
Open
Posted
•
Ends in 4 hours
Paid on delivery
I need a comprehensive vulnerability assessment and penetration test performed on my production web application. Because I can grant limited internal knowledge—such as architecture diagrams, sample credentials, and API documentation—I would like the engagement run as a grey box exercise rather than pure black-box reconnaissance. 1 External VA/PT - 4 public IPv4/region - Full manual validation through WAF/security stack 2 Internal VA/PT - 10 segments / 250 live IPs - Credentialed + non-credentialed testing 3 Web Application — Virtual Trust - 1 app / 20 modules / 10 roles - Grey/white box + targeted production validation 4 Web Application — CrimsonLogic - 1 app / 20 modules / 10 roles 5 API Security 50 endpoints base - Full OWASP API Top 10 + business logic 7 Configuration Review Agreed security components - Firewall/WAF/API/cloud/security configurations 8 AI/LLM - 1 app / 1 model / 5 interfaces / 1 RAG / 5 tools - Comprehensive OWASP-aligned LLM security 9 Agentic AI - 1 Excessive agency/tool/function security 10 Production - 1 controlled validation pass - Non-destructive 11 DR - 1 targeted validation During DR exercise 12 Remediation - 1 cycle / ≤10 C&H findings - Evidence-based retest 13 Reporting - 1 final report + executive report - Technical evidence + remediation
Project ID: 40685648
23 proposals
Open for bidding
Remote project
Active 1 day ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
23 freelancers are bidding on average ₹46,277 INR for this job

Hello, I can conduct a comprehensive grey-box Vulnerability Assessment & Penetration Testing (VAPT) engagement covering your infrastructure, web applications, APIs, configurations, and AI/LLM environment, with production testing carefully controlled and non-destructive. Scope & Approach • External VAPT: 4 public IPv4s with manual validation through WAF/security controls. • Internal VAPT: 10 segments / 250 live IPs with credentialed & non-credentialed testing. • Web Apps: Virtual Trust & CrimsonLogic 20 modules/10 roles each; authenticated testing, access control, session security, business logic & production validation. • API Security: 50 endpoints; OWASP API Top 10, authentication, authorization & business logic. • Configuration Review: Firewall, WAF, API, cloud & agreed security components. • AI/LLM: 1 model, 5 interfaces, RAG & 5 tools; OWASP-aligned security assessment. • Agentic AI: Excessive agency, tool/function permissions & authorization boundaries. • Production/DR: Controlled non-destructive validation and targeted DR exercise testing. • Remediation: One retest cycle for up to 10 Critical/High findings. • Reporting: Technical + executive reports with evidence, severity, impact, attack paths and remediation. Deliverables Evidence-based findings covering affected assets, validation/reproduction details, business impact, risk ratings and actionable remediation guidance. Regards, Kajal Majhi
₹225,000 INR in 7 days
5.6
5.6

We at Offensium Vault Private Limited (ISO 27001:2022 & ISO 9001:2015) can conduct a comprehensive grey-box VA/PT and security assessment across your external, internal, web, API, cloud, AI/LLM, and production environments. Scope & Approach • External VA/PT: 4 public IPv4s/region with manual validation of WAF/security controls • Internal VA/PT: 10 segments / 250 live IPs using credentialed & non-credentialed testing • Web Apps: Virtual Trust & CrimsonLogic — 20 modules, 10 roles; grey/white-box with controlled production validation • API Security: 50 endpoints covering OWASP API Top 10, authentication, authorization & business logic • Configuration Review: Firewall, WAF, API, cloud and agreed security components • AI/LLM: 1 app, model, 5 interfaces, RAG and 5 tools aligned with OWASP LLM guidance • Agentic AI: Excessive agency, tool/function abuse and authorization risks • Production & DR: Controlled, non-destructive validation • Retest: One evidence-based cycle for up to 10 Critical/High findings Deliverables Executive + detailed technical reports with PoCs, evidence, CVSS ratings, remediation guidance, and reproducible findings. Testing will prioritize safe validation with minimal production impact. We can work under NDA with your architecture diagrams, credentials and API documentation. Estimated timeline: 10–15 business days, subject to access and scheduling.
₹25,000 INR in 7 days
3.6
3.6

Hello, I am highly experienced in delivering comprehensive Vulnerability Assessment and Penetration Testing (VAPT) engagements across external and internal infrastructure, web applications, APIs, cloud/security configurations, and emerging AI/LLM and Agentic AI environments. I can perform this engagement as a controlled Grey Box assessment, leveraging the provided architecture diagrams, sample credentials, API documentation, application roles, and other authorized information to achieve deeper and more accurate validation while maintaining strict production-safety requirements. My approach covers manual validation beyond automated scanning, OWASP-aligned web and API testing, business-logic assessment, credentialed and non-credentialed internal testing, firewall/WAF/API/cloud configuration reviews, LLM/RAG/tool security, excessive-agency risks in agentic AI, controlled non-destructive production validation, and evidence-based remediation retesting. I will provide detailed technical findings with reproducible evidence, risk ratings, business impact, and practical remediation guidance, together with an executive-level report suitable for management and stakeholders. I am available to discuss the scope, methodology, rules of engagement, and testing windows, and I am ready to start immediately.
₹67,625 INR in 2 days
3.1
3.1

