Loading...
Loading...
Used for authorized security testing of desktop thick clients, covering local storage, update channels, IPC, traffic, and client-side trust boundaries.
npx skill4agent add zhaoxuya520/reverse-skill thick-clientNOW../field-journal/precedent-pentest.mdNOWNOWNEXTACT□ Process tree, child processes, drivers/services
□ Listening ports and outbound domains
□ Local sensitive paths: %APPDATA%, Keychain, Registry□ Plaintext configuration, hardcoded keys, debug switches
□ DLL hijacking/search order (Windows)
□ Database file (SQLite) permissions and encryption
□ IPC: Who can connect? Is authentication required?□ System proxy / application-specific TLS
□ Certificate pinning → Combine with mobile/js methodologies or Frida
□ API privilege escalation: Hidden admin interfaces on the client side□ .NET → dotnet-reverse; Native → ida/ghidra; Electron → asar + js-reverse| Tool | Purpose |
|---|---|
| Process Monitor / API Monitor | Behavior monitoring |
| Burp / mitmproxy | Traffic analysis |
| dnSpy / IDA / Ghidra | Reverse engineering |
| Sysinternals | Windows platform analysis |
| asar / nexe detection | Electron client analysis |
references/thick-client-checklist.md../dotnet-reverse/../ida-reverse/../js-reverse/../api-security/protocol-reversesupply-chain-security