Cyrex partnered with Bethesda to conduct grey box penetration testing for DOOM Eternal, securing backend live services including matchmaking, account management, and session controls to reinforce server-side security.
DOOM Eternal, developed by id Software and published by Bethesda Softworks, launched to critical acclaim and significant global adoption. As a large-scale AAA title with online components, protecting backend services was essential to maintaining player trust and operational stability.
The scope focused on non-gameplay backend systems responsible for:
Vulnerabilities in these areas could impact player progression, account integrity, and platform reputation. Bethesda required structured security validation to ensure server-side controls were robust before and after launch.
Cyrex conducted comprehensive grey box penetration testing, combining architectural awareness with real-world attack simulation.
Our objective was to validate the integrity of server-side security controls and identify weaknesses that could be exploited by malicious actors.
The engagement included structured testing of:
We simulated attacker behavior to evaluate access control enforcement, session validation, and business logic protections within backend services.
During testing, Cyrex identified multiple vulnerabilities ranging in severity from low-priority issues to findings deemed critical by Bethesda.
We delivered:
Following remediation, Cyrex conducted structured sanity and regression testing to confirm that vulnerabilities were resolved and no additional issues were introduced.
Your launch is months away. Hackers will find exploits in hours. Let our engineers secure your game before it's too late.
Response time: <24 hours • NDA included • No commitment required