Skip to content
Thornbury Labs
Authorised testing only. We test with your written authorisation, so scope and rules are agreed before testing begins. Testing is delivered by vetted third-party practitioners, and we do not describe our work as certified.

Testing approach

Grey box penetration testing: the practical middle ground

Grey box penetration testing gives the tester partial knowledge, usually test accounts and some documentation. So it mirrors an attacker who has stolen a login, which is how many real breaches begin.

  • Fixed fee before we start
  • Named tester in writing
  • Retest and attestation letter
Grey box penetration testing: provide accounts, test as each role and report access gaps

Why grey box penetration testing is the default for apps

Most application risk sits behind the login. Therefore a tester without accounts spends days just getting in, while a grey box tester starts testing immediately. Also, it reflects reality, since stolen credentials are a common way in. So the test mirrors how many real incidents start, rather than an idealised outsider.

What you provide for grey box penetration testing

You share enough to save discovery time, but not everything. That keeps the test realistic while still efficient.

  • Test accounts for each user role
  • A short description of key features
  • API documentation, if you have it
  • The list of out-of-scope areas

Grey box penetration testing readiness

Tick what you can prepare. Accounts matter most.

Your result appears here as you tick, so you can see what is still open.

How it compares with the other approaches

Each approach answers a slightly different question. So pick by the question you need answered.

ApproachQuestion it answers
Black boxWhat can a stranger find?
Grey boxWhat can a logged-in user, or a stolen account, reach?
White boxWhat weaknesses exist anywhere in the design?

Grey box penetration testing and your budget

Because discovery is shorter, more of the manual hours go into real testing. As a result, the Essential and Standard packages usually deliver the best coverage this way.

What auditors make of it

Auditors and enterprise customers generally prefer authenticated testing for applications, because that is where customer data lives. The report states the access given, so they can judge the depth. Severity follows the FIRST CVSS specification.

Grey box penetration testing questions

Why is grey box penetration testing so common?

Because it balances realism and depth. Testers start behind the login, so hours go into testing.

Do you need source code?

No. That would make it white box, which is a different choice.

Is grey box penetration testing enough for SOC 2?

For applications, it is the usual approach auditors expect.

Can we mix approaches?

Yes. For example, black box on the perimeter and grey box on the app.

Related guides

Book grey box penetration testing at a fixed fee

Send the roles and features. We reply with a fixed fee and stated hours, so you know what is covered.

Get my fixed-fee quote