ภาพประกอบสไตล์ญี่ปุ่นของแฮกเกอร์แมวดำวัยหนุ่มกำลังทดสอบระบบด้วย MacBook Pro ที่ติดสติกเกอร์โลโก้ Siam Thanat Hack ทางการ

Human-Led AI-Augmented

เจาะระบบอย่างมืออาชีพ ด้วยพลังของคนและ AI

บริการการทดสอบเจาะระบบ (Pentest) สำหรับ Web, Mobile, API และ Network พร้อมหลักฐานที่ตรวจสอบได้และคำแนะนำแก้ไขที่นำไปใช้ได้จริง

ใบรับรองมาตรฐานของ Siam Thanat Hack

CREST Pathway Plus
ขอใบเสนอราคา Pentest ดูบริการของเรา
เลื่อนลงเพื่อดูเพิ่มเติม

OFFENSIVE SECURITY / 01

บริการของเรา

มองหาช่องโหว่ที่โจมตีได้จริงพร้อมหลักฐานและวิธีแก้ที่นำไปใช้ต่อได้

01 / WEB APPLICATION

เจาะลึกกว่ารายการ OWASP Top 10

ทดสอบเว็บเพื่อหาช่องโหว่ที่โจมตีได้จริง รวมถึง business logic ที่เครื่องสแกนมองไม่เห็น

ขอบเขตที่ครอบคลุม

  • OWASP Top 10 และ OWASP ASVS
  • Authentication, session และ authorization
  • IDOR, injection, SSRF และ business logic

สิ่งที่คุณจะได้รับ

รายงานสรุปผู้บริหารและรายงานเทคนิค พร้อมหลักฐาน วิธี reproduce ผลกระทบ วิธีแก้ และ retest ตาม scope

02 / MOBILE APPLICATION

เห็นทั้งแอป มือถือ และ backend ที่เชื่อมต่อกัน

ทดสอบทั้งฝั่งแอปและ backend/API ตามกรอบ OWASP Mobile Top 10 เพื่อหาช่องโหว่ที่โจมตีได้จริง

ขอบเขตที่ครอบคลุม

  • การจัดเก็บข้อมูลบนเครื่องและการเข้ารหัส
  • TLS, certificate pinning และ session/token
  • Reverse engineering, tampering และ business logic

สิ่งที่คุณจะได้รับ

รายงานพร้อมคำแนะนำทั้งฝั่งแอปและ backend สรุปผล และ retest ตามขอบเขตที่ตกลง

03 / API PENETRATION TESTING

ทดสอบทีละ endpoint และต่อ attack chain

หาช่องโหว่ด้าน authentication, authorization, rate limiting และ data exposure ใน REST และ GraphQL API

ขอบเขตที่ครอบคลุม

  • REST, GraphQL และ token/session
  • BOLA / IDOR, rate limit และ abuse
  • Mass assignment, data exposure และ business logic

สิ่งที่คุณจะได้รับ

รายงานระดับ endpoint พร้อมหลักฐาน วิธี reproduce ผลกระทบ และคำแนะนำที่ทีมพัฒนานำไปใช้ต่อได้

04 / NETWORK

ยืนยันเส้นทางโจมตีจาก perimeter ถึงระบบสำคัญ

ทดสอบเครือข่ายภายนอกและภายในตาม scope และ Rules of Engagement ที่ตกลงร่วมกัน

ขอบเขตที่ครอบคลุม

  • Internet-facing services และ VPN gateway
  • Internal network, lateral movement และ Active Directory
  • Misconfiguration, privilege escalation และ segmentation

สิ่งที่คุณจะได้รับ

รายงานสรุปผู้บริหารและรายงานเทคนิค พร้อมหลักฐานสนับสนุน network segmentation และ retest ตาม scope

05 / SECURE CODE REVIEW

อ่าน logic ที่ black-box และ scanner เข้าไม่ถึง

วิเคราะห์ซอร์สโค้ดด้วยมือเพื่อหาช่องโหว่และ logic flaw พร้อม remediation ที่ใช้ได้จริง

ขอบเขตที่ครอบคลุม

  • Authentication และ authorization ในระดับโค้ด
  • Input validation, injection และ deserialization
  • Secret, encryption, dependency และ framework configuration

สิ่งที่คุณจะได้รับ

รายงานระบุตำแหน่ง file/line ผลกระทบ วิธีแก้ และคำแนะนำเชิง architecture เมื่อจำเป็น

06 / VULNERABILITY RESEARCH

ลงลึกถึง binary, protocol และ exploitability

งานวิจัยสำหรับ binary, protocol หรือ codebase ที่ต้องการมากกว่าการทดสอบตาม checklist ทั่วไป

ขอบเขตที่ครอบคลุม

  • วิเคราะห์ binary, protocol หรือ codebase เฉพาะทาง
  • Fuzzing, reverse engineering และ proof-of-concept
  • ประเมินผลกระทบและจัดทำ advisory

สิ่งที่คุณจะได้รับ

รายงาน advisory พร้อม proof-of-concept การจัดลำดับความเสี่ยง ผลกระทบ และแนวทาง mitigation

มนุษย์กำหนดขอบเขตและยืนยันทุก finding ส่วน AI ทำการทดสอบเชิงรุกอัตโนมัติภายใน Scope ที่ได้รับอนุญาต เพื่อเพิ่มความเร็ว ความครอบคลุม และประสิทธิภาพในการจำลองเทคนิคที่ผู้โจมตีจริงอาจใช้

ASSESSMENT GUIDE

VA Scan, Pentest และ Red Team ต่างกันอย่างไร

ทั้งสามรูปแบบตอบคำถามต่างกัน เลือกจากเป้าหมาย ขอบเขต และหลักฐานที่ต้องการ ไม่ใช่ใช้แทนกันโดยอัตโนมัติ

แผนภาพเปรียบเทียบ VA Scan, Pentest และ Red Team โดยมีแมวผู้เชี่ยวชาญและหุ่นยนต์ AI ประกอบแต่ละรูปแบบ

01 / VA SCAN

VA Scan / Vulnerability Assessment / สแกนช่องโหว่

ค้นหาช่องโหว่ในขอบเขตกว้างและช่วยจัดลำดับความสำคัญ การทำ VA ด้วยเครื่องสแกนเพียงอย่างเดียวไม่ทดแทน Pentest

ควรเลือกเมื่อ: ต้องการตรวจสอบเบื้องต้นใน Network ขนาดใหญ่ มองภาพรวมช่องโหว่จำนวนมาก และวางแผนตรวจสอบเชิงลึกต่อ

02 / PENTEST

Pentest / ทดสอบเจาะระบบ

ผู้เชี่ยวชาญทดสอบด้วยมือและยืนยัน exploitability กับผลกระทบภายใน Scope ที่ตกลงร่วมกัน

ควรเลือกเมื่อ: ต้องการหลักฐานว่าช่องโหว่โจมตีได้จริงและแนวทางแก้สำหรับแอปพลิเคชัน Web และ Mobile ที่สำคัญ

03 / RED TEAM

Red Team

จำลองสถานการณ์ตามวัตถุประสงค์และภัยคุกคาม ภายใต้ Scope และ Rules of Engagement ที่ชัดเจน เพื่อประเมินเป้าหมายด้านการป้องกัน การตรวจจับ และการตอบสนอง

ควรเลือกเมื่อ: องค์กรทำ VA และ Pentest อย่างสม่ำเสมอแล้ว และต้องการทดสอบความพร้อมของคน กระบวนการ และเทคโนโลยีต่อสถานการณ์ที่กำหนด

เลื่อนตารางในแนวนอนเพื่อดูทุกคอลัมน์ Scroll horizontally to view every column

มิติการประเมิน VA Scan Pentest Red Team
Image ความครอบคลุม
* มุ่งเป้าไปที่เป้าหมายที่ระบุไว้ในการทดสอบ เช่นการยึด Domain Controller หรือการฝัง Backdoor โดยหลบการตรวจจับโดย SOC ซึ่งไม่ได้ต้องการหาช่องโหว่ให้ได้มากที่สุด
Image หลักฐานการโจมตีได้จริง
* ยกเว้นช่องโหว่ที่กระทบความต่อเนื่องทางธุรกิจ
Image การจำลองสถานการณ์จริง
* เน้นทดสอบในระบบ Non-Production เพื่อลดผลกระทบ
* เน้นทดสอบกระบวนการ Detection กับ Response

อ่านบทความ: การทำ Pentest ต่างกับ VA อย่างไร

ABOUT STH / 02

เกี่ยวกับ

STH คือทีม White Hat สัญชาติไทยในกรุงเทพฯ ที่ผสานความเชี่ยวชาญเชิงลึก วินัยการทำงาน และการสื่อสารที่ตรวจสอบได้

บริษัทจดทะเบียนเมื่อ 11 ธันวาคม 2561 และดำเนินงานจากกรุงเทพฯ

01

จุดเริ่มต้นจากชุมชน

STH เติบโตจากการแบ่งปันความรู้ ทีมผู้ก่อตั้งคืออดีตผู้ดูแลเฟซบุ๊กเพจ สอนแฮกเว็บแบบแมว ๆ และต่อยอดสู่การแข่งขัน CTF การสร้างโจทย์ การวิจัยช่องโหว่ และงานที่ปรึกษาเชิงเทคนิคระดับความยากสูง

02

ประสบการณ์กับระบบสำคัญ

ผู้เชี่ยวชาญในทีมเคยทำงานกับระบบสำคัญของธนาคาร ระบบรับชำระเงิน และองค์กรชั้นนำ โดยยึดขอบเขตที่ได้รับอนุญาต Scope และ Rules of Engagement อย่างเคร่งครัด เราไม่รับการเข้าถึงโดยไม่ได้รับอนุญาต การแฮกบัญชี หรือการกู้คืนบัญชี

03

Human-Led, AI-Augmented

มนุษย์กำหนดขอบเขตและยืนยันทุก finding ส่วน AI ทำการทดสอบเชิงรุกอัตโนมัติภายใน Scope ที่ได้รับอนุญาต เพื่อเพิ่มความเร็ว ความครอบคลุม และประสิทธิภาพในการจำลองเทคนิคที่ผู้โจมตีจริงอาจใช้

เราใช้ AI ทำ reconnaissance และทดสอบโจมตีอัตโนมัติภายใน Scope ที่ได้รับอนุญาต เพื่อสำรวจ attack surface สร้างและทดสอบสมมติฐานได้รวดเร็วขึ้น ส่วนผู้เชี่ยวชาญกำหนดขอบเขต ควบคุมการทดสอบ ทำซ้ำ finding ประเมินผลกระทบ และอนุมัติรายงานฉบับสุดท้าย

ใบรับรองวิชาชีพที่มีอยู่ในทีม

  • Image
  • Image
  • Image
  • Image
  • Image
  • Image
  • Image
  • Image
  • Image
  • Image
  • Image
  • Image

HUMAN-LED × AI-AUGMENTED / 03

เราทดสอบระบบของคุณ ตั้งแต่ต้นจนจบกระบวนการ

ผู้เชี่ยวชาญกำหนดขอบเขต ควบคุมการทดสอบ และยืนยันผล ส่วน AI ทำการทดสอบเชิงรุกอัตโนมัติภายใน Scope เพื่อเพิ่มความเร็วและความครอบคลุม

ภาพอธิบาย Human Pentester ระบบเป้าหมายบนโทรศัพท์และคอมพิวเตอร์ และ AI Agent รูปแมวหุ่นยนต์

Human owns the decision

ผู้เชี่ยวชาญเป็นผู้นำตั้งแต่ scope ถึง sign-off

  • กำหนด Scope, Rules of Engagement และ test window
  • ทำ threat modeling และหา abuse case ที่ scanner มองไม่เห็น
  • เจาะระบบและประกอบ attack chain ด้วยมือ
  • ประเมินผลกระทบ ความเสี่ยง และวิธีแก้ก่อนออกรายงาน

Evidence from the real surface

ทดสอบกับพฤติกรรมจริงของระบบ ไม่ใช่ checklist อย่างเดียว

  • Web, Mobile, API และ Network ตามขอบเขตที่ตกลง
  • ตรวจ access control, session, data exposure และ business logic
  • เก็บหลักฐานที่ทำซ้ำได้ พร้อมคำอธิบายผลกระทบ
  • ส่งต่อ remediation ที่ทีมพัฒนานำไปใช้ได้

AI tests actively; humans retain authority

AI ทดสอบเชิงรุกอัตโนมัติ แต่มนุษย์ยืนยันทุก finding

  • ทำ reconnaissance และทดสอบโจมตีอัตโนมัติภายใน Scope ที่ได้รับอนุญาต
  • จัดทำ evidence index และตรวจความสอดคล้องของ checklist
  • อาจช่วยร่างรายงาน แต่รายงานสุดท้ายผ่าน human review
  • hypothesis จาก AI จะไม่เป็น finding จนกว่ามนุษย์ทำซ้ำได้

DELIVERY FLOW / 04

กระบวนการทำงานของเรา

ทุกช่วงมีเจ้าของงาน หลักฐาน และจุดตัดสินใจที่ชัดเจน

รายละเอียดขั้นตอนที่ 01

วางแผน

เปลี่ยนเป้าหมายทางธุรกิจให้เป็นขอบเขตการทดสอบที่ชัดเจน ปลอดภัย และได้รับอนุญาตก่อนเริ่มดำเนินงาน

เจ้าของงาน Engagement Lead ระยะเวลาโดยประมาณ 1-2 วันทำการ

สิ่งที่เราดำเนินการ

  • ยืนยันระบบ โดเมน IP Address, API และ Application ที่อยู่ในและนอกขอบเขต
  • จัดเตรียมบัญชีทดสอบ สิทธิ์การเข้าถึง MFA และ Test Data
  • กำหนด Test Window, Rules of Engagement และเงื่อนไขหยุดการทดสอบ
  • ระบุช่องทางสื่อสารและขั้นตอน Escalation สำหรับเหตุการณ์สำคัญ

Deliverables

  • Approved Scope & Rules of Engagement
  • Asset and Account Matrix
  • Test Schedule
  • Communication and Escalation Plan

Evidence

  • หนังสืออนุญาตให้ทดสอบ
  • รายการระบบและ Endpoint
  • Access Readiness Checklist
  • รายชื่อผู้ประสานงานและผู้อนุมัติ

Framework Mapping

Engagement GovernanceOWASP WSTG v4.2Authorized Testing

Decision Gate เริ่มการทดสอบเมื่อ Scope, Access, Test Window และ ROE ได้รับการยืนยันครบถ้วน

ดู Scope และ ROE

รายละเอียดขั้นตอนที่ 02

วิเคราะห์

สร้างแบบจำลองภัยคุกคามและแผนที่ Attack Surface เพื่อเลือกเส้นทางการโจมตีที่มีโอกาสเกิดขึ้นและส่งผลกระทบสูง

เจ้าของงาน Lead Pentester / Security Analyst ระยะเวลาโดยประมาณ 1-3 วันทำการ

สิ่งที่เราดำเนินการ

  • วิเคราะห์ Architecture, Trust Boundary และ Data Flow
  • จัดทำ Threat Model และ Abuse Cases
  • สำรวจ Attack Surface และเทคโนโลยีที่เปิดเผย
  • วิเคราะห์ Role, Privilege และเส้นทางเข้าถึงข้อมูลสำคัญ
  • จัดลำดับ Test Scenario ตามความเสี่ยงและผลกระทบ

