performing-thick-client-application-penetration-test skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. Conduct a thick client application penetration test to identify insecure Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/performing-thick-client-application-penetration-test/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-thick-client-application-penetration-test, or copy the skill folder into ~/.claude/skills/performing-thick-client-application-penetration-test/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/performing-thick-client-application-penetration-test/SKILL.md

SKILL.md (verbatim)

name: performing-thick-client-application-penetration-test
description: Conduct a thick client application penetration test to identify insecure
  local storage, hardcoded credentials, DLL hijacking, memory manipulation, and insecure
  API communication in desktop applications using dnSpy, Procmon, and Burp Suite.
domain: cybersecurity
subdomain: penetration-testing
tags:
- thick-client
- desktop-application
- dnSpy
- Procmon
- DLL-hijacking
- binary-analysis
- API-interception
version: '1.0'
author: mahipal
license: Apache-2.0
nist_ai_rmf:
- MEASURE-2.7
- MAP-5.1
- MANAGE-2.4
atlas_techniques:
- AML.T0070
- AML.T0066
- AML.T0082
nist_csf:
- ID.RA-01
- ID.RA-06
- GV.OV-02
- DE.AE-07
mitre_attack:
- T1595
- T1190
- T1059
- T1078
- T1003

Performing Thick Client Application Penetration Test

Overview

Thick client (fat client) penetration testing assesses the security of desktop applications that run locally on user machines and communicate with backend servers. Unlike web applications, thick clients present a broader attack surface including local file storage, binary analysis, memory manipulation, DLL injection, process interception, and client-server communication. Common targets include banking applications, ERP clients (SAP GUI), trading platforms, healthcare systems, and legacy enterprise software.

When to Use

  • When conducting security assessments that involve performing thick client application penetration test
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing

Prerequisites

  • Application installer and valid credentials
  • Windows/Linux test machine (isolated)
  • Tools: dnSpy, Procmon, Process Hacker, Wireshark, Burp Suite, Echo Mirage, Fiddler, IDA Pro/Ghidra
  • Administrative access to test machine

Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.

Phase 1 — Information Gathering

Static Analysis

# Identify application technology
# Check file properties, signatures, framework (.NET, Java, C++, Electron)
file application.exe
# .NET -> dnSpy, JetBrains dotPeek
# Java -> JD-GUI, JADX
# C/C++ -> Ghidra, IDA Pro
# Electron -> extract asar archive

# Check for .NET framework
Get-ChildItem -Path "C:\Program Files\TargetApp" -Recurse -Filter "*.dll" |
  ForEach-Object { [System.Reflection.AssemblyName]::GetAssemblyName($_.FullName).FullName }

# Strings analysis
strings application.exe | findstr -i "password\|secret\|api\|key\|token\|jdbc\|connection"

# Check for hardcoded credentials
strings application.exe | findstr -i "username\|user=\|pass=\|pwd=\|admin"

# Review configuration files
type "C:\Program Files\TargetApp\app.config"
type "C:\Program Files\TargetApp\settings.xml"
type "%APPDATA%\TargetApp\config.json"

# Check for certificate pinning
strings application.exe | findstr -i "cert\|pin\|ssl\|tls"

.NET Decompilation with dnSpy

# Open application in dnSpy
1. Launch dnSpy
2. File > Open > Select application.exe and DLLs
3. Search for:
   - "password", "secret", "connectionString"
   - Authentication methods
   - Encryption/decryption functions
   - API endpoints and keys
   - License validation logic

# Look for:
- Hardcoded credentials in source
- Insecure encryption (DES, MD5, base64 "encryption")
- SQL queries (potential injection)
- Disabled certificate validation
- Debug/verbose logging with sensitive data

Phase 2 — Dynamic Analysis

Process Monitoring

# Monitor file system activity with Procmon
# Filters:
#   Process Name = application.exe
#   Operation = CreateFile, WriteFile, ReadFile, RegSetValue

# Key observations:
# - Where does the app store data? (AppData, temp, registry)
# - Does it write credentials to disk?
# - Does it create temporary files with sensitive data?
# - What registry keys does it access?

