free retest of remediated findings, with the report updated to show them closed
  • ✓An attestation letter and findings platform access at no extra cost
  • ✓Senior in-house testers, no subcontractors or crowdsourced testers

Keep it tight

How to keep the price down

  1. 01Send an installer and a test account for each role during scoping. We size the work from the real build, not a description.
  2. 02Provide a build without obfuscation if you can. Testing the logic is the point, and defeating protection first adds days.
  3. 03Scope to the operating system most of your users run. If a macOS build shares its code with Windows, one platform may cover most of the risk.
  4. 04If only the back end carries the risk, test it as an API penetration test, from $4,000, so the same days are not counted twice.

Timeline

Onboarding begins within 24 hours of a signed proposal. The Small tier takes 5 to 6 testing days, with the report within 2 to 3 weeks of kickoff. The Medium tier takes 8 to 10 days and about 3 weeks. Large scopes are quoted and typically run 12 to 15 days over 4 to 5 weeks. The free retest follows your fixes.

Priced the same forSOC 2PCI DSSHIPAAISO 27001

FAQ

Questions about thick client penetration testing cost

01How much does a thick client penetration test cost?

It starts at $6,000 for one desktop application on one operating system, fixed before work begins, with a free retest. A custom protocol, a local service running as SYSTEM, several roles, or two operating systems is $9,200. Native or obfuscated apps and large back ends are quoted from the scope. Every price is on the pricing page.

02What is a thick client?

A desktop application that does real work on the user's machine instead of in a browser, such as trading, accounting, or line-of-business software. It stores data locally, runs code with the user's or the system's privileges, and talks to a back-end server. All three are attack surface.

03Why does it cost more than a web application test?

Because it adds a local attack surface on top of the server calls a web test covers: DLL loading, file and install permissions, local services, stored secrets, and privilege escalation on the machine. A web application test starts at $5,200. A thick client starts at $6,000.

04Do you test Citrix or RDS published applications?

Yes. Breaking out of a published application into the underlying desktop or server is part of the Medium tier, from $9,200, alongside the application itself.

05Do we need to share source code?

No. We test the compiled application with static and dynamic analysis, the way an attacker would. If you want the code read too, a secure code review can be added at its published prices.

06Is the back-end API included?

Yes. The API the client calls is tested with the client, because many thick-client flaws are authorization checks that only happen on the desktop. A very large back end tested in depth is quoted, or scoped as its own API test.

Get the exact number for your scope

Tell us what needs testing. You get a written fixed price within one business day, and the number does not move once testing starts.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.