Hi, I can perform a comprehensive VAPT covering web applications, APIs, internal/external infrastructure, configurations, and AI/LLM security. I’ll combine manual testing with OWASP-aligned methodology to identify real-world vulnerabilities, business-logic issues, and security gaps. You’ll receive clear risk-rated findings, PoC evidence, remediation guidance, and a complete retest report. Ready to start immediately.
₹25,000 INR in 10 days
2.4
2.4

We provide detailed vulnerability assessment and technical review of existing security controls for all targeted systems and assets are provided with this service. in the assessment, our team will present a comprehensive vulnerability report, a logical network connection drawing, a complete cyber asset inventory and recommended mitigation actions. What you will get with this project? - Full assessment report with all vulnerability, recommendation, test cases and Observations in detail. - Kindly contact me to get sample report. Waiting for your reply for further discussion. Thanks & Regards, Keyur
₹33,750 INR in 7 days
0.6
0.6

Hi, this is a large scope — external + internal VAPT across 250 IPs, two full web app assessments, API security, AI/LLM and agentic AI testing, config review, and a remediation retest cycle. Delivering this properly, solo, in 7 days isn't realistic without cutting corners on manual validation, so I've proposed a timeline that lets me actually do the work right. Phased approach: Week 1: External VA/PT + Configuration review Week 2: Internal VA/PT (250 IPs) + both web app assessments Week 3: API security, AI/LLM + Agentic AI testing, production validation, remediation retest, final reporting On the open question: any endpoints found beyond the initial 50 should be flagged separately, not assumed in-scope. Background: CEH-certified, hands-on with Burp Suite, Nmap, and Nessus, with a completed freelance dashboard VAPT (OWASP Top 10, CVSS-scored, full report with PoC and remediation). Happy to walk through my approach on a call before you award.
₹35,000 INR in 15 days
0.2
0.2

Hi, New on Freelancer — 20 years of development experience behind us. We're taking our first few projects here at a fraction of our normal rate purely to build our review history. You get senior agency work at junior pricing; we get a review. Straight trade. Given the complexity of web application environments, potential API vulnerabilities are often overlooked but can be critical entry points. I'd start with a thorough examination of your API endpoints for any misconfigurations or outdated security protocols. Can you provide access details or any specific areas of concern?
₹25,000 INR in 7 days
0.0
0.0

Hi, I’m new to the Freelancer platform, but I have 2+ years of hands-on experience in cybersecurity and VAPT. I have worked on Web, API, Android and infrastructure security assessments, including manual testing, vulnerability validation, PoC development, risk assessment, and professional security reporting. I can handle the assessment end-to-end, from understanding the scope and attack surface to identifying and validating vulnerabilities, preparing detailed findings, remediation recommendations, and supporting revalidation. Although I’m new to Freelancer, I’m not new to this field. I would really appreciate the opportunity to work on this project and demonstrate the quality of my work. Looking forward to working with you.
₹25,000 INR in 10 days
0.0
0.0

We propose to conduct a comprehensive enterprise security assessment covering External and Internal VA/PT, Web Application and API Security, Configuration Review, AI/LLM and Agentic AI Security, controlled Production and DR validation, remediation retesting, and detailed technical and executive reporting. The assessment will follow industry best practices and relevant OWASP-aligned methodologies, with manual validation, business-logic testing, evidence-based findings, risk prioritization, and actionable remediation recommendations. The engagement is proposed to be completed within approximately 25 working days with a qualified security testing team.
₹210,000 INR in 25 days
0.0
0.0

I can deliver a comprehensive Grey-Box VA/PT covering external and internal infrastructure, web applications, 50 API endpoints, WAF/cloud configuration, LLM/RAG, Agentic AI, and controlled production validation. My approach combines automated discovery with deep manual testing, business-logic validation, OWASP-aligned methodology, evidence-based reporting, remediation guidance, and retesting while maintaining strict non-destructive production safety.
₹25,000 INR in 7 days
0.0
0.0

Hi, I’m interested in your Grey-Box VA/PT project. I can perform comprehensive manual security testing across infrastructure, web applications, APIs, cloud configurations, AI/LLM, agentic AI, production/DR validation, remediation retesting, and detailed technical reporting. I follow OWASP-aligned methodologies with strict, non-destructive testing practices.
₹25,000 INR in 7 days
0.0
0.0

