Testing Thick Clients

Security-test desktop thick-client applications (.NET/WPF, Java, Electron, native Win32) against their local and network attack surface — proxying non-HTTP traffic, extracting secrets and DB connection strings from config/registry/memory, bypassing client-side trust controls, and reviewing update channels and DLL search order. Use when assessing an installed desktop app that talks to a backend, when Burp sees no traffic from a fat client, or when a two-tier app connects straight to a database.

trilwu 28c233a 7.5 KB Updated

File contents

trilwu/secskills/tree/main/secskills-offense/skills/testing-thick-clients commit 28c233a1be

Frequently asked questions

npx skillmds@latest add trilwu/testing-thick-clients