GGSec Cortex · Sample Reports

See Cortex in action

Real reports from GGSec Cortex against deliberately-vulnerable test applications. Same layout you get on your own scan — executive summary, evidence-graded findings, reproducible proof-of-concept, risk matrix, remediation plan and compliance mapping.

Evidence-Graded

Confirmed / Likely

Compliance Mapped

OWASP · PCI · ISO · GDPR

Coverage

Web · API · GraphQL · AI

Formats

HTML + PDF
Sample reports

Real scans, every angle

Each report is the unmodified output of a real Cortex run — open the HTML to explore it interactively, or download the PDF.

🚩
Flagship

Full-surface web assessment

The complete engine on a broad attack surface: SQL injection, reflected & stored XSS, JWT attacks, IDOR, NoSQL & LDAP injection, blind XXE and SSRF, PHP object injection, type-juggling auth bypass, path traversal and open redirect — plus known-CVE / dependency scanning and hard-coded-secret detection. 42 findings confirmed with hard evidence, showing the certainty-adjusted scoring end to end.

SQLiXSSJWTIDORNoSQLLDAPXXESSRFDeserializationType JugglingPath TraversalSCA/CVESecrets
🔬

Application deep-dive

A single PHP application, examined in depth: reflected & stored XSS, SQL injection, LDAP injection, server-side template injection, path traversal, file-upload → RCE and prototype pollution — each finding backed by a reproducible proof-of-concept and mapped to MITRE ATT&CK.

XSS (stored)SQLiLDAPSSTIPath TraversalFile Upload RCEPrototype Pollution
💉

Advanced-injection spotlight

A focused look at the kind of flaw pattern-only scanners miss: Server-Side Template Injection (second-order, store → render) and NoSQL injection. The AI follows the data flow; the dynamic engine proves execution — cleanly scored, low noise.

SSTI (2nd-order)NoSQLXSSXXESSRF
📡
Blind = proven

Out-of-band (blind) confirmation

Vulnerabilities with zero visible response, proven anyway. The built-in collaborator captures the callback the target makes back to us: blind SSRF and a blind PHP object-injection → RCE gadget (deserialize → __destruct → outbound request) — each confirmed by an out-of-band HTTP callback, not guesswork.

Blind SSRFObject Injection → RCEOOB HTTP CallbackZero in-band signal
🧬
Native engine

HTTP request-smuggling / desync

The high-end module in action: a native raw-socket engine confirms a front-end/back-end desync by timing-differentialCL.TE and TE.CL proven (evidence strength High, 92/100), with a repeatability gate and 5/5 negative controls clean so it isn’t a fluke. This is the class pattern-only scanners can’t touch.

CL.TETE.CLCWE-444Timing-differentialNeg-controls 5/5Repeatability gate
🤖
AI-native · new

AI chatbot prompt injection

The class almost no scanner tests: prompt injection (OWASP LLM01 / CWE-1427). Cortex found — and proved — that a live DeepSeek-backed chatbot would obey attacker instructions (unauthenticated, CVSS 9.1). We hardened it in one file and re-scanned: clean. Vendor notified under responsible disclosure. An AI scanner that audits AI apps.

Prompt InjectionOWASP LLM01CWE-1427Canary proofFound → Fixed
🕸️
API · GraphQL · new

Modern API, GraphQL & AI assessment

The modern-stack attack surface classic scanners never reach, in one pass. GraphQL (introspection leak, alias-amplification & depth-bomb DoS, resolver-level BFLA, SQLi via a string-interpolated argument), JWT RS256 → HS256 algorithm confusion forged from the published public key, mass assignment, broken function-level authorization, web cache deception, session fixation, unbounded-export DoS, NoSQL auth-bypass and both direct and indirect (RAG) prompt injection. 17 findings confirmed, zero false positives — and the report’s Exploitation Paths graph chains them into a full unauthenticated → admin takeover route.

GraphQLAPI Top 10JWT alg-confusionMass AssignmentBFLAWeb Cache DeceptionSession FixationResource ExhaustionIndirect Prompt InjectionAttack Paths
🧮
Business logic · access · new

Business-logic & access-control deep-dive

The detection classes that need reasoning, not signatures. A business-logic invariant break (negative-quantity & over-100% discount price tampering, CWE-840); HTTP parameter pollution type-confusion (CWE-235); mass assignment proven by a read-back oracle — role escalated user → admin then restored (CWE-915); spoofable X-Forwarded-For trust granting internal access (CWE-807); a dedicated CSRF root-cause split from mass-assignment; and stored-XSS store → render. The Exploitation-Paths graph chains them into a session-fixation → IDOR → mass-assignment → admin takeover route. A companion SAST source-audit surfaces plaintext password storage (CWE-256) and hard-coded credentials (CWE-798), reported as Potential (verify) — findings a runtime-only scanner never sees.

Business LogicHPP / Type ConfusionMass AssignmentProxy-Header TrustCSRFStored XSSIDOR ChainPlaintext PasswordsHard-coded SecretsAttack Paths
🎯

See this on your own application

These reports are from deliberately-vulnerable test applications. Point GGSec Cortex at your own environment and get the same client-ready output — evidence-graded findings, a prioritised fix plan and compliance mapping.

Request a Pilot Scan

Reports were generated against intentionally-vulnerable test applications. For authorised security testing only. · GG Advanced IT Security — ggsec.de