Skip to content
Thornbury Labs
Authorised testing only. We test with your written authorisation, so scope and rules are agreed before testing begins. Testing is delivered by vetted third-party practitioners, and we do not describe our work as certified.

Testing approach

Black box penetration testing: the outsider's view

Black box penetration testing gives the tester no inside information: no credentials, no documentation and no source code. So it shows what a real outsider could find, but it spends time on discovery.

  • Fixed fee before we start
  • Named tester in writing
  • Retest and attestation letter
Black box penetration testing: start blind, discover and probe and report outsider risk

What black box penetration testing simulates

The tester knows only your company name, domain or app address. Therefore they behave like an opportunistic attacker who found you online. That is realistic for your internet edge.

Where black box penetration testing fits

It fits external tests well. For example, it answers the question "what can a stranger reach from the internet" honestly.

  • External network and perimeter tests
  • Public websites without a login
  • Checking what is exposed by accident

Is black box penetration testing the right fit?

Tick what applies. Several ticks suggest black box suits this scope.

Your result appears here as you tick, so you can see what is still open.

What it costs you in coverage

Time spent discovering things you could simply tell the tester is time not spent testing. So for applications with logins, black box work often covers less ground for the same fee.

ApproachInside knowledgeTypical use
Black boxNone.External edge, outsider view.
Grey boxTest accounts and some documentation.Most application tests.
White boxFull access, including code.Deep reviews of critical systems.

Black box penetration testing and audits

Auditors care that the scope was tested thoroughly, not that the tester started blind. Therefore a grey box approach is often better evidence for an application. However, black box remains the natural choice for the perimeter.

How we scope it

We confirm in writing what the tester may and may not use, even when they start blind. Also, scope still lists the assets you own, because we only test what you authorise. Method follows NIST SP 800-115.

Black box penetration testing questions

Is black box penetration testing more realistic?

For the perimeter, yes. For applications, however, real attackers often obtain accounts, so grey box is closer to reality.

Does it cost more?

Not usually, but it covers less depth for the same hours because discovery takes time.

Will auditors accept black box penetration testing?

Yes, if the scope fits. Still, for apps, many prefer tests with authenticated access.

Do you still need our authorisation?

Always, because we only test assets you own or control.

Related guides

Scope black box penetration testing for your edge

Send the domains and ranges you own. We reply with a fixed fee, and testing starts only after you sign the authorisation.

Get my fixed-fee quote