# Web App Penetration Test — Proposal **Bryce Whitney | Offensive Security** **Overview:** I'm proposing a manual, offense-driven penetration test of your web application — not just automated scanning, but real exploitation of business logic and modern client-side attack chains that scanners miss. **Why Me:** Cross-sector background in offensive security and incident response gives me both an attacker's mindset and insight into how breaches actually unfold post-compromise. I don't just find vulnerabilities — I chain them into real attack paths and validate business impact. **Expertise:** - Client-side research: DOM XSS, CSPT/CSPT2CSRF chains, postMessage abuse, worker exploitation, CSP bypass - Manual web app testing with a full custom toolchain (recon, fuzzing, proxying) - Custom tooling built when off-the-shelf tools fall short - IR/forensics background informing realistic attacker modeling **Certifications:** GPEN, Bug Bounty Experience, Synack Red team member **Methodology:** Recon → Manual Discovery → Exploitation/Chaining → Reporting → Retest **Deliverables:** Executive summary, technical findings w/ PoCs & CVSS, remediation guidance, readout call Happy to discuss scope further.
₹20,000 INR in 5 days
0.0
0.0

Hello, I'm a security-focused PHP/Python developer experienced in identifying vulnerabilities and writing actionable security reports. I understand you need a grey-box VA/PT covering external and internal segments, two web applications, API security (OWASP API Top 10), and configuration review. I can perform manual validation alongside automated scanning, document findings with clear severity ratings and remediation steps, and align testing with your architecture diagrams and provided credentials. I'm available to start immediately and can adjust the timeline/scope to match your priorities. Happy to discuss the engagement details and provide a sample report structure before we begin.
₹25,000 INR in 7 days
0.0
0.0

Hello, I’m a cybersecurity professional with hands-on experience in penetration testing, application/API security, infrastructure assessments, security configuration reviews, and AI/LLM security. I can support this engagement across the full scope: external and internal VA/PT, grey/white-box web application testing, API security, configuration review, AI/LLM and agentic AI testing, controlled production/DR validation, remediation retesting, and technical/executive reporting. My approach combines automated discovery with extensive manual testing and exploitability validation. For web/API assessments, I focus on authentication, authorization, IDOR/BOLA, business logic, injection, privilege escalation, session security, and cross-role attack paths. For AI/LLM components, I can assess prompt injection, RAG security, data leakage, tool/function abuse, excessive agency, authorization boundaries, and OWASP-aligned LLM risks. Production testing will follow an agreed Rules of Engagement and use controlled, non-destructive validation. Findings will be manually verified with clear evidence, impact, severity, reproduction steps, and actionable remediation guidance. I’d be happy to discuss the scope, timeline, access requirements, deliverables, and testing methodology before commencement.
₹25,000 INR in 7 days
0.0
0.0

Hello, I am a Cybersecurity & Penetration Testing professional with hands-on experience in VAPT, Web Application Security, API Security, Network Security, vulnerability assessment, and manual security testing. I can conduct the proposed Grey Box VA/PT covering: • External & Internal Network VA/PT • Credentialed and non-credentialed testing • Web application security across modules and user roles • API Security assessment covering OWASP API Top 10 & business logic • WAF/security-control validation • Firewall, WAF, API, cloud and security configuration review • AI/LLM and Agentic AI security assessment aligned with OWASP guidance • Controlled, non-destructive production validation • DR security validation • Evidence-based remediation retesting • Detailed technical and executive reports with risk ratings, evidence, impact and remediation My methodology combines automated discovery with thorough manual validation to identify real vulnerabilities and minimize false positives. Since this involves production systems, I will strictly follow the agreed scope, Rules of Engagement and testing windows to avoid business disruption. I am available to discuss the architecture, credentials, API documentation and scope before commencing the engagement. Regards, Arsh Cybersecurity | VAPT | Web & API Security
₹20,000 INR in 7 days
0.0
0.0

I work as an application security engineer. Let me know if my profile looks good. Let’s discuss the scope of work and timelines and let’s get this rolling.
₹33,000 INR in 7 days
0.0
0.0

India, India
Payment method verified
Member since Nov 24, 2025
₹12500-37500 INR
₹75000-150000 INR
₹12500-37500 INR
₹75000-150000 INR
₹150000-250000 INR
$15-25 USD / hour
₹12500-37500 INR
₹1500-12500 INR
₹600-1500 INR
$10-30 USD
₹600-1500 INR
₹100-400 INR / hour
$750-1500 USD
₹37500-75000 INR
$30-250 USD
£20-250 GBP
₹12500-37500 INR
$30-250 USD
$30-250 USD
₹12500-37500 INR
₹600-1500 INR
$250-750 USD
₹750-1250 INR / hour
₹1500-12500 INR
$250-750 USD