Deliverables

  • Attack Surface Map
  • Threat Model and Abuse Cases
  • Prioritized Test Scenarios
  • Initial Attack Hypotheses

Evidence

  • Endpoint และ Service Inventory
  • Role and Privilege Matrix
  • Data Flow และ Trust Boundary
  • Reconnaissance Artifacts

Framework Mapping

MITRE ATT&CK v19.1ReconnaissanceResource Development - เมื่อได้รับอนุญาตและอยู่ใน ScopeOWASP WSTG: Information Gathering

Decision Gate ยืนยัน High-value Assets, Trust Boundaries และ Attack Paths ที่จะนำไปทดสอบ

ดู Attack Surface

รายละเอียดขั้นตอนที่ 03

ทดสอบ

ดำเนินการทดสอบเชิงรุกด้วยเทคนิค Manual เพื่อยืนยันช่องโหว่และเชื่อมโยงเป็น Attack Chain ภายใต้ขอบเขตที่ได้รับอนุญาต

เจ้าของงาน Technical Lead / Pentest Team ระยะเวลาโดยประมาณ 5-15 วันทำการ

สิ่งที่เราดำเนินการ

  • ทดสอบ Authentication, Authorization และ Session Management
  • วิเคราะห์ Business Logic และการข้ามขั้นตอนของระบบ
  • ยืนยันช่องโหว่ด้วย Manual Exploitation
  • เชื่อมโยงหลายช่องโหว่เพื่อประเมินผลกระทบแบบ Attack Chain
  • ควบคุมการทดสอบไม่ให้เกิน Rules of Engagement

Deliverables

  • Verified Security Findings
  • Proof of Concept
  • Attack Chain Diagram
  • Test Coverage Matrix

Evidence

  • HTTP Requests and Responses
  • Screenshots and Screen Recordings
  • Commands, Logs and Tool Output
  • PoC Code และ Impact Evidence

Framework Mapping

OWASP Top 10:2025OWASP WSTG v4.2 Test IDsMITRE ATT&CK v19.1 Tactics & Techniquesเฉพาะพฤติกรรมที่ทดสอบและยืนยันแล้ว

Decision Gate ช่องโหว่ต้องทำซ้ำได้ มีหลักฐานเพียงพอ และอธิบายผลกระทบต่อระบบหรือธุรกิจได้

ดู Coverage และ Evidence

รายละเอียดขั้นตอนที่ 04

ยืนยันผล

ตรวจสอบผลการทดสอบซ้ำเพื่อตัด False Positive ระบุขอบเขตที่ได้รับผลกระทบ และประเมินความเสี่ยงจากหลักฐานที่พิสูจน์ได้

เจ้าของงาน Validation Lead / QA Reviewer ระยะเวลาโดยประมาณ 1-3 วันทำการ

สิ่งที่เราดำเนินการ

  • ทำซ้ำช่องโหว่ด้วยเงื่อนไขที่ควบคุมได้
  • ตรวจสอบ Preconditions และข้อจำกัดของการโจมตี
  • ทดสอบ Negative Control เพื่อแยกพฤติกรรมปกติออกจากช่องโหว่
  • ประเมินผลกระทบต่อ Confidentiality, Integrity และ Availability
  • วิเคราะห์ผลกระทบทางธุรกิจและความเป็นไปได้ในการโจมตีจริง

Deliverables

  • Validated Findings
  • Affected Asset and Scope
  • Impact Analysis
  • Risk Rating and Rationale
  • Remediation Priority

Evidence

  • Reproduction Steps
  • Successful and Failed Test Cases
  • Privilege หรือ Data Impact
  • Preconditions and Environmental Context

Framework Mapping

OWASP Top 10:2025 CategoryOWASP WSTG Test ReferenceMITRE ATT&CK Technique MappingImpact & Risk Validation

Decision Gate จัดสถานะเป็น Confirmed, Informational หรือ Rejected พร้อมเหตุผลที่ตรวจสอบย้อนกลับได้

ดู Risk Rationale

รายละเอียดขั้นตอนที่ 05

รายงาน

แปลงผลการทดสอบเป็นข้อมูลสำหรับผู้บริหารและทีมเทคนิค พร้อมลำดับความสำคัญและแนวทางแก้ไขที่นำไปปฏิบัติได้จริง

เจ้าของงาน Report Owner / QA Reviewer ระยะเวลาโดยประมาณ 3-5 วันทำการ

สิ่งที่เราดำเนินการ

  • สรุปภาพรวมความเสี่ยงและผลกระทบต่อธุรกิจ
  • จัดทำรายละเอียดทางเทคนิคและขั้นตอนการทำซ้ำ
  • แสดง Attack Path และความสัมพันธ์ระหว่างช่องโหว่
  • เสนอแนวทางแก้ไขทั้งระยะเร่งด่วนและระยะยาว
  • ตรวจสอบคุณภาพและลบข้อมูลสำคัญที่ไม่จำเป็นออกจากหลักฐาน

Deliverables

  • Executive Report
  • Technical Pentest Report
  • Finding and Evidence Register
  • Attack Chain Visualization
  • Prioritized Remediation Plan

Evidence

  • Sanitized Screenshots
  • Request and Response References
  • PoC and Reproduction Steps
  • Evidence Traceability Index

Framework Mapping

OWASP Top 10:2025 CoverageOWASP WSTG Test CoverageMITRE ATT&CK Attack PathFinding-to-Framework Matrix

Decision Gate ยืนยันข้อเท็จจริง ผู้รับผิดชอบแก้ไข ลำดับความสำคัญ และรายการที่ต้องเข้าสู่ Retest

ดูตัวอย่างรายงาน

รายละเอียดขั้นตอนที่ 06

Retest

ทดสอบการแก้ไขภายใต้เงื่อนไขเดิม ตรวจสอบ Bypass หรือ Variant ที่เกี่ยวข้อง และยืนยันว่าความเสี่ยงได้รับการลดลงจริง

เจ้าของงาน Original Tester / QA Reviewer ระยะเวลาโดยประมาณ 1-3 วันทำการ

สิ่งที่เราดำเนินการ

  • ทำซ้ำ PoC และขั้นตอนจากผลการทดสอบเดิม
  • ตรวจสอบ Root Cause ไม่เฉพาะอาการที่ปรากฏ
  • ทดสอบ Variant และเส้นทาง Bypass ที่เกี่ยวข้อง
  • ตรวจสอบผลกระทบจากการแก้ไขต่อฟังก์ชันเดิม
  • เปรียบเทียบหลักฐานก่อนและหลังการแก้ไข

Deliverables

  • Retest Report
  • Finding Status Update
  • Closure Evidence
  • Residual Risk Summary
  • รายการช่องโหว่ที่ยังต้องดำเนินการต่อ

Evidence

  • Before and After Requests
  • Updated Configuration หรือ Application Version
  • Retest Screenshots
  • Timestamped Verification Results

Framework Mapping

Original OWASP Reference RetainedOriginal ATT&CK Mapping RetainedFix VerificationClosure Traceability

Decision Gate ยืนยันสถานะหลัง Retest พร้อมหลักฐานประกอบเป็น Closed, Partially Remediated, Open, Unable to Verify หรือ Risk Accepted

ระยะเวลาเป็นค่าประมาณและอาจเปลี่ยนแปลงตาม Scope, Access และ Rules of Engagement

Governance & Compliance

มาตรฐานและกรอบการทดสอบ

กฎหมายทั่วไปและความมั่นคงปลอดภัยไซเบอร์ระดับชาติ

ธนาคารและระบบการชำระเงิน (ธปท.)

หลักทรัพย์และสินทรัพย์ดิจิทัล (ก.ล.ต.) และ ประกันภัย (คปภ.)

VERIFIABLE TRUST / 05

มาตรฐานที่ตรวจสอบได้

ดาวน์โหลดใบรับรองจริง และตรวจสอบหลักการส่งมอบงานของเราได้โดยตรง

01

Human validation

ทุก finding ผ่านการทำซ้ำและยืนยันด้วยมือ

02

Evidence ready

มีหลักฐาน วิธี reproduce ผลกระทบ และ remediation

03

Responsible AI

AI เป็น automated testing layer แต่มนุษย์เป็นผู้ตัดสินผลทดสอบ

04

Retest closure

ตรวจการแก้ไขและส่งหลักฐานตาม package หรือ scope

START THE CONVERSATION / 06

จะทำ Pentest ทั้งที
ทำกับทีมที่ “ถนัด” ไปเลย

ส่งข้อมูลระบบเบื้องต้น พร้อมขอบเขตการทดสอบ และช่วงเวลาที่ต้องการให้เราเริ่มประเมินแผนการดำเนินงาน

PENTEST FAQ / 07

คำถามที่พบบ่อยเกี่ยวกับบริการ Pentest

รวมคำตอบเรื่องขอบเขต ราคา ระยะเวลา และข้อกำหนดของหน่วยงานกำกับดูแล หากไม่พบคำตอบที่ต้องการ ทักมาคุยกับทีมได้โดยตรง

Pentest กับ VA Scan ต่างกันอย่างไร ควรเริ่มจากแบบไหน

VA Scan ใช้เครื่องมือสแกนหาช่องโหว่ในวงกว้าง เหมาะกับการตรวจสุขภาพระบบจำนวนมากและจัดลำดับความเสี่ยงก่อน ส่วน Pentest คือการที่ผู้เชี่ยวชาญลงมือเจาะจริงเพื่อพิสูจน์ว่าช่องโหว่ใช้โจมตีได้หรือไม่ พร้อมหลักฐานและวิธีแก้ ระบบที่สำคัญต่อธุรกิจหรือเก็บข้อมูลลูกค้าจึงควรทำ Pentest ควบคู่กับ VA ตามรอบ ไม่ใช่เลือกอย่างใดอย่างหนึ่งแทนกัน

ทีมที่ทดสอบมีความเชี่ยวชาญและใบรับรองอะไรบ้าง

ทีม STH มีประสบการณ์ทดสอบเจาะระบบให้แอปพลิเคชันทางการเงินชั้นนำ และได้รับการรับรองมาตรฐานสากลทั้งในระดับองค์กรและระดับบุคคลของผู้เชี่ยวชาญที่เข้าทดสอบจริง อีกทั้งเคยเป็นแชมป์การแข่งขัน Thailand Cyber Top Talent 2023 เราพร้อมสนับสนุนการดำเนินงานตลอดโครงการ ตั้งแต่ให้คำปรึกษาช่วงเริ่มต้น เตรียมความพร้อมก่อนดำเนินการ สื่อสารช่องโหว่ที่พบระหว่างดำเนินการ และให้คำปรึกษาในการปิดช่องโหว่ต่าง ๆ อย่างรัดกุม

ทดสอบด้วยคนจริง หรือแค่รันเครื่องสแกนอัตโนมัติ

งานของเรานำโดยมนุษย์ ผู้เชี่ยวชาญกำหนดขอบเขต ลงมือเจาะจริง และยืนยันทุก finding ด้วยมือก่อนเข้ารายงาน เราใช้ AI และเครื่องมืออัตโนมัติช่วยเร่ง Reconnaissance และเพิ่มความครอบคลุมภายใน Scope ที่ได้รับอนุญาต แต่สิ่งที่เครื่องสแกนทำแทนไม่ได้ เช่น การเชื่อมหลายช่องโหว่ให้เป็นการโจมตีจริง การทดสอบ Business Logic, IDOR และ Authentication ยังทำโดยผู้เชี่ยวชาญ คุณจึงได้หลักฐานที่โจมตีได้จริงและตัด False Positive ออกแล้ว ไม่ใช่รายงานสำเร็จรูปจากเครื่องสแกน

ค่าบริการ Pentest คิดจากอะไร

คิดจากขอบเขตเป็นหลัก เช่น จำนวนระบบ ขนาดของแอปพลิเคชัน จำนวนฟังก์ชันหรือ API ที่ต้องทดสอบ และรูปแบบการทดสอบ (Black-box, Gray-box หรือ White-box) เมื่อส่งรายละเอียดระบบมาให้เรา ทีมจะประเมินเป็นจำนวนวันทำงาน (man-day) และออกใบเสนอราคาที่ระบุขอบเขตชัดเจนก่อนเริ่มงานทุกครั้ง

ทดสอบหนึ่งระบบใช้เวลานานแค่ไหน

ขึ้นอยู่กับขนาดและความซับซ้อนของระบบ โดยทั่วไปแอปพลิเคชันหนึ่งระบบใช้เวลาทดสอบประมาณ 1–3 สัปดาห์รวมการจัดทำรายงาน หลังจากทีมของคุณแก้ไขช่องโหว่แล้ว เรานัดรอบ Retest เพื่อยืนยันผลการแก้ไขอีกครั้ง

เมื่อทดสอบเสร็จจะได้รับอะไรบ้าง

รายงานฉบับเต็มที่มีทั้งบทสรุปผู้บริหารและรายละเอียดทางเทคนิค ทุก finding ระบุขั้นตอนการทำซ้ำ หลักฐาน ระดับความเสี่ยงตาม CVSS และคำแนะนำการแก้ไขที่นำไปใช้ได้จริง พร้อมช่องทางสอบถามทีมทดสอบโดยตรง และรายงานผล Retest หลังการแก้ไข

หน่วยงานกำกับดูแลกำหนดให้ทำ Pentest หรือไม่

หลายอุตสาหกรรมมีข้อกำหนดโดยตรง เช่น สถาบันการเงินภายใต้หลักเกณฑ์ของธนาคารแห่งประเทศไทย ธุรกิจหลักทรัพย์และสินทรัพย์ดิจิทัลภายใต้ ก.ล.ต. และระบบบัตรตาม PCI DSS ส่วน PDPA และ พ.ร.บ.ไซเบอร์ฯ กำหนดเป็นหน้าที่ดูแลความมั่นคงปลอดภัยตามความเสี่ยง เราสรุปข้อกำหนดของแต่ละหน่วยงานพร้อมลิงก์เอกสารต้นทางไว้ที่หน้ามาตรฐานและข้อกำหนด

ต้องเตรียมอะไรบ้างก่อนเริ่มทดสอบ

หลัก ๆ คือช่วยกำหนดขอบเขตร่วมกับเรา เช่น รายการระบบ URL หรือไฟล์ติดตั้งแอป บัญชีทดสอบตามบทบาทผู้ใช้ และช่วงเวลาที่สะดวกให้ทดสอบ จากนั้นเราจัดทำเอกสารขอบเขตและกติกาการทดสอบ (Rules of Engagement) ให้ตกลงร่วมกันเป็นลายลักษณ์อักษรก่อนเริ่มงาน

ข้อมูลของบริษัทเราปลอดภัยแค่ไหนระหว่างการทดสอบ

การทดสอบทั้งหมดทำภายในขอบเขตที่ได้รับอนุญาตเป็นลายลักษณ์อักษรและอยู่ภายใต้สัญญารักษาความลับ STH ได้รับการรับรอง ISO/IEC 27001:2022 และ ISO 9001:2015 ซึ่งครอบคลุมการจัดการหลักฐาน การจัดเก็บข้อมูล และการส่งมอบรายงานอย่างรัดกุมตลอดโครงการ

Image

OffSec

OSCP

OffSec Certified Professional

ความน่าเชื่อถือของผู้ออกใบรับรอง

OffSec เป็นผู้ให้บริการหลักสูตร ห้องปฏิบัติการ และการรับรองวิชาชีพด้าน Cybersecurity ที่เน้นการลงมือปฏิบัติจริง

ความสามารถที่สะท้อน

การระบุช่องโหว่ การโจมตีระบบ การยกระดับสิทธิ์ Active Directory และการจัดทำรายงานผล

คุณค่าต่อลูกค้า

สนับสนุนการทดสอบที่ลงมือพิสูจน์จริง พร้อมหลักฐานและขั้นตอนที่ทีมเทคนิคทำซ้ำได้

ดูข้อมูล OSCP จาก OffSec

Issuer credibility

OffSec provides hands-on cybersecurity training, labs, and professional certifications.

