Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert

What is Pentest (penetration testing)?

DefinitionA pentest, or penetration test, is an authorized, simulated attack with a defined scope in which specialists try to exploit flaws in applications, networks or cloud environments to prove what a real attacker could achieve.

How it works

A pentest starts with an agreed scope and rules of engagement: which assets will be tested, in which time windows, what is forbidden and whom to call if something goes wrong. Then come reconnaissance, vulnerability identification, exploitation attempts, privilege escalation and reporting. The NIST SP 800-115 technical guide describes these phases and treats penetration testing as the way to validate whether a flaw exists and what its impact is.

Depending on the information given to the tester, a pentest can be:

  • Black box: no internal information, like an external attacker.
  • Gray box: partial information, such as the credentials of a regular user.
  • White box: broad access to architecture, configurations and sometimes source code.

Pentest vs vulnerability scan

A scan is an automated sweep that compares versions and configurations against databases of known flaws. It provides breadth and frequency, but it produces false positives and barely sees business logic or authorization flaws. A pentest is driven by people: it validates whether a flaw is exploitable and chains small weaknesses together to show the real impact. One does not replace the other.

In practice

A pentest makes the most sense before or right after launching an application, migrating to the cloud or making a significant network change, and when there is a regulatory or contractual requirement, as in PCI DSS. A good report ranks findings by impact, includes evidence and remediation advice, and is followed by a retest to confirm the flaws were closed.

Network Secure performs penetration tests on applications, networks and cloud environments.

Frequently asked questions

What is the difference between a pentest and a Red Team?

A pentest seeks to find and prove as many exploitable flaws as possible within a defined scope, usually with the defenders aware. A Red Team simulates an adversary against the whole organization, covertly, to test whether the defense detects and contains the attack.

How often should you run a pentest?

Periodically and always after significant changes, such as a new application or a cloud migration. PCI DSS, for example, requires a pentest at least every 12 months and after significant changes.

Go deeper