Kiosk and Desktop Breakout Testing

Breakout testing examines whether a user can escape the restrictions of a kiosk, locked-down desktop or virtual session. ProCheckUp tests the controls that separate the permitted task from the operating system, local data and connected services.

Scope a breakout assessment with a description of the build and what a normal user should be allowed to do.

Choose the environment and user perspective

  • Kiosks and restricted applications: assess whether the intended task can lead to commands, files, settings or other applications.

  • Locked-down desktops: examine permitted user actions, local permissions and relevant hardening controls.

  • Citrix and remote desktop sessions: test the boundaries of published applications, session permissions and the resources available to the user.

  • Connected systems: define whether testing can extend beyond the session or host. Wider network pivoting needs explicit authorisation.

A related build review

Our Windows 11 and Azure Virtual Desktop case study examined a physical laptop and a virtual desktop from agreed user and simulated elevated-access perspectives. It illustrates build and permission testing; it is not presented as a Citrix engagement.

What the assessment examines

  • Routes out of the restricted application into the operating system, command execution or unapproved programs.

  • Access to local files, configuration, stored credentials and security settings.

  • User privilege boundaries and the impact of excessive permissions or insecure applications.

  • Authentication and relevant remote-session controls.

  • Connected resources or traffic only where included in the agreed scope.

Agree the testing approach

Testing can begin with limited prior knowledge, supplied user credentials or supporting build and configuration information. The chosen perspective should match the question: what can a visitor, ordinary employee or another agreed user actually reach?

Provide a representative build and user account. Identify physical access, peripherals, session types and restrictions that must remain effective. Agree the testing window, excluded systems, permitted techniques and contact for pausing work if the environment is affected.

A breakout assessment is focused on the restrictions of the agreed environment. Threat-led red teaming, persistence, data extraction and broader attack simulation require their own objectives and authorisation; they are not implied by a kiosk or desktop test.

Reporting and hardening verification

The report should show which restriction was bypassed, the access obtained, the evidence and the resulting risk. Practical hardening recommendations help the team responsible for the build address the finding. Record any limits or areas that could not be tested.

Discuss retesting of relevant changes, the environment and roles to be checked, and the associated terms. Build variants, user roles, session types and access arrangements affect scope, effort and timing.

Related services

Scope a breakout assessment

Scope a breakout assessment. Tell us the kiosk, desktop or virtual-session technology, user roles and intended restrictions. We can discuss representative builds, access and reporting.

Need Help?

If you have any questions about cyber security or would like a free consultation, don't hesitate to give us a call!

Our Services

Keep up to date!


For More Information Please Contact Us

Smiling Person

ACCREDITATIONS