Demonstrated capability

Vulnerability identification, system exploitation, privilege escalation, Active Directory, and professional reporting.

Customer value

Supports practical testing backed by reproducible evidence and technically useful findings.

View official OSCP information
Image

OffSec

OSWE

OffSec Web Expert

ความน่าเชื่อถือของผู้ออกใบรับรอง

OffSec เป็นผู้ให้บริการหลักสูตร ห้องปฏิบัติการ และการรับรองวิชาชีพด้าน Cybersecurity ที่เน้นการลงมือปฏิบัติจริง

ความสามารถที่สะท้อน

White-box testing การวิเคราะห์ Source Code การเชื่อมโยงช่องโหว่ และ Custom Exploit Development

คุณค่าต่อลูกค้า

ช่วยค้นหา Server-side และ Logic Flaw ที่ต้องอาศัยการวิเคราะห์เชิงลึกกว่าการสแกนทั่วไป

ดูคู่มือสอบ OSWE จาก OffSec

Issuer credibility

OffSec provides hands-on cybersecurity training, labs, and professional certifications.

Demonstrated capability

White-box testing, source-code analysis, vulnerability chaining, and custom exploit development.

Customer value

Supports deeper discovery of server-side and logic flaws beyond routine scanning.

View the official OSWE exam guide
Image

OffSec

OSEP

OffSec Experienced Penetration Tester

ความน่าเชื่อถือของผู้ออกใบรับรอง

OffSec เป็นผู้ให้บริการหลักสูตร ห้องปฏิบัติการ และการรับรองวิชาชีพด้าน Cybersecurity ที่เน้นการลงมือปฏิบัติจริง

ความสามารถที่สะท้อน

Client-side attacks การหลบหลีก Antivirus และ Application Allow-listing การเชื่อมโยง Attack Path และ Active Directory ขั้นสูง

คุณค่าต่อลูกค้า

ช่วยประเมินว่ามาตรการป้องกันหลายชั้นสามารถหยุดเส้นทางโจมตีที่สมจริงได้เพียงใด

ดูข้อมูล OSEP จาก OffSec

Issuer credibility

OffSec provides hands-on cybersecurity training, labs, and professional certifications.

Demonstrated capability

Client-side attacks, antivirus and application allow-listing evasion, attack chaining, and advanced Active Directory.

Customer value

Helps assess how effectively layered defenses resist realistic attack paths.

View official OSEP information
Image

OffSec

OSCE

OffSec Certified Expert

ความน่าเชื่อถือของผู้ออกใบรับรอง

OffSec เป็นผู้ให้บริการหลักสูตร ห้องปฏิบัติการ และการรับรองวิชาชีพด้าน Cybersecurity ที่เน้นการลงมือปฏิบัติจริง

ความสามารถที่สะท้อน

Web attacks, Userland Exploit Development, Antivirus Evasion และการโจมตีระบบเครือข่ายหรือ Edge

คุณค่าต่อลูกค้า

เพิ่มมุมมองเชิงลึกสำหรับงานที่ต้องวิเคราะห์ Exploitability และเทคนิคโจมตีระดับต่ำ

ดู OSCE FAQ จาก OffSec

Issuer credibility

OffSec provides hands-on cybersecurity training, labs, and professional certifications.

Demonstrated capability

Web attacks, userland exploit development, antivirus evasion, and network or edge-system attacks.

Customer value

Adds depth to assessments requiring exploitability analysis and low-level attack expertise.

View the official OSCE FAQ
Image

EC-Council

CEH

Certified Ethical Hacker

ความน่าเชื่อถือของผู้ออกใบรับรอง

EC-Council เป็นองค์กรด้านการฝึกอบรมและการรับรองวิชาชีพ Cybersecurity

ความสามารถที่สะท้อน

องค์ความรู้ด้าน Ethical Hacking, Threats, Attack Vectors, Detection, Prevention และ Security Methodology

คุณค่าต่อลูกค้า

สนับสนุนการประเมินที่ครอบคลุมภัยคุกคามหลายรูปแบบภายใต้กรอบจริยธรรมและการอนุญาตที่ชัดเจน

ดูข้อมูลการสอบ CEH จาก EC-Council

Issuer credibility

EC-Council is a cybersecurity training and professional-certification organization.

Demonstrated capability

Ethical-hacking knowledge across threats, attack vectors, detection, prevention, and assessment methodology.

Customer value

Supports broad threat coverage within a clearly authorized and ethical testing process.

View official CEH exam information
Image

CompTIA

CompTIA PenTest+

CompTIA PenTest+

ความน่าเชื่อถือของผู้ออกใบรับรอง

CompTIA พัฒนาผลิตภัณฑ์ฝึกอบรมและการรับรองวิชาชีพ IT แบบไม่ผูกกับผู้ผลิต (vendor-neutral)

ความสามารถที่สะท้อน

Engagement Management, Reconnaissance, Vulnerability Analysis, Exploitation, Post-exploitation, Lateral Movement และ Reporting

คุณค่าต่อลูกค้า

ช่วยให้โครงการมีโครงสร้างตั้งแต่การวางแผนขอบเขตจนถึงคำแนะนำ Remediation ที่นำไปดำเนินการได้

ดูข้อมูล PenTest+ จาก CompTIA

Issuer credibility

CompTIA develops vendor-neutral IT training and certification products.

Demonstrated capability

Engagement management, reconnaissance, vulnerability analysis, exploitation, post-exploitation, lateral movement, and reporting.

Customer value

Supports a structured assessment from scope planning through actionable remediation.

View official PenTest+ information
Image

GIAC

GPEN

GIAC Penetration Tester

ความน่าเชื่อถือของผู้ออกใบรับรอง

GIAC พัฒนาและบริหารการรับรองวิชาชีพเฉพาะทางด้าน Information Security

ความสามารถที่สะท้อน

การวางแผน Pentest, Reconnaissance, Scanning, Exploitation, Post-exploitation, Pivoting และ Password Attacks

คุณค่าต่อลูกค้า

สนับสนุนการทดสอบโครงสร้างพื้นฐานที่เป็นระบบและเชื่อมโยงผลทางเทคนิคกับเส้นทางโจมตีจริง

ดูข้อมูล GPEN จาก GIAC

Issuer credibility

GIAC develops and administers specialist information-security certifications.

Demonstrated capability

Penetration-test planning, reconnaissance, scanning, exploitation, post-exploitation, pivoting, and password attacks.

Customer value

Supports systematic infrastructure testing connected to realistic attack paths.

View official GPEN information
Image

GIAC

GWAPT

GIAC Web Application Penetration Tester

ความน่าเชื่อถือของผู้ออกใบรับรอง

GIAC พัฒนาและบริหารการรับรองวิชาชีพเฉพาะทางด้าน Information Security

ความสามารถที่สะท้อน

Authentication, Session, Configuration, SQL Injection, CSRF, XSS และ Client-side Injection

คุณค่าต่อลูกค้า

ช่วยเพิ่มความลึกในการทดสอบเว็บและเส้นทางโจมตีที่เชื่อมกับข้อมูลหรือบัญชีผู้ใช้

ดูข้อมูล GWAPT จาก GIAC

Issuer credibility

GIAC develops and administers specialist information-security certifications.

Demonstrated capability

Authentication, session, configuration, SQL injection, CSRF, XSS, and client-side injection testing.

Customer value

Adds depth to web assessments involving user accounts, sensitive data, and application attack paths.

View official GWAPT information
Image

ISC2

CISSP

Certified Information Systems Security Professional

ความน่าเชื่อถือของผู้ออกใบรับรอง

ISC2 เป็นสมาคมสมาชิกไม่แสวงหากำไรสำหรับผู้เชี่ยวชาญด้าน Cybersecurity

ความสามารถที่สะท้อน

Risk Management, Security Architecture, IAM, Security Assessment, Operations และ Secure Development

คุณค่าต่อลูกค้า

ช่วยแปลผลการทดสอบทางเทคนิคให้เชื่อมกับระดับความเสี่ยง สำหรับผู้ที่ต้องรับผิดชอบแก้ไข และบริบทการกำกับดูแลขององค์กร

ดูข้อมูล CISSP จาก ISC2

Issuer credibility

ISC2 is a nonprofit member association for cybersecurity professionals.

Demonstrated capability

Risk management, security architecture, IAM, assessment, operations, and secure development.

Customer value

Helps connect technical findings with business risk, remediation ownership, and security governance.

View official CISSP information
Image

CREST

CREST CRT

CREST Registered Penetration Tester

ความน่าเชื่อถือของผู้ออกใบรับรอง

CREST เป็นองค์กรสมาชิกสากลที่ไม่แสวงหากำไร ซึ่งรับรององค์กรและผู้เชี่ยวชาญด้าน Cybersecurity

ความสามารถที่สะท้อน

การทดสอบโครงสร้างพื้นฐาน เว็บ ระบบปฏิบัติการ Network Services การตีความผลสแกน และการยืนยันช่องโหว่

คุณค่าต่อลูกค้า

สนับสนุนงานทดสอบที่มีวินัยทางเทคนิคและสอดคล้องกับแนวทางวิชาชีพของ CREST

ดูข้อมูล CREST CRT

Issuer credibility

CREST is an international not-for-profit membership body that accredits cybersecurity organizations and certifies professionals.

Demonstrated capability

Infrastructure and web testing, operating systems, network services, scan interpretation, and vulnerability validation.

Customer value

Supports technically disciplined assessments aligned with CREST professional practice.

View official CREST CRT information
Image

CREST

CREST CPSA

CREST Practitioner Security Analyst

ความน่าเชื่อถือของผู้ออกใบรับรอง

CREST เป็นองค์กรสมาชิกสากลที่ไม่แสวงหากำไร ซึ่งรับรององค์กรและผู้เชี่ยวชาญด้าน Cybersecurity

ความสามารถที่สะท้อน

Testing Lifecycle, Scoping, Windows, Unix, Network Services, Web Technologies และ Vulnerability Assessment

คุณค่าต่อลูกค้า

สนับสนุนการกำหนดขอบเขต การดำเนินการ และการตีความผลทดสอบอย่างสม่ำเสมอ

ดูข้อมูล CREST CPSA

Issuer credibility

CREST is an international not-for-profit membership body that accredits cybersecurity organizations and certifies professionals.

Demonstrated capability

Testing lifecycle, scoping, Windows, Unix, network services, web technologies, and vulnerability assessment.

Customer value

Supports consistent scoping, execution, and interpretation of security tests.

View official CREST CPSA information
Image

Hack The Box Academy

HTB CWES

HTB Certified Web Exploitation Specialist

ความน่าเชื่อถือของผู้ออกใบรับรอง

Hack The Box ให้บริการ HTB Academy เป็นแพลตฟอร์มฝึกอบรม Cybersecurity แบบโต้ตอบและลงมือปฏิบัติจริง

ความสามารถที่สะท้อน

Web Application และ API Penetration Testing, Bug Bounty Methodology, Risk Evaluation และ Actionable Reporting

คุณค่าต่อลูกค้า

สนับสนุนการทดสอบเว็บและ API สมัยใหม่ด้วยทักษะที่ผ่านสถานการณ์ปฏิบัติจริง

ดูข้อมูลใบรับรองจาก Hack The Box Academy

Issuer credibility

Hack The Box operates HTB Academy, an interactive, hands-on cybersecurity training platform.

Demonstrated capability

Web-application and API penetration testing, bug-bounty methodology, risk evaluation, and actionable reporting.

Customer value

Supports practical assessment of modern web applications and APIs.

View official HTB Academy certification information

DECISION GATE / SCOPE

ขอบเขตและกติกาการทดสอบ Scope & Rules of Engagement

เราตกลงเป้าหมาย สิทธิ์ วิธีทดสอบ และจุดหยุดร่วมกันก่อนเริ่ม เพื่อให้การทดสอบลงลึกได้โดยควบคุมผลกระทบต่อธุรกิจ We agree targets, authority, test methods, and stop conditions before execution so the assessment can go deep while controlling business impact.

ภาพประกอบการกำหนด Scope และ Rules of Engagement ก่อนเริ่มทดสอบ

ระบบและสิทธิ์ที่ต้องเตรียม

ขอบเขตระบบและ Access สำหรับการทดสอบ
ระบบScopeAccess
เว็บและ APIDomains, routes, APIs, admin portals, roles และ integrationsบัญชีทดสอบ, MFA path, API documentation และ test data
แอปมือถือAndroid/iOS builds, package IDs, deep links, local storage และ backend APIsTest builds, devices, accounts, source หรือ symbols เมื่อตกลง
เครือข่ายภายนอกPublic IP ranges, DNS, VPN, gateways, cloud edge และ exposed servicesApproved source IPs, maintenance window และ emergency contacts
เครือข่ายภายในSubnets, hosts, Active Directory, identity, segmentation และ management servicesVPN/jump host, test workstation, test identities และ routing prerequisites

เลือกรูปแบบการทดสอบให้เหมาะกับเป้าหมาย

เปรียบเทียบ Black Box, Gray Box และ White Box
รูปแบบข้อมูลและสิทธิ์เหมาะกับคุณค่าต่อลูกค้า
ภาพประกอบ Black Boxให้ข้อมูลเป้าหมายสาธารณะขั้นต่ำมุมมองผู้โจมตีภายนอกยืนยัน Exposure ที่สมจริง
ภาพประกอบ Gray Boxให้บัญชีทดสอบและเอกสารที่จำเป็นRole, Business Logic และ Authenticated Pathsสมดุลความสมจริง ความลึก และเวลาส่งมอบ
ภาพประกอบ White Boxให้ Architecture, Source, Configuration และสิทธิ์ที่ตกลงCoverage และ Root-cause Analysis เชิงลึกมองเห็นเชิงเทคนิคและบริบทการแก้ไขสูงสุด

Rules of Engagement ที่ยืนยันก่อนเริ่ม

  • หนังสืออนุญาตและผู้อนุมัติที่ระบุชื่อ
  • ทรัพย์สินใน Scope และรายการที่ยกเว้น
  • เทคนิคที่อนุญาตและห้ามใช้
  • Test window, source IPs, rate limits และ stop conditions
  • การจัดการข้อมูล Production และอายุการเก็บหลักฐาน
  • ช่องทางยกระดับเหตุการณ์ Critical
  • การ Cleanup, ลบบัญชีทดสอบ และเงื่อนไข Revisit

Gate: พร้อมเริ่มเมื่อ Scope, Access, Test Window, ROE และช่องทาง Escalation ได้รับการยืนยัน

Systems and access to prepare

System scope and access required for testing
SystemScopeAccess
Web and APIDomains, routes, APIs, admin portals, roles, and integrationsTest accounts, MFA path, API documentation, and test data
MobileAndroid/iOS builds, package IDs, deep links, local storage, and backend APIsTest builds, devices, accounts, source, or symbols when agreed
External NetworkPublic IP ranges, DNS, VPN, gateways, cloud edge, and exposed servicesApproved source IPs, maintenance window, and emergency contacts
Internal NetworkSubnets, hosts, Active Directory, identity, segmentation, and management servicesVPN/jump host, test workstation, test identities, and routing prerequisites

Select the testing model that fits the objective

Black Box, Gray Box, and White Box comparison
ModelInformation and accessBest fitCustomer value
Black Box testing model illustrationMinimal public target informationAn external attacker viewRealistic exposure validation
Gray Box testing model illustrationTest accounts and selected documentationRoles, business logic, and authenticated pathsBalanced realism, depth, and delivery time
White Box testing model illustrationAgreed architecture, source, configuration, and accessDeep coverage and root-cause analysisMaximum technical visibility and remediation context

Rules of Engagement confirmed before testing

  • Written authorization and named approvers
  • In-scope and excluded assets
  • Allowed and prohibited techniques
  • Test window, source IPs, rate limits, and stop conditions
  • Production-data handling and evidence retention
  • Critical-event escalation
  • Cleanup, test-account removal, and revisit conditions

Gate: Ready to begin when scope, access, the test window, ROE, and escalation paths are confirmed.

