Securing Salesforce: Pentesting and Config Review.
Cloud & SaaS
Salesforce

Key Takeaways
- The components you are actually testing: Lightning components, Apex classes and controllers, Visualforce, Salesforce objects and fields, and SOQL.
- How to build your own Lightning app, public site and Lightning Web Component, so you can practise the techniques without touching a client org.
- The 3 access control layers and where each one fails: record level, field level and object level security.
- Config review using the tools Salesforce already gives you: Portal Health Checkup, Health Check, guest user sharing rule access, and Salesforce Optimizer.
What's inside
Salesforce is the most widely deployed CRM, which makes it a standing target for anyone after personally identifiable information, lifestyle data or behavioural data. The uncomfortable part is that a large share of real Salesforce exposure comes from sharing rules and guest user permissions, not from an exploitable bug in code.
This guide covers both halves. The first is a working introduction to how a Salesforce app is built and how to pentest it, including access control testing and SOQL. The second is the configuration review: what to check, in what order, and which built-in tools surface it.
What the 59 pages cover
Look inside













