Contact

What is Penetration Testing?

Definition

Penetration testing (pentesting) is an authorised exercise in which security specialists look for vulnerabilities in a system, web application or network using the techniques a real attacker would, within a scope agreed in writing beforehand. The goal is to find weaknesses, demonstrate whether and how they can be exploited, and report them with remediation advice. Unlike automated vulnerability scanning, it verifies findings by hand and chains them together.

Also known as: penetration test, pentest, pen test, pentesting, ethical hacking

Timeline of an authorised penetration test: scoping, reconnaissance, testing, reporting with risk ratings and retesting after fixes

Not the same as a vulnerability scan

Vulnerability scanPenetration test
MethodAutomated toolsTools plus manual expert analysis
FocusBreadth: known signaturesDepth: business logic, access control, chaining
False positivesCommonFindings are verified before reporting
CadenceContinuous or weeklyPeriodic and after major changes

A scanner quickly spots an outdated library or a missing header. It takes a person who understands what the application is supposed to do to notice that user A can read user B's invoice by changing an order number in the URL, a classic authorization flaw. The real value of a pentest is showing how several findings that look minor on their own combine into serious impact.

Scope and written authorisation

Authorisation is what separates a penetration test from an attack. Attempting to access systems without the owner's written permission can be a criminal offence in most jurisdictions, whatever the intent. Before testing starts, a rules-of-engagement document settles:

  • the domains, IP ranges, applications and APIs in scope, and what is explicitly out of scope
  • staging or production, and permitted testing windows
  • whether techniques such as denial of service or social engineering are allowed
  • who to alert, and how, if a critical issue turns up mid-test
  • how personal and confidential data encountered during testing is handled

Hosting, CDN and cloud providers have their own testing policies, so when infrastructure belongs to a third party, their rules shape the scope as well.

How much the testers know

  • Black box: testers get only the address, mimicking an outside attacker, but spend part of the budget on reconnaissance.
  • Grey box: test accounts for different roles and basic documentation are provided; usually the most efficient balance for web applications.
  • White box: source code, architecture and configuration are shared, giving the most coverage for the time spent.

Web application tests commonly follow the OWASP Web Security Testing Guide as their methodology and map findings to OWASP Top 10 categories.

What a good report contains

  1. An executive summary for non-technical readers: overall risk and the top three issues.
  2. For each finding: a description, the affected URL or component, a severity rating (often CVSS) and the business impact.
  3. Enough evidence to reproduce it: request and response samples, screenshots.
  4. Concrete remediation advice rather than a generic “validate input”.
  5. The outcome of a retest once fixes are in.

The real deliverable is fixed vulnerabilities. If findings never make it into the issue tracker with an owner, the test ends up as a PDF in a folder.

When and how often

Common triggers are a new product's launch, changes to critical flows such as payments or authentication, and a regular schedule. Standards such as PCI DSS require periodic penetration testing for systems that handle card data. A pentest is a snapshot: a deployment the next day can introduce a new flaw. It works best alongside secure coding practices, dependency monitoring and continuous scanning.

Related terms

← Back to the glossary