DECISION GATE / ATTACK SURFACE

Attack Surface ที่เรานำไปทดสอบAttack Surface We Carry Into Testing

เปลี่ยนรายการระบบให้เป็นแผนที่ Entry Points, Trust Boundaries, Roles และเส้นทางเข้าถึงข้อมูลสำคัญTurn the asset inventory into a map of entry points, trust boundaries, roles, and paths to sensitive data.

ภาพประกอบแผนที่ Attack Surface สำหรับเว็บ มือถือ และเครือข่าย

Web และ API

พื้นผิวการโจมตีเว็บและการอ้างอิง
พื้นที่ทดสอบการอ้างอิง
Entry points, routes, authentication และ sessionsOWASP WSTG v4.2; OWASP Top 10:2025
Object/function authorization, rate limits และ sensitive business flowsOWASP API Security Top 10:2023
Configuration, files, integrations, SSRF และ cloud storageWSTG v4.2 และ API Security
Authorized adversary behaviorsMITRE Enterprise ATT&CK T1595 Active Scanning และ T1190 Exploit Public-Facing Application

Mobile

พื้นผิวการโจมตีแอปมือถือและการอ้างอิง
พื้นที่ทดสอบการอ้างอิง
Package, code, update path และ tamper resistanceMASVS 2.1 CODE/RESILIENCE; MASTG 2.0
Local storage, cryptography และ privacyMASVS-STORAGE, CRYPTO และ PRIVACY
Authentication, platform, deep links และ network trafficMASVS-AUTH, PLATFORM และ NETWORK
Backend APIs และพฤติกรรมที่เกี่ยวข้องAPI Top 10:2023; MITRE Mobile ATT&CK T1664, T1417, T1533

Network

พื้นผิวการโจมตีเครือข่ายและการอ้างอิง
พื้นที่ทดสอบการอ้างอิง
Public services, VPN, gateways และ cloud edgeT1595, T1133, T1190
Internal hosts และ service discoveryT1046
Identities และ trust pathsT1078
Remote-service exploitation, segmentation และ lateral pathsMITRE Enterprise ATT&CK Discovery และ Lateral Movement; T1210

Outputs

  • Asset และ endpoint inventory
  • Role และ privilege matrix
  • Data-flow และ trust-boundary map
  • Prioritized abuse cases และ attack paths
  • Assumptions และ exclusions

ATT&CK ใช้เป็นฐานความรู้พฤติกรรมผู้โจมตีสำหรับ Mapping เฉพาะเทคนิคที่ได้รับอนุญาต ทดสอบ และมีหลักฐาน ไม่ใช่มาตรฐานทดสอบหรือเปอร์เซ็นต์ Coverage

Gate: ยืนยัน High-value Assets, Trust Boundaries และ Attack Paths ที่มีเหตุผลเพียงพอสำหรับการทดสอบ

Web and API

Web attack surface and references
Test areaReference mapping
Entry points, routes, authentication, and sessionsOWASP WSTG v4.2; OWASP Top 10:2025
Object/function authorization, rate limits, and sensitive business flowsOWASP API Security Top 10:2023
Configuration, files, integrations, SSRF, and cloud storageWSTG v4.2 and API Security
Authorized adversary behaviorsMITRE Enterprise ATT&CK T1595 Active Scanning and T1190 Exploit Public-Facing Application

Mobile

Mobile attack surface and references
Test areaReference mapping
Package, code, update path, and tamper resistanceMASVS 2.1 CODE/RESILIENCE; MASTG 2.0
Local storage, cryptography, and privacyMASVS-STORAGE, CRYPTO, and PRIVACY
Authentication, platform, deep links, and network trafficMASVS-AUTH, PLATFORM, and NETWORK
Backend APIs and relevant behaviorAPI Top 10:2023; MITRE Mobile ATT&CK T1664, T1417, T1533

Network

Network attack surface and references
Test areaReference mapping
Public services, VPN, gateways, and cloud edgeT1595, T1133, T1190
Internal hosts and service discoveryT1046
Identities and trust pathsT1078
Remote-service exploitation, segmentation, and lateral pathsMITRE Enterprise ATT&CK Discovery and Lateral Movement; T1210

Outputs

  • Asset and endpoint inventory
  • Role and privilege matrix
  • Data-flow and trust-boundary map
  • Prioritized abuse cases and attack paths
  • Assumptions and exclusions

ATT&CK is adversary-behavior knowledge used to map authorized, tested, and evidenced techniques. It is not a testing standard or coverage percentage.

Gate: Confirm the high-value assets, trust boundaries, and justified attack paths selected for testing.

DECISION GATE / COVERAGE

Coverage ที่กว้างขึ้น หลักฐานที่มนุษย์รับผิดชอบBroader Coverage, Human-Owned Evidence

AI ทำ reconnaissance และทดสอบเชิงรุกอัตโนมัติภายใน Scope เพื่อเพิ่มความเร็วและความครอบคลุม ส่วนผู้เชี่ยวชาญควบคุมการทดสอบ ยืนยันผลกระทบ และอนุมัติทุก FindingAI performs reconnaissance and automated active testing within scope to increase speed and coverage; specialists control testing, validate impact, and approve every finding.

ภาพประกอบการทำงานร่วมกันระหว่างผู้เชี่ยวชาญและ AI เพื่อขยาย Coverage

AI ทดสอบ แต่ผู้เชี่ยวชาญจาก STH ตัดสินผล

บทบาท AI และ Human ตลอดการทดสอบ
ขั้นตอนAIHuman
PlanningNormalize รายการทรัพย์สิน เสนอ Coverage gaps และ reference mappingsอนุมัติ Scope, safety constraints, ลำดับ และความลึก
Testingทำ reconnaissance สร้างสมมติฐาน และทดสอบเชิงรุกอัตโนมัติภายใน Scopeควบคุมการทดสอบ วิเคราะห์ Business Logic และยืนยัน Exploitation
Validationจัดกลุ่ม Artifacts และช่วย Cross-referenceทำซ้ำ Finding, รัน negative control, ยืนยัน affected scope และผลกระทบ
Reportingช่วย Index หลักฐานและ Draft trace linksให้เหตุผลและอนุมัติถ้อยคำ Remediation, Severity และรายงานสุดท้าย

มาตรฐานหลักฐาน

  • Request/response หรือ command/output
  • Timestamp และ affected asset
  • Reproduction steps และ preconditions
  • Positive proof พร้อม negative control ที่เกี่ยวข้อง
  • ผลกระทบต่อข้อมูล สิทธิ์ และธุรกิจ
  • Sanitized screenshot, recording หรือ PoC
  • Reviewer และสถานะ

ลูกค้าได้ Coverage ที่เร็วและกว้างขึ้น โดยไม่ลดความรับผิดชอบ ความสามารถในการทำซ้ำ และคุณภาพของหลักฐาน

Gate: Finding เข้ารายงานเมื่อทำซ้ำได้ อยู่ใน Scope มีหลักฐานเพียงพอ อธิบายผลกระทบได้ และผ่าน Human Review

AI runs automated testing; humans remain accountable

AI and human roles across the assessment
PhaseAIHuman
PlanningNormalizes asset lists, suggests coverage gaps, and reference mappingsApproves scope, safety constraints, sequence, and test depth
TestingPerforms reconnaissance, generates hypotheses, and runs automated active testing within scopeControls testing, analyzes business logic, and validates exploitation
ValidationClusters artifacts and assists cross-reference checksReproduces findings, runs negative controls, and establishes scope and impact
ReportingAssists evidence indexing and draft trace linksAssigns rationale and approves wording, remediation, severity, and the final report

Evidence standard

  • Request/response or command/output
  • Timestamp and affected asset
  • Reproduction steps and preconditions
  • Positive proof plus a relevant negative control
  • Data, privilege, and business impact
  • Sanitized screenshot, recording, or PoC
  • Reviewer and status

Gain faster, broader coverage without reducing accountability, reproducibility, or evidence quality.

Gate: A finding enters the report only when it is reproducible, in scope, sufficiently evidenced, impact-backed, and human-reviewed.

DECISION GATE / RISK

เหตุผลเบื้องหลังระดับความเสี่ยงHow We Build the Risk Rationale

แยกความรุนแรงทางเทคนิคออกจากความเสี่ยงทางธุรกิจ แล้วแสดงสมมติฐาน คะแนน และ Vector ให้ตรวจสอบย้อนกลับได้Separate technical severity from business risk and expose the assumptions, score, and vector for traceability.

ภาพอธิบายแนวคิดการจัดระดับความเสี่ยงจาก Likelihood และ Impact

OWASP Risk Rating

Risk = Likelihood × Impact

Factors และเกณฑ์การให้คะแนน 0-9
องค์ประกอบFactorsเกณฑ์
LikelihoodThreat agent: skill, motive, opportunity, size; Vulnerability: discovery, exploit, awareness, detectionLow <3, Medium 3-<6, High 6-9
ImpactTechnical: confidentiality, integrity, availability, accountability; Business: financial, reputation, compliance, privacyLow <3, Medium 3-<6, High 6-9

เราให้คะแนนปัจจัยที่เกี่ยวข้อง แล้ววางผลลงในตาราง Likelihood-Impact เพื่อให้เห็นระดับความเสี่ยง จากนั้นจึงทบทวนตามบริบทธุรกิจและมาตรการที่ลูกค้ามีอยู่ หากยังไม่มีข้อมูลธุรกิจ เราจะใช้ผลกระทบทางเทคนิคเป็นฐานและบันทึกสมมติฐานไว้ในรายงาน

CVSS v4.0

แผนภาพกลุ่ม Metric ของ CVSS v4.0: Base, Threat, Environmental และ Supplemental
Metric groups ที่ใช้คำนวณ
กลุ่มMetrics
BaseAV, AC, AT, PR, UI และผลกระทบ CIA ต่อ Vulnerable/Subsequent Systems
ThreatExploit Maturity
EnvironmentalSecurity requirements และ Modified Base metrics สำหรับสภาพแวดล้อมลูกค้า
SupplementalSafety, automation, recovery, value density, response effort และ provider urgency ใช้เป็นบริบทและไม่เปลี่ยนคะแนน

CVSS ช่วยบอกระดับความรุนแรงของช่องโหว่ด้วยมาตรฐานเดียวกัน ตั้งแต่ 0.0-10.0 รายงานของ STH ระบุทั้งคะแนน ระดับความรุนแรง และ CVSS Vector เพื่อให้ทีมเทคนิคตรวจสอบหรือเปรียบเทียบผลได้ เราใช้เครื่องมืออ้างอิงของ FIRST ตามมาตรฐาน CVSS v4.0 เพื่อให้คะแนนโปร่งใสและสอดคล้องกัน

Remediation priority

เราเรียงลำดับการแก้ไขจากความรุนแรงทางเทคนิค ความเป็นไปได้ที่โจมตีได้จริง ความสำคัญของระบบหรือข้อมูล ผลกระทบต่อธุรกิจของลูกค้า และมาตรการควบคุมที่มีอยู่ พร้อมบันทึกเหตุผลของแต่ละลำดับไว้ชัดเจน

ผู้บริหารเห็นเหตุผลของลำดับความสำคัญ ส่วนทีมเทคนิคเห็น Metrics และหลักฐานที่ใช้ตัดสิน

Gate: ยืนยันสถานะ Finding, CVSS Vector, OWASP Risk Rationale, Business Context และ Remediation Priority

OWASP Risk Rating

Risk = Likelihood × Impact

Factors and 0-9 thresholds
ComponentFactorsThresholds
LikelihoodThreat agent: skill, motive, opportunity, size; Vulnerability: discovery, exploit, awareness, detectionLow <3, Medium 3-<6, High 6-9
ImpactTechnical: confidentiality, integrity, availability, accountability; Business: financial, reputation, compliance, privacyLow <3, Medium 3-<6, High 6-9

We score the relevant factors and place the result on the likelihood-impact matrix to make the risk level clear. We then review it against the customer’s business context and existing controls. If business data is unavailable, we use technical impact as the baseline and document the assumption.

CVSS v4.0

Diagram of CVSS v4.0 metric groups: Base, Threat, Environmental, and Supplemental
Metric groups used in calculation
GroupMetrics
BaseAV, AC, AT, PR, UI and vulnerable/subsequent-system CIA impacts
ThreatExploit Maturity
EnvironmentalSecurity requirements and Modified Base metrics for the customer environment
SupplementalSafety, automation, recovery, value density, response effort, and provider urgency are contextual only and do not change the score

CVSS gives every vulnerability a severity score on the same 0.0-10.0 scale. STH reports the score, severity rating, and CVSS vector so technical teams can validate or compare the result. We use FIRST’s CVSS v4.0 reference calculator to keep scoring consistent and transparent.

Remediation priority

We prioritize remediation by considering technical severity, verified exploitability, the importance of affected systems or data, customer business impact, and existing controls. The rationale for each priority is documented clearly.

Executives see why remediation is prioritized; technical teams see the metrics and evidence behind the decision.

Gate: Confirm finding status, CVSS vector, OWASP risk rationale, business context, and remediation priority.

DECISION GATE / REPORT

จากหลักฐานสู่รายงานที่ลงมือแก้ได้From Evidence to an Actionable Report

รายงานชุดเดียวสื่อสารได้ทั้งกับผู้บริหาร เจ้าของระบบ และทีมที่ลงมือแก้ไขOne report set communicates clearly to executives, system owners, and remediation teams.

