Testing approach
Black box penetration testing: the outsider's view
Black box penetration testing gives the tester no inside information: no credentials, no documentation and no source code. So it shows what a real outsider could find, but it spends time on discovery.
- Fixed fee before we start
- Named tester in writing
- Retest and attestation letter
What black box penetration testing simulates
The tester knows only your company name, domain or app address. Therefore they behave like an opportunistic attacker who found you online. That is realistic for your internet edge.
Where black box penetration testing fits
It fits external tests well. For example, it answers the question "what can a stranger reach from the internet" honestly.
- External network and perimeter tests
- Public websites without a login
- Checking what is exposed by accident
Is black box penetration testing the right fit?
Tick what applies. Several ticks suggest black box suits this scope.
Your result appears here as you tick, so you can see what is still open.
What it costs you in coverage
Time spent discovering things you could simply tell the tester is time not spent testing. So for applications with logins, black box work often covers less ground for the same fee.
| Approach | Inside knowledge | Typical use |
|---|---|---|
| Black box | None. | External edge, outsider view. |
| Grey box | Test accounts and some documentation. | Most application tests. |
| White box | Full access, including code. | Deep reviews of critical systems. |
Black box penetration testing and audits
Auditors care that the scope was tested thoroughly, not that the tester started blind. Therefore a grey box approach is often better evidence for an application. However, black box remains the natural choice for the perimeter.
How we scope it
We confirm in writing what the tester may and may not use, even when they start blind. Also, scope still lists the assets you own, because we only test what you authorise. Method follows NIST SP 800-115.
Black box penetration testing questions
Is black box penetration testing more realistic?
For the perimeter, yes. For applications, however, real attackers often obtain accounts, so grey box is closer to reality.
Does it cost more?
Not usually, but it covers less depth for the same hours because discovery takes time.
Will auditors accept black box penetration testing?
Yes, if the scope fits. Still, for apps, many prefer tests with authenticated access.
Do you still need our authorisation?
Always, because we only test assets you own or control.
Related guides
Scope black box penetration testing for your edge
Send the domains and ranges you own. We reply with a fixed fee, and testing starts only after you sign the authorisation.
Get my fixed-fee quote