# Monitor with Process Hacker
# Check: loaded DLLs, network connections, handles, tokens

# Monitor network traffic
# Wireshark filter: ip.addr == <server_ip>
# Check for: unencrypted credentials, API keys, tokens

Traffic Interception

# Intercept HTTP/HTTPS traffic with Burp Suite
# Configure system proxy: 127.0.0.1:8080
# Install Burp CA certificate in Windows certificate store

# For non-HTTP protocols, use Echo Mirage
# Inject into process and intercept TCP/UDP traffic

# For HTTPS with certificate pinning:
# Method 1: Patch certificate validation in dnSpy
# Method 2: Use Frida to hook SSL validation
frida -l bypass_ssl_pinning.js -f application.exe

# Fiddler for .NET applications
# Enable HTTPS decryption
# Monitor API calls, request/response bodies

Phase 3 — Vulnerability Testing

Authentication Bypass

# Test local authentication bypass
1. Open dnSpy, find authentication method
2. Set breakpoint on credential validation
3. Modify return value to bypass (Debug > Set Next Statement)
4. Or: Patch binary to always return true

# Test for credential storage
# Check: registry, config files, SQLite databases, Windows Credential Manager
reg query "HKCU\Software\TargetApp" /s
type "%APPDATA%\TargetApp\user.db"
# SQLite: sqlite3 user.db ".dump"

DLL Hijacking

# Identify DLL search order vulnerability
# Use Procmon to find DLLs loaded from writable paths
# Filter: Result = NAME NOT FOUND, Path ends with .dll

# Create malicious DLL
# msfvenom -p windows/exec CMD=calc.exe -f dll -o hijacked.dll
# Place in application directory or writable PATH directory

# DLL sideloading
# If app loads DLL without full path:
# 1. Create DLL with same exports
# 2. Place in app directory
# 3. DLL loads before legitimate version

Memory Analysis

# Dump process memory
# Use Process Hacker > Process > Properties > Memory
# Search for plaintext credentials, tokens, session IDs

# Strings from memory dump
strings process_dump.dmp | findstr -i "password\|token\|session\|bearer"

# Modify memory values (license bypass, privilege escalation)
# Use Cheat Engine or x64dbg to:
# 1. Find memory address of authorization variable
# 2. Modify value (e.g., isAdmin = 0 -> isAdmin = 1)

Input Validation

# SQL Injection in local database
# Test input fields with: ' OR 1=1--
# If app uses local SQLite/SQL Server Express

# Command injection
# Test fields that interact with OS:
# File paths: ..\..\..\..\windows\system32\cmd.exe
# Print/export: | calc.exe

# Buffer overflow
# Send oversized input to text fields
# Monitor with x64dbg for crashes
# Check for SEH-based or stack-based overflows

Phase 4 — API Security Testing

# Capture API calls from thick client
# In Burp Suite, analyze:

# IDOR (Insecure Direct Object Reference)
# Change user IDs in requests to access other users' data
# GET /api/users/1001 -> GET /api/users/1002

# Authorization bypass
# Remove or modify JWT tokens
# Test role escalation: change role claim from "user" to "admin"

# Mass assignment
# Add additional parameters to API requests
# POST /api/profile {"name": "test", "isAdmin": true}

# Rate limiting
# Test for brute-force protection on login API
# Test for account lockout bypass

Findings Template

Finding Severity CVSS Remediation
Hardcoded database credentials in binary Critical 9.1 Use secure credential storage (DPAPI, vault)
DLL hijacking via writable app directory High 7.8 Use full DLL paths, validate DLL signatures
Plaintext credentials in memory High 7.5 Zero memory after use, use SecureString
No certificate pinning Medium 6.5 Implement certificate pinning
Local SQLite DB with cleartext passwords Critical 9.0 Use bcrypt/Argon2 hashing
Disabled SSL validation in code High 8.1 Enable proper certificate validation