ตัวอย่างปกรายงาน Penetration Testing ของ STH

Report anatomy

  1. Cover Classification, ลูกค้า, Engagement, Version และวันที่
  2. Executive Summary ภาพรวมผลกระทบทางธุรกิจ
  3. Scope & ROE ระบบ ข้อยกเว้น Access model และกติกา
  4. Methodology Standard และ Coverage matrix
  5. Risk overview Findings ที่จัดลำดับแล้ว
  6. Finding Details ID, Assets, Status, Risk, CVSS score/vector, Evidence, Impact และ Remediation
  7. Attack chain ความสัมพันธ์ของ Findings
  8. Recommended Solutions Roadmap และผู้รับผิดชอบแก้ไข
  9. Appendix Evidence และ Framework traceability

Initial Report และ Revisit Report

ความแตกต่างของรายงานก่อนและหลังการแก้ไข
รายงานเนื้อหาหลักหลักฐานและผลลัพธ์
Initial ReportScope/วันที่ทดสอบ, Initial risk snapshot, Findings และคำแนะนำหลักฐานครบ, Remediation และ Ownership
Revisit ReportRetest scope/date/version พร้อม Finding ID และ Risk เดิมสถานะ Closed, Partially Remediated, Open, Unable to Verify หรือ Risk Accepted; Before/after evidence, bypass results และ residual risk

Gate: ยืนยันข้อเท็จจริง ผู้รับผิดชอบแก้ไข ลำดับความสำคัญ และรายการที่ต้องเข้าสู่ Revisit

Report anatomy

  1. Cover Classification, customer, engagement, version, and date
  2. Executive Summary Business impact at a glance
  3. Scope & ROE Systems, exclusions, access model, and rules
  4. Methodology Standards and coverage matrix
  5. Risk overview Prioritized findings
  6. Finding Details ID, assets, status, risk, CVSS score/vector, evidence, impact, and remediation
  7. Attack chain Relationships between findings
  8. Recommended Solutions Roadmap and remediation ownership
  9. Appendix Evidence and framework traceability

Initial Report and Revisit Report

Initial and post-remediation reporting
ReportCore contentEvidence and outcome
Initial ReportOriginal scope and dates, initial risk snapshot, findings, and recommendationsComplete evidence, remediation, and ownership
Revisit ReportRetest scope/date/version with original finding ID and riskClosed, Partially Remediated, Open, Unable to Verify, or Risk Accepted; before/after evidence, bypass results, and residual risk

Gate: Confirm facts, remediation owners, priorities, and items requiring revisit.

LEGAL & PRIVACY / 01

นโยบายความเป็นส่วนตัว Privacy Policy

ปรับปรุงล่าสุด 13 กรกฎาคม 2026

เราให้ความสำคัญกับการรักษาความเป็นส่วนตัวของผู้เข้าชมเว็บไซต์ นโยบายนี้อธิบายวิธีที่เว็บไซต์ประมวลผลข้อมูลและสิทธิของคุณเกี่ยวกับข้อมูลส่วนบุคคล

ข้อมูลที่เว็บไซต์เก็บรวบรวม

เว็บไซต์นี้ไม่เก็บข้อมูลส่วนบุคคลที่สามารถระบุตัวตนของผู้เข้าชมโดยอัตโนมัติ ข้อมูลที่ผู้ใช้ส่งผ่านแบบฟอร์มขอใบเสนอราคาจะใช้เพื่อประเมินขอบเขตโครงการ จัดทำข้อเสนอ และติดต่อกลับตามความยินยอมที่ผู้ใช้ให้ไว้

คุกกี้ที่เว็บไซต์ใช้

ฟังก์ชัน LINE

วิดเจ็ต LINE เป็นฟังก์ชันจากบุคคลที่สามและจะไม่ถูกโหลดจนกว่าคุณจะอนุญาตคุกกี้ฟังก์ชัน คุณเปลี่ยนหรือถอนความยินยอมได้จากปุ่มตั้งค่าคุกกี้ท้ายหน้า โดยยังใช้ลิงก์ LINE โดยตรงและสแกน QR Code ที่เว็บไซต์จัดเตรียมไว้ได้โดยไม่ต้องโหลดวิดเจ็ต

Cloudflare Web Analytics

เมื่อคุณอนุญาตคุกกี้วัดผล เว็บไซต์จะโหลด Cloudflare Web Analytics เพื่อช่วยให้เราเข้าใจการใช้งานเว็บไซต์ในภาพรวม เราจะไม่โหลดสคริปต์นี้หากคุณเลือกใช้เฉพาะคุกกี้ที่จำเป็น และคุณสามารถเปลี่ยนหรือถอนความยินยอมได้จากปุ่มตั้งค่าคุกกี้ท้ายหน้า อ่านรายละเอียดได้ที่ Cloudflare Privacy Policy

การเพิ่มประสิทธิภาพและรักษาความปลอดภัยเว็บไซต์

เมื่อให้บริการบนระบบ production เราอาจใช้ Cloudflare เพื่อเพิ่มประสิทธิภาพและป้องกันการโจมตี โดย Cloudflare อาจประมวลผลข้อมูลทางเทคนิคหรือวางคุกกี้ที่จำเป็นต่อการให้บริการ อ่านรายละเอียดได้ที่ Cloudflare Privacy Policy

ลิงก์ไปยังเว็บไซต์ภายนอก

เว็บไซต์อาจมีลิงก์ไปยังเว็บไซต์อื่น เมื่อคุณออกจากเว็บไซต์ของเรา เราไม่สามารถควบคุมหรือรับผิดชอบต่อการคุ้มครองข้อมูลของเว็บไซต์ภายนอกได้ โปรดตรวจสอบนโยบายความเป็นส่วนตัวของเว็บไซต์นั้นก่อนให้ข้อมูล

การเปลี่ยนแปลงนโยบาย

เราอาจปรับปรุงนโยบายนี้เป็นครั้งคราว โดยจะแสดงวันที่ปรับปรุงล่าสุดไว้ด้านบน การเปลี่ยนแปลงมีผลเมื่อเผยแพร่บนเว็บไซต์นี้

ข้อมูลติดต่อ

หากมีคำถามเกี่ยวกับนโยบายความเป็นส่วนตัว ติดต่อ privacy@sth.sh

Last updated on July 13, 2026

We are committed to safeguarding and preserving the privacy of our website visitors. This policy explains how the website processes information and informs you of your rights regarding personal data.

Information Collected By Our Website

This website does not automatically collect personally identifiable information from visitors. Information submitted through the quotation form is used to assess project scope, prepare a proposal, and contact the requester under the consent they provide.

Cookies Used By Our Website

LINE Functionality

The third-party LINE widget is not loaded until you allow functional cookies. You can change or withdraw consent from Cookie settings in the footer. The first-party direct LINE link and QR code remain available without loading the widget.

Cloudflare Web Analytics

When you allow analytics cookies, the website loads Cloudflare Web Analytics to help us understand overall site usage. This script is not loaded when you choose essential cookies only, and you can change or withdraw consent from Cookie Settings in the footer. Read the Cloudflare Privacy Policy for details.

Site Optimization And Security

When deployed to production, we may use Cloudflare to optimize and protect the site. Cloudflare may process technical data or place cookies that are necessary to provide these services. Read the Cloudflare Privacy Policy for details.

Third Party Links

Our website may contain links to other websites. Once you leave our site, we do not control and cannot be responsible for how another website protects your information. Please review the privacy statement applicable to that website before providing information.

Changes To This Privacy Policy

We may update this Privacy Policy from time to time. The latest revision date appears at the top of this policy, and changes become effective when they are posted on this website.

Contact Information

If you have questions regarding this privacy policy, contact privacy@sth.sh.

QMS & ISMS / 02

นโยบายคุณภาพและความมั่นคงปลอดภัยสารสนเทศ Quality and Information Security Policy

ปรับปรุงล่าสุด 26 พฤศจิกายน 2025

บริษัท สยามถนัดแฮก จำกัด ผสานการบริหารคุณภาพและความมั่นคงปลอดภัยสารสนเทศไว้ในกระบวนการดำเนินงานหลัก เรามุ่งให้บริการ Cyber Security ที่มีความแม่นยำ พร้อมปกป้องข้อมูลที่ได้รับความไว้วางใจจากลูกค้า

นโยบายคุณภาพ (ISO 9001:2015)

เรามุ่งให้บริการ Penetration Testing และงานที่ปรึกษาที่ถูกต้อง นำไปใช้ได้จริง และเป็นไปตามมาตรฐานวิชาชีพ โดยยึดหลักดังต่อไปนี้

  • ส่งมอบผลการประเมินที่มีหลักฐาน เพื่อให้ลูกค้าระบุและแก้ไขช่องโหว่ได้อย่างแม่นยำ
  • ตอบสนองหรือก้าวเกินความคาดหวังของลูกค้าด้วยการส่งมอบตรงเวลา การสื่อสารชัดเจน และคำปรึกษาจากผู้เชี่ยวชาญ
  • พัฒนาความรู้และทักษะของทีมเทคนิคอย่างต่อเนื่องให้ทันต่อเทคโนโลยีและรูปแบบการโจมตีใหม่
  • ประเมินและปรับปรุงกระบวนการดำเนินงานอย่างต่อเนื่อง เพื่อเพิ่มประสิทธิภาพและคุณภาพบริการ

นโยบายความมั่นคงปลอดภัยสารสนเทศ (ISO/IEC 27001:2022)

เราให้ความสำคัญกับการปกป้องทรัพย์สินสารสนเทศของลูกค้า คู่ค้า และองค์กร โดยควบคุมการรักษาความลับ ความถูกต้องครบถ้วน และความพร้อมใช้งานของข้อมูล

  • ปกป้องทรัพย์สินทางปัญญาและข้อมูลสำคัญจากการเข้าถึง การรั่วไหล หรือการแก้ไขโดยไม่ได้รับอนุญาต
  • ระบุ ประเมิน และจัดการความเสี่ยงที่เกี่ยวข้องกับบุคลากร กระบวนการ และเทคโนโลยีเชิงรุก
  • ดำเนินงานตามกฎหมายที่เกี่ยวข้อง รวมถึงพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล (PDPA) และข้อกำหนดด้าน Cyber Security
  • รักษาแผนตอบสนองเหตุการณ์และความต่อเนื่องทางธุรกิจ เพื่อให้องค์กรพร้อมรับมือเหตุการณ์ด้านความปลอดภัย

การสื่อสารและทบทวนนโยบาย

นโยบายนี้สื่อสารแก่พนักงานและผู้มีส่วนได้ส่วนเสีย และได้รับการทบทวนอย่างน้อยปีละครั้ง เพื่อให้สอดคล้องกับทิศทางองค์กรและภัยคุกคามที่เปลี่ยนแปลง

การรายงานเหตุการณ์ด้านความปลอดภัย

หากพบประเด็นด้านความปลอดภัยในระบบของเรา โปรดรายงานโดยตรงที่ security@sth.sh เราจะตอบรับรายงานภายใน 24 ชั่วโมง

Last updated on November 26, 2025

Siam Thanat Hack Co., Ltd. integrates quality management and information security into the core of our operations. We are dedicated to delivering precision-driven cybersecurity services while safeguarding the data entrusted to us.

Quality Policy (ISO 9001:2015)

We are committed to providing professional penetration testing and consultancy services that are accurate, actionable, and meet the highest professional standards. We adhere to the following principles:

  • Deliver evidence-based security assessments that allow clients to identify and remediate vulnerabilities effectively and precisely.
  • Consistently meet or exceed client expectations through timely delivery, clear communication, and expert consultation.
  • Ensure our technical team maintains industry-leading qualifications and continually updates its skills to match emerging technologies and attack vectors.
  • Continuously evaluate and refine our operational processes to maximize efficiency and service quality.

Information Security Policy (ISO/IEC 27001:2022)

We prioritize the protection of information assets belonging to our clients, partners, and our organization. We enforce controls to ensure the Confidentiality, Integrity, and Availability of data across all operations.

  • Rigorously protect intellectual property and sensitive data from unauthorized access, leakage, or tampering.
  • Proactively identify, evaluate, and mitigate security risks associated with our people, processes, and technology.
  • Operate in accordance with applicable laws, including the Personal Data Protection Act (PDPA), and relevant cybersecurity regulations.
  • Maintain robust incident response and business continuity plans to ensure resilience against security events.

Policy Communication & Review

This policy is communicated to employees and stakeholders to ensure a shared understanding of our standards. It is reviewed at least annually to remain aligned with our strategic direction and the evolving cybersecurity landscape.

Reporting Security Incidents

If you identify a security issue within our systems, report it directly to security@sth.sh. We acknowledge all security reports within 24 hours.

INFORMATION SECURITY MANAGEMENT

ISO/IEC 27001:2022 และ Penetration Testing

มาตรฐานระบบบริหารจัดการความมั่นคงปลอดภัยสารสนเทศ หรือ ISMS สำหรับจัดการความเสี่ยงต่อข้อมูล บุคลากร กระบวนการ และเทคโนโลยีอย่างเป็นระบบ

ข้อกำหนดที่เกี่ยวข้องกับ Penetration Testing

  • ISO/IEC 27001:2022 ไม่ได้กำหนดให้องค์กรทุกแห่งต้องทำ Penetration Testing ตามรอบเวลาตายตัว แต่กำหนดให้ระบุ ประเมิน และจัดการความเสี่ยงด้านความมั่นคงปลอดภัยสารสนเทศอย่างเป็นระบบ
  • Penetration Testing สามารถใช้เป็นวิธีควบคุมและหลักฐานสนับสนุน Annex A 8.8 การจัดการช่องโหว่ทางเทคนิค, A.8.29 การทดสอบความมั่นคงปลอดภัยระหว่างการพัฒนาและการยอมรับระบบ และ A.5.35 การทบทวนความมั่นคงปลอดภัยอย่างเป็นอิสระ
  • ขอบเขตและความถี่ควรกำหนดจากผลประเมินความเสี่ยง ข้อกำหนดทางกฎหมาย หน่วยงานกำกับดูแล สัญญา และความสำคัญของระบบ
  • ผลการทดสอบควรถูกนำเข้าสู่กระบวนการ Risk Treatment การแก้ไข การยอมรับความเสี่ยง และหลักฐานการปรับปรุง ISMS อย่างต่อเนื่อง
ประเด็นสำคัญ

ISO/IEC 27001 เป็นมาตรฐานแบบ risk-based ไม่ใช่รายการ test case การทำ Penetration Testing จึงต้องผูกกับความเสี่ยงและ Statement of Applicability ของแต่ละองค์กร

เปิดข้อมูล ISO/IEC 27001:2022 จาก ISO

WEB APPLICATION RISK AWARENESS

OWASP Top 10 และ Penetration Testing

เอกสารสร้างความตระหนักที่สรุปฉันทามติเกี่ยวกับความเสี่ยงสำคัญต่อ Web Application เพื่อช่วยให้องค์กรจัดลำดับประเด็นที่ควรป้องกันและตรวจสอบ

เวอร์ชันอ้างอิงแยกตามประเภทระบบ

Web Application - OWASP Top 10:2025
Mobile - OWASP Mobile Top 10 2024
API - OWASP API Security Top 10 2023
LLM - OWASP Top 10 for LLM Applications 2025

เกี่ยวข้องกับ Penetration Testing อย่างไร

  • ผู้ทดสอบใช้หมวดเหล่านี้ช่วยวาง coverage และเชื่อมโยง finding กับภาษาความเสี่ยงที่ทีมพัฒนา ผู้บริหาร และผู้ตรวจสอบเข้าใจร่วมกัน
  • OWASP Top 10 ไม่ใช่มาตรฐานการทดสอบหรือ checklist ที่ครอบคลุมทุก test case และไม่ควรใช้แทน methodology ของ Penetration Testing
  • การทดสอบที่ดีควรใช้ OWASP WSTG และ ASVS ร่วมกับการทดสอบ Business Logic, API, Authentication, Authorization และบริบทเฉพาะของระบบ
ประเด็นสำคัญ

