Testing approach
Grey box penetration testing: the practical middle ground
Grey box penetration testing gives the tester partial knowledge, usually test accounts and some documentation. So it mirrors an attacker who has stolen a login, which is how many real breaches begin.
- Fixed fee before we start
- Named tester in writing
- Retest and attestation letter
Why grey box penetration testing is the default for apps
Most application risk sits behind the login. Therefore a tester without accounts spends days just getting in, while a grey box tester starts testing immediately. Also, it reflects reality, since stolen credentials are a common way in. So the test mirrors how many real incidents start, rather than an idealised outsider.
What you provide for grey box penetration testing
You share enough to save discovery time, but not everything. That keeps the test realistic while still efficient.
- Test accounts for each user role
- A short description of key features
- API documentation, if you have it
- The list of out-of-scope areas
Grey box penetration testing readiness
Tick what you can prepare. Accounts matter most.
Your result appears here as you tick, so you can see what is still open.
How it compares with the other approaches
Each approach answers a slightly different question. So pick by the question you need answered.
| Approach | Question it answers |
|---|---|
| Black box | What can a stranger find? |
| Grey box | What can a logged-in user, or a stolen account, reach? |
| White box | What weaknesses exist anywhere in the design? |
Grey box penetration testing and your budget
Because discovery is shorter, more of the manual hours go into real testing. As a result, the Essential and Standard packages usually deliver the best coverage this way.
What auditors make of it
Auditors and enterprise customers generally prefer authenticated testing for applications, because that is where customer data lives. The report states the access given, so they can judge the depth. Severity follows the FIRST CVSS specification.
Grey box penetration testing questions
Why is grey box penetration testing so common?
Because it balances realism and depth. Testers start behind the login, so hours go into testing.
Do you need source code?
No. That would make it white box, which is a different choice.
Is grey box penetration testing enough for SOC 2?
For applications, it is the usual approach auditors expect.
Can we mix approaches?
Yes. For example, black box on the perimeter and grey box on the app.
Related guides
Book grey box penetration testing at a fixed fee
Send the roles and features. We reply with a fixed fee and stated hours, so you know what is covered.
Get my fixed-fee quote