References

Other files in this skill

assets/template.md (verbatim)

Thick Client Penetration Test — Report Template

Document Control

Field Value
Application [Name and version]
Technology [.NET / Java / C++ / Electron]
Platform [Windows / macOS / Linux]
Period [Start] — [End]

Executive Summary

[Overview of thick client security posture, key vulnerabilities found in binary, storage, and communication]

Findings

Finding [N]: [Title]

Attribute Detail
Category [Binary / Storage / Communication / Authentication]
Severity [Level]
CVSS [Score]
Remediation [Fix]

Recommendations

  1. [Priority recommendations for thick client hardening]

references/api-reference.md (verbatim)

API Reference: Thick Client Penetration Testing

Analysis Tools

Tool Purpose Target
dnSpy .NET decompilation and debugging .NET Framework/Core apps
ILSpy .NET decompilation (read-only) .NET assemblies
JD-GUI / JADX Java decompilation JAR/APK files
Ghidra / IDA Pro Native binary reverse engineering C/C++ executables
Procmon File/registry/network activity monitoring Any Windows app
Process Hacker Process inspection, memory, DLLs Running processes
Burp Suite HTTP/HTTPS traffic interception Client-server communication
Echo Mirage TCP/UDP traffic interception Non-HTTP protocols
Frida Dynamic instrumentation Any platform

Static Analysis Targets

Target Search Pattern Risk
Hardcoded credentials password, secret, apikey in strings Critical
Connection strings jdbc:, Server=, mongodb:// Critical
SQL queries SELECT, INSERT, UPDATE Medium
URLs and endpoints http://, https:// Info
Disabled SSL validation ServerCertificateValidationCallback High

DLL Hijacking Detection

Step Tool Action
1 Procmon Filter: Result = NAME NOT FOUND, Path ends with .dll
2 Check Verify if DLL search path includes writable directories
3 Validate Test with benign DLL in writable directory

Local Storage Locations

Location Type Risk
%APPDATA%\<app> Config, SQLite Credential storage
%LOCALAPPDATA%\<app> Cache, logs Data leakage
HKCU\Software\<app> Registry settings Stored credentials
App install directory Config files Hardcoded secrets

Python Libraries

Library Version Purpose
sqlite3 stdlib Audit local SQLite databases
re stdlib Pattern matching for credentials/URLs
subprocess stdlib Execute system analysis tools
pathlib stdlib File system traversal

References

references/standards.md (verbatim)

Standards — Thick Client Application Penetration Testing

Frameworks

OWASP Thick Client Top 10

  1. Improper Platform Usage
  2. Insecure Data Storage
  3. Insecure Communication
  4. Insecure Authentication
  5. Insufficient Cryptography
  6. Insecure Authorization
  7. Client Code Quality
  8. Code Tampering
  9. Reverse Engineering
  10. Extraneous Functionality

references/workflows.md (verbatim)

Workflows — Thick Client Penetration Testing

Attack Flow

Application Binary
    │
    ├── Static Analysis (dnSpy/Ghidra/JD-GUI)
    │   ├── Hardcoded credentials
    │   ├── Encryption analysis
    │   └── API endpoint discovery
    │
    ├── Dynamic Analysis (Procmon/Process Hacker)
    │   ├── File system monitoring
    │   ├── Registry access tracking
    │   └── Memory inspection
    │
    ├── Traffic Interception (Burp/Fiddler/Echo Mirage)
    │   ├── API security testing
    │   ├── Certificate pinning bypass
    │   └── Authentication token analysis
    │
    └── Binary Exploitation
        ├── DLL hijacking
        ├── Memory manipulation
        └── Binary patching

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.