การไม่พบช่องโหว่ในหมวด OWASP Top 10 ไม่ได้หมายความว่าระบบไม่มีความเสี่ยง การกำหนด scope และ test cases ต้องอ้างอิง Attack Surface จริงเสมอ

THREAT-INFORMED SECURITY

MITRE ATT&CK® และ Penetration Testing

ฐานความรู้ที่รวบรวมพฤติกรรมของผู้โจมตีที่สังเกตได้ และจัดโครงสร้างเป็น tactics และ techniques เพื่อใช้ภาษาร่วมกันในงานความมั่นคงปลอดภัย

บทบาทในการทดสอบ

  • ATT&CK ช่วยให้ทีมทดสอบเลือกพฤติกรรมผู้โจมตีที่สอดคล้องกับ threat model, attack surface และความสำคัญของระบบ
  • สามารถใช้จัดทำ adversary emulation plan, เชื่อมโยงหลักฐานกับพฤติกรรมการโจมตี และสื่อสารช่องว่างการป้องกัน การตรวจจับ และการตอบสนอง

กำหนด coverage จากความเสี่ยงจริง

  • การ map ผลทดสอบเข้ากับ ATT&CK ช่วยสร้างความเชื่อมโยงย้อนกลับได้ แต่ไม่ได้พิสูจน์ว่าทดสอบครบทุกเทคนิคหรือครอบคลุมความเสี่ยง 100%
  • ขอบเขตต้องพิจารณาบริบทธุรกิจ สถาปัตยกรรม และข้อมูล threat intelligence ที่เกี่ยวข้อง ไม่ใช่เลือก test cases จากตารางเพียงอย่างเดียว
ขอบเขตของกรอบความรู้

ATT&CK เป็นฐานความรู้และแบบจำลองพฤติกรรมผู้โจมตีที่สังเกตได้ ไม่ใช่หน่วยงานกำกับดูแล มาตรฐาน ใบรับรอง หรือ checklist ที่รับประกัน coverage 100%

เปิด MITRE ATT&CK Resources

Role in testing

  • ATT&CK helps testing teams select observed adversary behaviors relevant to the threat model, attack surface, and criticality of the system.
  • It can inform adversary-emulation plans, map evidence to attacker behavior, and communicate gaps across protection, detection, and response.

Derive coverage from actual risk

  • Mapping test results to ATT&CK improves traceability; it does not prove that every technique was tested or that risk coverage is 100%.
  • Scope must reflect business context, architecture, and relevant threat intelligence rather than selecting test cases from the matrix alone.
Knowledge-base boundary

ATT&CK is a knowledge base and model of observed adversary behavior. It is not a regulator, standard, certification, or a 100%-coverage checklist.

Open MITRE ATT&CK Resources

PERSONAL DATA PROTECTION

พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 และ Penetration Testing

มาตรา 37 กำหนดให้ผู้ควบคุมข้อมูลส่วนบุคคลจัดให้มีมาตรการรักษาความมั่นคงปลอดภัยที่เหมาะสม โดย Penetration Testing เป็นวิธีหนึ่งในการตรวจสอบประสิทธิผลของการควบคุมทางเทคนิค

หน้าที่ตามมาตรา 37

  • ผู้ควบคุมข้อมูลส่วนบุคคลต้องมีมาตรการที่เหมาะสม เพื่อป้องกันการสูญหาย เข้าถึง ใช้ เปลี่ยนแปลง แก้ไข หรือเปิดเผยโดยปราศจากอำนาจหรือโดยมิชอบ
  • มาตรการขั้นต่ำต้องมีมาตรการเชิงองค์กรและเชิงเทคนิค และอาจรวมมาตรการทางกายภาพเมื่อจำเป็นตามระดับความเสี่ยง โดยต้องทบทวนเมื่อจำเป็นหรือเมื่อเทคโนโลยีเปลี่ยนแปลง

บทบาทของ Penetration Testing

  • ใช้ทดสอบว่าการควบคุมทางเทคนิคของ Web, Mobile, API, Network และ Cloud สามารถป้องกันการเข้าถึงหรือเปิดเผยข้อมูลโดยมิชอบได้จริงหรือไม่
  • การทดสอบต้องได้รับอนุญาต กำหนดขอบเขตตามความเสี่ยง ลดการเก็บข้อมูลส่วนบุคคลที่ไม่จำเป็น ปกปิดหลักฐาน และกำหนดการเก็บรักษาและลบที่ชัดเจน
ไม่ใช่หลักฐานทั้งหมดของ compliance

มาตรา 37 และประกาศมาตรการรักษาความมั่นคงปลอดภัยไม่ได้กำหนดให้ทำ Penetration Testing ปีละ 1 ครั้ง และผลทดสอบเพียงอย่างเดียวไม่ใช่หลักฐานว่าปฏิบัติตาม PDPA ครบถ้วน

Section 37 duty

  • A data controller must provide appropriate security measures to prevent unauthorized or unlawful loss, access, use, alteration, correction, or disclosure of personal data.
  • Minimum safeguards must include organizational and technical measures and may include physical measures where necessary according to risk. They must be reviewed when necessary or when technology changes.

Role of Penetration Testing

  • Testing can validate whether technical controls across web, mobile, API, network, and cloud environments resist unauthorized access or disclosure in practice.
  • Assessments must be authorized and risk-based, minimize unnecessary personal-data collection, redact evidence, and define secure retention and deletion.
Not complete compliance evidence

The PDPA does not mandate annual Penetration Testing. Section 37 and the security-measures notification require appropriate measures, while testing is one way to validate technical controls; a test report alone is not evidence of complete PDPA compliance.

NATIONAL CYBERSECURITY / RISK & AUDIT

พระราชบัญญัติการรักษาความมั่นคงปลอดภัยไซเบอร์ พ.ศ. 2562 และ Penetration Testing

กฎหมายกำหนดหน้าที่ด้านการประเมินความเสี่ยงและการตรวจสอบด้านความมั่นคงปลอดภัยไซเบอร์ ส่วน Penetration Testing เป็นวิธีและหลักฐานทางเทคนิคที่อาจใช้สนับสนุน ไม่ใช่การตรวจสอบทั้งหมด

หน้าที่ตามพระราชบัญญัติ

  • มาตรา 44 กำหนดให้หน่วยงานของรัฐ หน่วยงานควบคุมหรือกำกับดูแล และหน่วยงานโครงสร้างพื้นฐานสำคัญทางสารสนเทศ (CII) จัดทำประมวลแนวทางปฏิบัติและกรอบมาตรฐาน โดยอย่างน้อยต้องมีแผนการตรวจสอบและประเมินความเสี่ยงด้านการรักษาความมั่นคงปลอดภัยไซเบอร์ประจำปี
  • มาตรา 54 กำหนดให้หน่วยงาน CII จัดให้มีการประเมินความเสี่ยงและการตรวจสอบด้านความมั่นคงปลอดภัยไซเบอร์อย่างน้อยปีละหนึ่งครั้ง และส่งผลสรุปให้สำนักงานคณะกรรมการการรักษาความมั่นคงปลอดภัยไซเบอร์แห่งชาติภายในสามสิบวันนับแต่วันที่ดำเนินการแล้วเสร็จ

บทบาทของ Penetration Testing

  • Penetration Testing เป็นหลักฐานทางเทคนิคที่ช่วยสนับสนุนการประเมินความเสี่ยงและการตรวจสอบ แต่ไม่ใช่การตรวจสอบด้านความมั่นคงปลอดภัยไซเบอร์ทั้งหมด
  • ประมวลแนวทางปฏิบัติและกรอบมาตรฐาน พ.ศ. 2564 ข้อ 21.3.4 และ 21.3.6 ใช้ถ้อยคำเชิงแนะนำให้พิจารณา Penetration Testing ตามความเสี่ยงและความจำเป็น โดยเน้นบริการสำคัญและระบบที่เชื่อมต่ออินเทอร์เน็ต
  • หากดำเนินการ ขอบเขตควรครอบคลุม Host, Network และ Application ที่เกี่ยวข้อง และผู้ทดสอบควรมีความเป็นอิสระจากระบบและกระบวนการที่ถูกทดสอบ
ขอบเขตข้อกำหนด

พระราชบัญญัติไม่ได้กำหนดให้ทุกองค์กรต้องทำ Penetration Testing ทุกปี ต้องแยกหน้าที่ตรวจสอบและประเมินความเสี่ยงตามกฎหมายออกจากวิธีทดสอบทางเทคนิคที่เลือกใช้

Statutory duties

  • Section 44 requires government agencies, regulators or supervisors, and critical information infrastructure (CII) organizations to create a code of practice and standards framework whose minimum content includes an annual cybersecurity inspection and risk-assessment plan.
  • Section 54 specifically requires CII organizations to arrange a cybersecurity risk assessment and cybersecurity audit at least annually, then send a summary to NCSA within thirty days after completion.

Role of Penetration Testing

  • Penetration Testing is technical evidence supporting risk assessment and audit, not the whole audit.
  • Clauses 21.3.4 and 21.3.6 of the B.E. 2564 (2021) Code of Practice use recommendatory risk-and-need wording for Penetration Testing, focusing on critical and Internet-facing services.
  • When performed, scope should cover the relevant host, network, and application layers, and testers should be independent of the systems and processes under assessment.
Requirement boundary

The Act does not require every organization to conduct annual Penetration Testing. Keep the statutory risk-assessment and audit duties distinct from the technical testing method selected to support them.

BANK OF THAILAND / SECURITY ASSESSMENT

แนวปฏิบัติการทดสอบเจาะระบบของธนาคารแห่งประเทศไทย

สรุปข้อกำหนดหลักสำหรับ VA และ Penetration Testing แนวทางรักษาความมั่นคงปลอดภัยของ Mobile Banking และ iPentest โดยเรียงตามความเกี่ยวข้องกับการกำกับดูแล

1. สนช. 1/2564 - ข้อกำหนด VA และ Penetration Testing โดยตรง

  • ข้อ 5.1.6 กำหนดให้ประเมินช่องโหว่ทุกระบบตามระดับความเสี่ยงอย่างน้อยปีละ 1 ครั้ง และเมื่อมีการเปลี่ยนแปลงอย่างมีนัยสำคัญ
  • ต้องทดสอบเจาะระบบโดยผู้เชี่ยวชาญที่มีความเป็นอิสระ ครอบคลุมระบบงานและระบบเครือข่ายที่เชื่อมต่อเครือข่ายสาธารณะ (Internet-facing) อย่างน้อยปีละ 1 ครั้ง และทุกครั้งที่มีการเปลี่ยนแปลงอย่างมีนัยสำคัญ
  • ข้อกำหนดนี้อยู่ในส่วน Cyber Hygiene สำหรับผู้ประกอบธุรกิจระบบและบริการการชำระเงินภายใต้การกำกับตามขอบเขตของประกาศ

2. ธปท.ว.1218/2568 / ประกาศ ธปท. ที่ 4/2568 - Mobile Banking Security

  • ใช้บังคับกับสถาบันการเงินตามกฎหมายว่าด้วยธุรกิจสถาบันการเงินทุกแห่งที่ให้บริการ Mobile Banking ตามนิยามในประกาศ
  • กำหนดมาตรการขั้นต่ำด้าน Mobile Banking เช่น secure protocol และ certificate pinning, anti-tampering, session security, source code obfuscation และการตรวจจับ rooted หรือ jailbroken devices
  • ใช้มาตรการเหล่านี้เป็น control baseline ในการกำหนด scope และ test cases ของ Mobile Application Penetration Testing โดยต้องตรวจสอบเวอร์ชันประกาศและ checklist ที่องค์กรของคุณใช้อยู่

3. iPentest - แนวปฏิบัติเสริมสำหรับการทดสอบแบบ Intelligence-led

  • ใช้ Threat Intelligence สร้างสถานการณ์จำลองและกำหนดขอบเขตให้ครอบคลุม critical functions รวมถึงกระบวนการป้องกัน ตรวจจับ และตอบสนอง
  • เหมาะสำหรับประเมินความพร้อมเชิงลึกเพิ่มเติมจาก VA และ Penetration Testing ตามรอบปกติ โดยควบคุมความเสี่ยง ขอบเขต เวลา และการสื่อสารอย่างรัดกุม
ขอบเขตการใช้บังคับ

เอกสารทั้ง 3 ฉบับมีขอบเขตผู้ถูกกำกับและวัตถุประสงค์ต่างกัน การใช้ผลทดสอบเพื่อยื่นต่อ ธปท. ควรยืนยันประกาศ หนังสือเวียน checklist และรูปแบบรายงานฉบับล่าสุดกับฝ่าย Compliance ขององค์กรก่อนกำหนด scope

SECURITIES AND EXCHANGE COMMISSION

ข้อกำหนดการทดสอบเจาะระบบของสำนักงาน ก.ล.ต.

