Skip to content
winfunc
Penetration testing

Code-informed penetration testing.

Extend every engagement with full codebase context: mapped attack surface, traced data flows, and reproducible proof. Keep coverage going after the report is delivered.

What's included
  1. acme
  2. /billing-api
  3. /Pentest
  4. /Run 318
Exploitable
Validator1m 42s
  1. Started isolated environment14:02:08
    sandbox · billing-api@4f2c1e9
  2. Read file14:02:11
    read_file · services/invoices.ts
  3. Seeded two tenants14:02:25
    tenant_a · tenant_b
  4. Requested tenant B's invoice as tenant A14:02:31
    GET /invoices/inv_b_0192
  5. Response contained tenant B data14:02:32
    200 · tenant: tenant_b
  6. Verdict recorded14:02:33
    exploitable · evidence attached
Proof of conceptHarmless
$ curl -s -H "Authorization: Bearer $TENANT_A" \
    https://sandbox.local/invoices/inv_b_0192

HTTP/1.1 200 OK
{ "id": "inv_b_0192", "tenant": "tenant_b" }
Environment
isolated · no egress
Impact
Read another tenant's invoice
Re-run
Queued after the patch merges
Pentest · validation runIllustrative data
The problem

A pentest is a snapshot. Your code keeps moving.

Human testers bring judgment to a fixed scope and window. winfunc adds the source code: every entry point, every path, every business rule. It keeps investigating as the code changes, so coverage doesn't end when the engagement does.

Included

What winfunc covers.

  • Source-to-sink investigation within an agreed codebase scope
  • Reproduction steps or proof-of-concept where testing is in scope
  • Business-logic hypotheses across authorization and sensitive flows
  • Race-condition and TOCTOU investigation
  • Severity tied to prerequisites and evidence
  • Continuous code review between point-in-time assessments
  • Suggested remediation opened as pull requests
Outcomes

What your team walks away with.

01

Beyond pattern matching

winfunc reasons about business rules, permission models, and state across related code paths, and preserves its assumptions.

02

Reproducible proof

Findings include reproduction steps or a scoped proof-of-concept whenever a suitable environment is available.

03

Coverage between tests

Scheduled and pull-request reviews keep investigating as the code changes between annual assessments.

04

A partner for testers

Services firms use winfunc to map attack surface faster and spend human time where judgment matters most.

Start with one repository

Bring us your hardest codebase.
We'll bring the proof.

Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.

Scoped with you. Delivered with evidence.