SAMPLE CLIENT DELIVERABLE

Web Penetration Test Report

This demonstrates how SecAgent can present validated findings, evidence, business impact, prioritized remediation, and retest status after an authorized engagement.

DemoCorp Web Portal

Engagement ID: SA-DEMO-2026-0914

AssessmentAuthorized Multi-Agent Web Pentest
Report dateOctober 2, 2026
Overall riskModerate
Retest statusCompleted
Pre-test score42/100
Post-remediation86/100
Validated findings7
Verified closed5

Executive summary

SecAgent identified several security weaknesses affecting browser-side controls, administrative access exposure, and session protection. No destructive testing or denial-of-service activity was performed. The highest-priority items were remediated and verified during retesting. Two lower-priority hardening items remain open.

Scope & methodology

Illustrative authorized scope: portal.democorp.example and its documented API. Testing included attack-surface mapping, authentication/session review, access-control checks, API review, configuration analysis, controlled input testing, evidence validation, risk correlation, remediation guidance, and retest verification.

Findings register

IDFindingSeverityStatusOwner
SA-001Administrative interface exposed without network restrictionCriticalVerified ClosedPlatform
SA-002Session cookie missing SameSite protectionHighVerified ClosedApplication
SA-003Content Security Policy not enforcedHighVerified ClosedFrontend
SA-004Verbose server banner disclosureMediumOpenInfrastructure
SA-001

Administrative interface exposed without network restriction

Critical

An administrative route was reachable from the public internet. While authentication was present, unrestricted exposure increased attack surface and the likelihood of credential-focused attacks.

Affected assetadmin.democorp.example
Business impactPrivileged access exposure
ConfidenceValidated
RetestVerified Closed

Evidence summary

HTTP 200 observed on authorized administrative route from external test origin. Authentication challenge confirmed. No credentials were bypassed or brute-forced.
Recommendation
Restrict administrative access using a trusted access proxy, VPN, IP allowlist, or identity-aware gateway. Enforce MFA and centralized audit logging. During retest, confirm the administrative route is no longer reachable from an untrusted network.
SA-002

Session cookie missing SameSite protection

High

The primary authenticated session cookie did not include an explicit SameSite attribute, reducing browser-level cross-site request protections.

Affected assetportal.democorp.example
Business impactSession abuse risk
ConfidenceValidated
RetestVerified Closed
Recommendation
Set session cookies to Secure, HttpOnly, and an appropriate SameSite policy. Re-evaluate cross-site workflows before selecting Strict or Lax. Retest authenticated workflows after deployment.
SA-004

Verbose server banner disclosure

Medium

HTTP response metadata disclosed unnecessary platform/version information that could aid targeted reconnaissance.

Affected assetportal.democorp.example
Business impactReconnaissance assistance
ConfidenceValidated
RetestOpen
Recommendation
Suppress unnecessary server/version headers at the application server or reverse proxy. Confirm operational monitoring does not depend on public disclosure of version strings.

Prioritized remediation plan

PriorityAction
P0Restrict administrative access and verify MFA
P1Strengthen session cookie policy
P1Deploy and test Content Security Policy
P2Reduce server information disclosure

Retest conclusion

Five findings were verified closed during the illustrative retest. Two lower-priority items remain open. The client should treat the report as a point-in-time assessment and continue secure change management, dependency updates, logging, access reviews, and periodic retesting.

Recommended disposition: close remediated items, assign owners and target dates to remaining findings, and schedule targeted verification after fixes.