หลักเกณฑ์ด้านเทคโนโลยีสารสนเทศสำหรับผู้ประกอบธุรกิจภายใต้การกำกับ เพื่อให้ระบบสำคัญได้รับการทดสอบ รายงาน และแก้ไขช่องโหว่อย่างเหมาะสม

ข้อกำหนดหลักด้าน Penetration Testing

  • ระบบงานและระบบเครือข่ายที่เชื่อมต่อกับเครือข่ายสาธารณะต้องทดสอบอย่างน้อยปีละ 1 ครั้ง และทุกครั้งที่มีการเปลี่ยนแปลงอย่างมีนัยสำคัญ
  • ระบบอื่นต้องประเมินความเสี่ยงจากการบุกรุกผ่านเครือข่ายภายใน เพื่อกำหนดขอบเขตและทดสอบตามความเหมาะสม
  • ผู้ทดสอบต้องเป็นผู้เชี่ยวชาญภายในหรือภายนอกที่เป็นอิสระจากเจ้าของระบบและการพัฒนาระบบ การใช้ Scanner เพียงอย่างเดียวเป็น Vulnerability Assessment และไม่สามารถทดแทน Penetration Testing ได้
  • เมื่อพบช่องโหว่ต้องแก้ไขและป้องกันภัยอย่างทันท่วงที เก็บรายงานไม่น้อยกว่า 2 ปี และพร้อมนำส่งสำนักงานเมื่อได้รับการร้องขอ
  • รายงานควรระบุผู้ทดสอบ วันที่ ขอบเขต ช่องโหว่ วิธีที่ใช้ตรวจพบ ระดับความเสี่ยง และแนวทางป้องกันแก้ไข
ขอบเขตการใช้บังคับ

ข้อกำหนดที่ใช้จริงขึ้นอยู่กับประเภทใบอนุญาตและประกาศที่ครอบคลุมผู้ประกอบธุรกิจแต่ละประเภท ควรยืนยันกับ Compliance หรือที่ปรึกษากฎหมายก่อนกำหนด scope

STRICT DISCLOSURE & ETHICS

Confidential & Authorized

ทุกการทดสอบต้องได้รับอนุญาต มีขอบเขตชัดเจน รักษาความลับ และดำเนินการโดยไม่สร้างความเสียหายหรือผลกระทบต่อการดำเนินธุรกิจ

หลักการรักษาความลับและจริยธรรม

  • เริ่มทดสอบเมื่อได้รับหนังสืออนุญาต Scope และ Rules of Engagement ที่ตกลงร่วมกันเท่านั้น ห้ามเข้าถึงระบบ บุคคล หรือข้อมูลนอกขอบเขต
  • จำกัดผู้เข้าถึงข้อมูลลูกค้า Finding และ Evidence ตามหลัก Need-to-know ใช้ช่องทางรับส่งและจัดเก็บที่เข้ารหัส พร้อมกำหนดระยะเวลาเก็บและลบข้อมูล
  • กำหนดช่วงเวลาทดสอบ อัตราการส่งคำขอ Stop Conditions และช่องทางฉุกเฉิน หลีกเลี่ยงการทดสอบแบบทำลาย การแก้ไขข้อมูล และการคง Persistence เว้นแต่ได้รับอนุมัติโดยชัดแจ้ง
  • เก็บหลักฐานเท่าที่จำเป็น ปกปิดข้อมูลส่วนบุคคลและความลับทางธุรกิจ และรายงานเฉพาะผลที่ทำซ้ำและยืนยันได้โดยผู้เชี่ยวชาญ
  • ไม่เปิดเผย ใช้ประโยชน์ หรือส่งต่อข้อมูลและช่องโหว่ของลูกค้าโดยไม่ได้รับอนุญาต รวมถึงควบคุมการใช้ AI โดยมนุษย์และไม่ส่งข้อมูลลูกค้าเข้าสู่บริการ AI สาธารณะ
Safety First

เป้าหมายของ Penetration Testing คือพิสูจน์ความเสี่ยงอย่างปลอดภัยและให้ข้อมูลสำหรับแก้ไข ไม่ใช่สร้างความเสียหาย ขัดขวางบริการ หรือเพิ่มความเสี่ยงให้ธุรกิจ

รายงานช่องโหว่อย่างรับผิดชอบที่ pentest@sth.sh

PAYMENT CARD INDUSTRY DATA SECURITY STANDARD

PCI DSS v4.0.1 และ Penetration Testing

มาตรฐานความมั่นคงปลอดภัยสำหรับองค์กรที่จัดเก็บ ประมวลผล ส่งผ่าน หรืออาจส่งผลต่อความปลอดภัยของข้อมูลบัตรชำระเงิน

ข้อกำหนดที่เกี่ยวข้องกับ Penetration Testing

  • PCI DSS ออกโดย PCI Security Standards Council และใช้กับ Merchant, Acquirer, Issuer, Processor และ Service Provider ที่อยู่ในขอบเขต Cardholder Data Environment (CDE)
  • Requirement 11.4 กำหนดการทดสอบภายในและภายนอกอย่างน้อยทุก 12 เดือน และหลังการอัปเกรดหรือเปลี่ยนแปลงโครงสร้างพื้นฐานหรือแอปพลิเคชันที่มีนัยสำคัญ
  • วิธีทดสอบต้องครอบคลุม Network และ Application layer รวมถึงช่องโหว่และภัยคุกคามที่เกิดขึ้นในช่วง 12 เดือนที่ผ่านมา พร้อมแก้ไขช่องโหว่ที่ใช้โจมตีได้และ Retest เพื่อยืนยันผล
  • หากใช้ Network Segmentation เพื่อลดขอบเขต PCI DSS ต้องทดสอบประสิทธิผลของการแบ่งส่วนตามความถี่และเงื่อนไขที่มาตรฐานกำหนด
ก่อนใช้ยื่น Compliance

ขอบเขต ความถี่ ผู้ทดสอบ และหลักฐานขึ้นอยู่กับประเภทองค์กรและวิธีประเมิน เช่น SAQ หรือ ROC ควรยืนยัน PCI DSS v4.0.1 ฉบับปัจจุบันกับ QSA หรือ Compliance ขององค์กร

เปิด PCI SSC Document Library

Penetration Testing requirements

  • PCI DSS is published by the PCI Security Standards Council and applies to merchants, acquirers, issuers, processors, and service providers within the Cardholder Data Environment (CDE).
  • Requirement 11.4 requires internal and external testing at least once every 12 months and after significant infrastructure or application upgrades or changes.
  • The methodology must address network and application layers, including vulnerabilities and threats experienced during the previous 12 months. Exploitable findings must be corrected and retested.
  • When network segmentation is used to reduce PCI DSS scope, its effectiveness must be tested at the frequency and under the conditions specified by the standard.
Before a compliance submission

Scope, frequency, tester qualification, and evidence depend on the entity and assessment method, such as SAQ or ROC. Confirm the current PCI DSS v4.0.1 text with your QSA or Compliance team.

Open the PCI SSC Document Library

NATIONAL DIGITAL ID

ข้อกำหนด Penetration Testing สำหรับสมาชิก NDID

NDID คือโครงสร้างพื้นฐานสำหรับพิสูจน์และยืนยันตัวตนดิจิทัลที่เชื่อมผู้ให้บริการในบทบาทต่าง ๆ เข้าด้วยกัน

สิ่งที่สมาชิกต้องเตรียมสำหรับ Security Assessment

  • ทดสอบระบบ Application, Web, Network layer และ Operating System ของสมาชิกที่เกี่ยวข้องกับระบบที่เชื่อมต่อกับ NDID Platform โดยไม่รวม NDID Node เว้นแต่เกณฑ์ที่ได้รับระบุเป็นอย่างอื่น
  • เกณฑ์ onboarding ที่ผู้ใช้ให้มาระบุให้ใช้ผู้ทดสอบจากนิติบุคคลภายนอก และแนบหลักฐานคุณสมบัติผู้ทดสอบ เช่น GPEN, eCPPT, OSCP หรือใบรับรองอื่นตามรายการที่ NDID ยอมรับสำหรับบทบาทนั้น
  • แนวทางทดสอบอ้างอิง OSSTMM หรือ NIST SP 800-115 ร่วมกับ OWASP Web/Mobile Testing Guide หรือใช้ PTES/ISSAF ตามเกณฑ์ฉบับที่ NDID ส่งให้สมาชิก
  • Critical, High และ Medium ต้องได้รับการแก้ไข ส่วน Low ต้องแก้ไขหรือบันทึกเหตุผล พร้อม Retest ช่องโหว่ที่แก้ไขแล้ว
  • จัดส่ง Final Penetration Test Report และใบรับรองผู้ทดสอบให้ NDID พิจารณา โดยเกณฑ์ที่ให้มาระบุความถี่อย่างน้อยปีละครั้งและหลัง Significant Change
ยืนยัน Criteria ล่าสุด

รายละเอียดอาจแตกต่างตามบทบาทสมาชิกและ onboarding package ข้อความนี้สรุปจากเกณฑ์ที่ผู้ใช้ให้มา ไม่ใช่เอกสารสาธารณะฉบับควบคุม สมาชิกควรใช้ Criteria ล่าสุดที่ได้รับจาก NDID เป็นหลัก

What members prepare for a security assessment

  • Test the member applications, web systems, network layer, and operating systems involved in the NDID Platform connection. The NDID Node is excluded unless the issued criteria state otherwise.
  • The onboarding criteria supplied by the user call for an external juristic-person testing provider and evidence of tester qualifications such as GPEN, eCPPT, OSCP, or another certification accepted by NDID for the member role.
  • Testing follows OSSTMM or NIST SP 800-115 with the OWASP Web/Mobile Testing Guide, or PTES/ISSAF, according to the criteria issued to the member.
  • Critical, High, and Medium findings must be corrected. Low findings are corrected or supported by a recorded rationale, and corrected vulnerabilities are retested.
  • The member submits the final Penetration Test Report and tester certificate to NDID. The supplied criteria state at least annually and after significant changes.
Confirm the current criteria

Details may differ by member role and onboarding package. This summary reflects the criteria supplied by the user, not a publicly controlled document. Members should follow the latest criteria received from NDID.

BANK OF THAILAND / ELECTRONIC MONEY

ธนาคารแห่งประเทศไทย: e-Money และการทดสอบความปลอดภัย

สนช. 7/2561 กำหนดหลักเกณฑ์สำหรับผู้ประกอบธุรกิจบริการเงินอิเล็กทรอนิกส์ภายใต้พระราชบัญญัติระบบการชำระเงิน

ความเกี่ยวข้องกับ Penetration Testing

  • ใช้กับผู้ประกอบธุรกิจ e-Money ที่ได้รับอนุญาตหรือขึ้นทะเบียนตามกฎหมายว่าด้วยระบบการชำระเงิน
  • ข้อ 4.2.6-4.2.10 เน้นวงเงิน การลงทะเบียนและรับแจ้งสูญหาย การคืนเงิน การตรวจสอบยอดคงเหลือและวันหมดอายุ และการควบคุมการโอนเงินผ่านระบบของผู้ให้บริการ
  • สนช. 7/2561 ไม่ได้กำหนดรอบ Penetration Testing โดยตรง แต่ Flow เหล่านี้ควรถูกนำไปสร้าง Business Logic และ Abuse Case สำหรับการทดสอบ e-Money
  • ข้อกำหนด VA/Penetration Testing โดยตรงสำหรับผู้ประกอบธุรกิจที่อยู่ในขอบเขตมาจากหลักเกณฑ์ IT Risk/Cyber Hygiene ที่ใช้ร่วมกัน เช่น สนช. 1/2564
กำหนด Scope ให้ถูกฉบับ

การถือ e-Money license ไม่ได้ทำให้ทุกข้อใน สนช. 1/2564 ใช้เหมือนกันทั้งหมด ต้องยืนยันประเภทใบอนุญาต ความมีนัยสำคัญ และประกาศฉบับปัจจุบันกับ Compliance ก่อนทดสอบ

เปิดหลักเกณฑ์ e-Money ของ ธปท.

How it relates to Penetration Testing

  • It applies to authorized or registered e-Money operators under the Payment Systems Act.
  • Clauses 4.2.6-4.2.10 address limits, registration and loss reporting, refunds, balance and expiry checks, and control of transfers through the provider's system.
  • SorNorChor. 7/2561 does not directly prescribe a Penetration Testing schedule. These flows should instead inform e-Money business-logic and abuse-case testing.
  • Direct VA/Penetration Testing obligations for in-scope operators arise from applicable IT Risk and Cyber Hygiene rules, such as SorNorChor. 1/2564.
Map the correct rules to scope

Holding an e-Money license does not make every provision of SorNorChor. 1/2564 apply identically. Confirm license type, significance, and the current notifications with Compliance before testing.

Open BOT e-Money regulations

BANK OF THAILAND / CYBER HYGIENE

ธนาคารแห่งประเทศไทย: VA และ Penetration Testing - สนช. 1/2564

ข้อกำหนด Cyber Hygiene โดยตรงสำหรับ Vulnerability Assessment และ Penetration Testing ของผู้ให้บริการและผู้ประกอบธุรกิจตามกฎหมายว่าด้วยระบบการชำระเงินที่อยู่ในขอบเขตของประกาศ

Vulnerability Assessment

  • ข้อ 5.1.6 กำหนดให้ประเมินช่องโหว่ทุกระบบตามระดับความเสี่ยงอย่างน้อยปีละ 1 ครั้ง และเมื่อมีการเปลี่ยนแปลงอย่างมีนัยสำคัญ

Penetration Testing

  • ต้องดำเนินการโดยผู้เชี่ยวชาญที่มีความเป็นอิสระ ครอบคลุมระบบงานและระบบเครือข่ายที่เชื่อมต่อเครือข่ายสาธารณะ อย่างน้อยปีละ 1 ครั้ง และทุกครั้งที่มีการเปลี่ยนแปลงอย่างมีนัยสำคัญ
ขอบเขตการใช้บังคับ

ประกาศใช้กับผู้ให้บริการระบบการชำระเงินที่มีความสำคัญ ผู้ประกอบธุรกิจระบบการชำระเงินภายใต้การกำกับ และผู้ประกอบธุรกิจบริการการชำระเงินภายใต้การกำกับที่มิใช่สถาบันการเงินหรือสถาบันการเงินเฉพาะกิจ ควรยืนยันประเภทใบอนุญาตและประกาศที่มีผลใช้ล่าสุดกับ Compliance

เปิดประกาศ สนช. 1/2564

Vulnerability Assessment

  • Clause 5.1.6 requires vulnerability assessments for all systems according to risk at least annually and after significant changes.

Penetration Testing

  • Independent experts must conduct Penetration Testing of Internet-facing applications and networks at least annually and after every significant change.
Applicability

The notification applies to designated payment-system providers and regulated payment-system or payment-service businesses that are not financial institutions or specialized financial institutions. Confirm the entity's licence and the latest applicable notifications with Compliance.

Open SorNorChor. 1/2564

BANK OF THAILAND / MOBILE BANKING

ธนาคารแห่งประเทศไทย: Mobile Banking Security - ธปท.ว.1218/2568 / ประกาศ ธปท. ที่ 4/2568

มาตรการขั้นต่ำสำหรับ Mobile Banking ที่ใช้เป็น control baseline ของการทดสอบ โดยมีแนวปฏิบัติ Biometric Technology เป็นข้อมูลเสริมเมื่อระบบใช้ชีวมิติ

1. ขอบเขตของประกาศ

  • ธปท.ว.1218/2568 / ประกาศ ธปท. ที่ 4/2568 ใช้กับสถาบันการเงินทุกแห่งที่ให้บริการ Mobile Banking ตามนิยามในประกาศ

2. Mobile Penetration Testing baseline

  • ขอบเขตทดสอบควรครอบคลุม secure protocol และ certificate pinning, anti-tampering, session security, source code obfuscation, rooted/jailbroken device handling และความเสี่ยงจาก remote-control software หรือ malware
  • ทดสอบทั้ง Mobile Application, API/backend, authentication, transaction flow และ fraud/business logic ที่เชื่อมโยงกัน

3. Biometric Technology เป็นแนวปฏิบัติเสริม

  • หากใช้ชีวมิติ ควรตรวจ Trusted Source, Presentation Attack Detection หรือ liveness, การคุ้มครองข้อมูลชีวมิติ และการบริหารความเสี่ยงตลอดวงจร
รอบการทดสอบ

ประกาศ Mobile Banking และแนวปฏิบัติ Biometric เป็น control baseline แต่ไม่ได้กำหนดรอบ Penetration Testing โดยตนเอง ต้องใช้ร่วมกับข้อกำหนด IT Risk ที่ใช้กับองค์กร

1. Notification scope

  • BOT Circular 1218/2568 / Notification 4/2568 applies to all financial institutions providing Mobile Banking as defined by the notification.

2. Mobile Penetration Testing baseline

  • Testing should assess secure protocols and certificate pinning, anti-tampering, session security, source-code obfuscation, rooted or jailbroken device handling, and risks from remote-control software or malware.
  • Assess the connected mobile application, API/backend, authentication, transaction flows, and fraud or business-logic controls together.

3. Biometric Technology as supplemental guidance

  • Where biometrics are used, assess trusted sources, presentation-attack detection or liveness, biometric-data protection, and lifecycle risk management.
Testing cadence

The Mobile Banking notification and Biometric guideline provide a control baseline; they do not independently prescribe a Penetration Testing cadence. Apply the IT Risk requirements governing the organization.

