Penetration Testing
An authorised, simulated attack on a system, application or network in which testers attempt to exploit vulnerabilities, showing how an attacker could gain access and what impact each weakness would have.
A penetration test goes beyond listing potential weaknesses: qualified testers attempt to exploit them, chain them together and demonstrate impact within an agreed scope and rules of engagement. Engagements usually move through planning, reconnaissance, scanning and enumeration, exploitation, post-exploitation and reporting. Tests are described by how much information testers receive: black box with no internal knowledge, white box with full access to documentation or source code, and grey box with partial knowledge such as user credentials.
Organisations commission penetration tests before major releases, after significant changes, to meet contractual or regulatory expectations and to check that existing controls work. Common targets include web and mobile applications, APIs, internal and external networks, cloud configurations and wireless networks, while social engineering tests assess how staff respond. PCI DSS, for example, requires regular internal and external penetration testing of environments that handle payment card data.
A test reflects a system at one point in time and only within its scope, so it complements rather than replaces continuous vulnerability management. Written authorisation is essential, and production systems, especially industrial control systems, need careful planning to avoid disruption. Widely used methodologies include NIST SP 800-115, the OWASP Web Security Testing Guide and the Penetration Testing Execution Standard (PTES).
Key points
- Testers actively exploit weaknesses to demonstrate real impact within an agreed scope.
- Black, white and grey box tests differ in how much information testers receive.
- Written authorisation and rules of engagement are prerequisites for any test.
- Results are point-in-time and complement continuous vulnerability management.
Where AiVibe comes in
AiVibe's security services include vulnerability assessment and penetration testing in black, white, grey box and API formats.
Related terms
- Vulnerability Assessment and Penetration Testing (VAPT)Cybersecurity & Compliance
- Vulnerability ManagementCybersecurity & Compliance
- OWASP Top 10Cybersecurity & Compliance
- API SecurityCybersecurity & Compliance
- Payment Card Industry Data Security Standard (PCI DSS)Cybersecurity & Compliance
- Dynamic Application Security Testing (DAST)Cybersecurity & Compliance