BANK OF THAILAND / INTELLIGENCE-LED TESTING

ธนาคารแห่งประเทศไทย: iPentest - หนังสือเวียน 1252/2562

แนวปฏิบัติ Intelligence-led Penetration Testing หรือ iPentest ที่หนังสือเวียนปี 2562 ส่งถึงธนาคารพาณิชย์ เพื่อประเมินความพร้อมด้านการป้องกัน การตรวจจับ และการตอบสนองต่อภัยไซเบอร์

1. Governance และผู้ทดสอบ

  • กำหนดการกำกับดูแลโดยหน่วยงานที่เกี่ยวข้อง รวมถึง IT Risk Management และ Compliance พร้อมผู้รับผิดชอบและเกณฑ์คัดเลือกผู้ทดสอบที่ชัดเจน

2. Threat-informed scope

  • ใช้ Threat Intelligence สร้างสถานการณ์จำลอง และกำหนดขอบเขตให้ครอบคลุม critical functions บุคลากร และกระบวนการป้องกัน ตรวจจับ และรับมือ

3. การควบคุมความเสี่ยง

  • เน้นการทดสอบบน Production เพื่อสะท้อนสถานการณ์จริง แต่ขั้นตอนที่เสี่ยงสามารถย้ายไป UAT หรือ Pre-production และต้องระบุในรายงาน
  • รักษาขอบเขตและเวลาเป็นความลับ กำหนดมาตรการควบคุมความเสี่ยงและช่องทางสื่อสาร แล้วนำผลไปวางแผนแก้ไข
ขอบเขตการใช้บังคับ

หนังสือเวียนปี 2562 ส่งถึงธนาคารพาณิชย์ โดยกำหนดให้ D-SIBs และธนาคารพาณิชย์ที่มี Cyber Inherent Risk ระดับสูงดำเนินการตามแนวปฏิบัติภายในปี 2563 ส่วนธนาคารพาณิชย์อื่นให้พิจารณาตามความเสี่ยงและความพร้อม ไม่ใช่ข้อกำหนดรายปีสำหรับทุกสถาบันการเงิน

เปิดแนวปฏิบัติ iPentest ของธนาคารแห่งประเทศไทย

1. Governance and testers

  • Establish oversight involving relevant functions, including IT Risk Management and Compliance, with clear owners and tester-selection criteria.

2. Threat-informed scope

  • Use threat intelligence to build realistic scenarios and scope critical functions, people, and the processes used to protect, detect, and respond.

3. Risk controls

  • Prefer production testing for realism, while high-risk steps may move to UAT or pre-production and must be identified in the report.
  • Keep scope and timing confidential, define test-risk controls and communications, and use results for remediation planning.
Applicability

The 2019 circular was addressed to commercial banks. It directed D-SIBs and commercial banks with high Cyber Inherent Risk to implement the guideline by 2020, while other commercial banks considered their risk and readiness. It is not a universal annual requirement for every financial institution.

Open the Bank of Thailand iPentest guideline

SEC / DIGITAL ASSET BUSINESS

ข้อกำหนด Penetration Testing สำหรับธุรกิจสินทรัพย์ดิจิทัล

หลักเกณฑ์ของสำนักงาน ก.ล.ต. สำหรับผู้ประกอบธุรกิจสินทรัพย์ดิจิทัลที่ได้รับใบอนุญาต ไม่ใช่ข้อกำหนดของตลาดหลักทรัพย์แห่งประเทศไทย

ข้อกำหนดโดยตรงสำหรับระบบงานสำคัญ

  • ครอบคลุมผู้ประกอบธุรกิจสินทรัพย์ดิจิทัลตามประเภทใบอนุญาตที่เกี่ยวข้อง เช่น Exchange, Broker, Dealer, Advisory Service และ Fund Manager
  • ข้อ 18 กำหนดให้ทดสอบเจาะระบบงานสำคัญก่อนเริ่มให้บริการ และหลังเริ่มให้บริการอย่างน้อยปีละ 1 ครั้ง โดยบุคคลที่เป็นอิสระจากหน่วยงาน IT ที่รับผิดชอบระบบ
  • ต้องรายงานผลต่อสำนักงาน ก.ล.ต. ภายใน 30 วันนับจากวันที่ได้รับผลอย่างเป็นทางการ และไม่เกิน 90 วันนับจากวันที่สิ้นสุดกระบวนการทดสอบ
  • Scope ต้องเชื่อมกับระบบงานสำคัญจริงของใบอนุญาต เช่น Trading, Wallet/Custody, Customer Portal, API, Infrastructure และระบบสนับสนุนที่มีผลต่อบริการ
หน่วยงานที่ถูกต้องคือ ก.ล.ต.

ธุรกิจสินทรัพย์ดิจิทัลอยู่ภายใต้สำนักงาน ก.ล.ต. ไม่ใช่ SET และรายละเอียดที่ใช้จริงขึ้นกับประเภทใบอนุญาตและประกาศฉบับประมวลล่าสุด

เปิดหลักเกณฑ์ธุรกิจสินทรัพย์ดิจิทัลของ ก.ล.ต.

Direct requirements for critical systems

  • It covers relevant licensed digital-asset business types, including exchanges, brokers, dealers, advisory services, and fund managers.
  • Clause 18 requires Penetration Testing of critical systems before service commencement and at least annually after commencement, performed by a person independent of the IT unit responsible for the systems.
  • Results must be reported to the SEC within 30 days of receiving the official result and no later than 90 days after the testing process ends.
  • Scope should reflect the license's actual critical systems, such as trading, wallet or custody, customer portals, APIs, infrastructure, and supporting systems affecting the service.
The regulator is the SEC

Digital-asset businesses are regulated by the Thai SEC, not the Stock Exchange of Thailand. Applicable details depend on license type and the latest consolidated rules.

Open the SEC digital-asset business rules

NCSA / WEBSITE SECURITY STANDARD

NCSA Website Security Standard พ.ศ. 2568

มาตรฐานการรักษาความมั่นคงปลอดภัยสำหรับเว็บไซต์ ครอบคลุม Governance และ Security Operation ของเว็บไซต์ทุกสถาปัตยกรรม

ใครต้องทำและ Penetration Testing เกี่ยวข้องอย่างไร

  • ใช้บังคับกับหน่วยงานของรัฐ หน่วยงานควบคุมหรือกำกับดูแล และหน่วยงานโครงสร้างพื้นฐานสำคัญทางสารสนเทศ (CII) ส่วนเอกชนทั่วไปได้รับการส่งเสริมให้นำไปใช้
  • ประกาศลงวันที่ 16 กันยายน 2568 และมีผลเมื่อพ้นหนึ่งปี จึงมีผลวันที่ 16 กันยายน 2569
  • หน่วยงานในขอบเขตต้องประเมินตนเองตามแบบ ค๑ อย่างน้อยปีละ 1 ครั้ง ประเมินระดับผลกระทบ รายงานตามระดับ และจัดทำแผนแก้ไขแบบ ค๒ เมื่อไม่สอดคล้อง
  • มาตรฐานไม่ได้ทำให้การประเมินตนเองกลายเป็นข้อบังคับ Penetration Testing รายปีโดยอัตโนมัติ แต่ Penetration Testing เป็นหลักฐานเชิงเทคนิคเพื่อพิสูจน์ Website Security Operation และช่องโหว่ที่โจมตีได้จริง
เลือก Scope จาก Impact

Scope ควรครอบคลุม Web Application, Web Server, Database และ Cloud หรือ Web Hosting ที่เกี่ยวข้อง ตามสถาปัตยกรรมและระดับผลกระทบของเว็บไซต์ ไม่ใช่ตรวจเฉพาะหน้าเว็บ

เปิดมาตรฐานเว็บไซต์จากราชกิจจานุเบกษา

Who is in scope and how Penetration Testing supports it

  • It applies to government agencies, regulatory or supervisory bodies, and Critical Information Infrastructure organizations. General private-sector adoption is encouraged.
  • The notification was issued on 16 September 2025 and takes effect after one year, on 16 September 2026.
  • In-scope organizations perform the Kor 1 self-assessment at least annually, determine impact level, report accordingly, and create a Kor 2 remediation plan for gaps.
  • The standard does not automatically turn the annual self-assessment into a blanket annual Penetration Testing requirement. Penetration Testing provides technical evidence for Website Security Operation and exploitable-vulnerability validation.
Derive scope from impact

Scope should cover the web application, web server, database, and relevant cloud or web-hosting components according to the architecture and website impact level, rather than testing only the public pages.

Open the Website Security Standard in the Royal Gazette

OFFICE OF INSURANCE COMMISSION / IT RISK

สำนักงานคณะกรรมการกำกับและส่งเสริมการประกอบธุรกิจประกันภัย

IT Risk พ.ศ. 2563 กำหนดหลักเกณฑ์การกำกับดูแลและบริหารจัดการความเสี่ยงด้านเทคโนโลยีสารสนเทศสำหรับบริษัทประกันชีวิตและบริษัทประกันวินาศภัย

Risk-based evidence ไม่ใช่ข้อบังคับ Pentest แบบตายตัว

  • ใช้กับบริษัทประกันภัยที่อยู่ภายใต้การกำกับของสำนักงาน คปภ. เพื่อให้มี Governance, Information Asset Management, IT Risk Management และ Cybersecurity controls ที่เหมาะสม
  • ประกาศหลักไม่ได้กำหนดรูปแบบหรือความถี่ของ Penetration Testing โดยตรง และไม่ได้บังคับว่าจะต้องเป็น Black-box, Grey-box หรือ White-box
  • Penetration Testing สามารถใช้เป็นหลักฐานเชิงเทคนิคเพื่อประเมินประสิทธิผลของมาตรการควบคุมและความเสี่ยงที่โจมตีได้จริง โดยเลือก Scope จาก Information Asset Inventory และผล Risk Assessment
  • ระบบที่ควรพิจารณาตามความเสี่ยง ได้แก่ Core Insurance Systems, Customer/Agent Portals, Mobile Applications, APIs, External-facing systems และ Infrastructure ที่จัดเก็บข้อมูลสำคัญ
ประโยชน์ต่อการบริหารความเสี่ยง

Penetration Testing ช่วยให้องค์กรมีหลักฐานที่ตรวจสอบได้สำหรับการบริหารความเสี่ยงด้านเทคโนโลยีสารสนเทศ และประเมินประสิทธิผลของมาตรการควบคุม โดยขอบเขตและรอบการทดสอบควรกำหนดตามความเสี่ยงของระบบและข้อกำหนดที่ใช้กับองค์กรของคุณ

Risk-based evidence, not a fixed Penetration Testing mandate

  • It applies to insurance companies supervised by the Office of Insurance Commission and establishes expectations for governance, information-asset management, IT risk management, and cybersecurity controls.
  • The principal notification does not directly prescribe a Penetration Testing method or frequency, nor does it mandate black-box, grey-box, or white-box testing.
  • Penetration Testing can provide technical evidence of control effectiveness and exploitable risk, with scope derived from the information-asset inventory and risk assessment.
  • Risk-based candidates include core insurance systems, customer and agent portals, mobile applications, APIs, external-facing systems, and infrastructure holding sensitive data.
Accurate customer wording

State that Penetration Testing supports IT Risk management and control validation. Do not claim the OIC mandates annual Penetration Testing unless another requirement applicable to that insurer does so.

OFFICIAL CREST REGISTRY

ตรวจสอบ CREST Pathway Plus

รู้จัก CREST ความหมายของสถานะ Pathway+ และเหตุผลที่ช่วยเพิ่มความมั่นใจ เมื่อเลือก STH เป็นผู้ให้บริการ Penetration Testing

CREST Pathway Plus
องค์กรในทะเบียน Pathway+ Siam Thanat Hack

CREST คือองค์กรสมาชิกไม่แสวงหากำไรระดับนานาชาติที่กำหนดและยกระดับมาตรฐาน ของผู้ให้บริการและผู้เชี่ยวชาญด้าน Cyber Security เพื่อสร้างความเชื่อมั่นให้ผู้ซื้อบริการ หน่วยงานรัฐ และหน่วยงานกำกับดูแล

CREST Pathway+ คือสถานะสำหรับองค์กรที่ผ่านขั้น Pathway และจัดทำการประเมินความพร้อม เทียบกับข้อกำหนดองค์กรของ CREST ในสาขาบริการ Security Assessment ซึ่งรวมถึงการทำ Penetration Testing และ Vulnerability Assessment เพื่อวัดความพร้อมและระบุช่องว่างในการพัฒนาคุณภาพ

การที่ STH ได้รับสถานะ Pathway+ และมีชื่ออยู่ในทะเบียนทางการของ CREST แสดงถึงกระบวนการพัฒนาคุณภาพที่เป็นระบบ การยึดหลักจรรยาบรรณ และความมุ่งมั่นยกระดับการกำกับดูแล วิธีการทำงาน และการคุ้มครองข้อมูลตามมาตรฐานสากล ลูกค้าจึงมีข้อมูลอ้างอิงที่โปร่งใสมากขึ้นเมื่อพิจารณาผู้ให้บริการ Penetration Testing

เปิดทะเบียน CREST ตรง Siam Thanat Hack

STH BRAND ASSETS

ดาวน์โหลดโลโก้ STH

เลือกเวอร์ชันที่เหมาะกับพื้นหลัง และดาวน์โหลดไฟล์ PNG ต้นฉบับไปใช้งาน

PROJECT INTAKE

ขอใบเสนอราคา Pentest

ส่งข้อมูลระบบ ขอบเขตบริการ และช่วงเวลาที่ต้องการ เพื่อให้ทีม STH ประเมินโครงการและติดต่อกลับ

01

Contact details

02 Services

03

Project Scope

04

วันที่ต้องการรับบริการ

CERTIFICATE / PDF PREVIEW

ISO/IEC 27001:2022

ใบรับรองระบบบริหารจัดการความมั่นคงปลอดภัยสารสนเทศของ Siam Thanat Hack

CERTIFICATE / PDF PREVIEW

ISO 9001:2015

ใบรับรองระบบบริหารงานคุณภาพของ Siam Thanat Hack

COMPANY CERTIFICATE / PDF PREVIEW

หนังสือรับรองบริษัท

หนังสือรับรองนิติบุคคลของ Siam Thanat Hack ฉบับภาษาไทยและภาษาอังกฤษ

VAT REGISTRATION / PDF PREVIEW

ทะเบียนภาษีมูลค่าเพิ่ม (ภ.พ.20)

สำเนาทะเบียนภาษีมูลค่าเพิ่มของสำนักงานใหญ่และสาขา 1

SME-GP / PDF PREVIEW

ทะเบียนผู้ประกอบการ SME-GP

หนังสือรับรองการขึ้นทะเบียนผู้ประกอบการ SME เพื่อการจัดซื้อจัดจ้างภาครัฐ

CERTIFICATE / PDF PREVIEW

ทะเบียนที่ปรึกษา

หนังสือรับรองการขึ้นทะเบียนที่ปรึกษากับศูนย์ข้อมูลที่ปรึกษา กระทรวงการคลัง

AWARD / PDF PREVIEW

Prime Minister Awards 2024

Thailand Cybersecurity Excellence Award 2024 - Contribution Award

AWARD / PDF PREVIEW

Prime Minister Awards 2025

Thailand Cybersecurity Excellence Awards 2025 - Best Performance Awards