Penetration Test Types
- What Angle do you need? -
The 3 Types - A Monochromatic Spectrum
Black Box - The Mystery Mission
- What is it? - You know nothing of the system - no passwords, no internal workings, you've got nothing
- The Goal? - Simulate real world attacks from the perspective of a hacker!
- Usefulness? - The ultimate, realistic test on how exposed your system is to unknown dangers
" Think of it as sneaking into a highly secure fortress without any blueprints or inside info; or trying to crack a safe with just instincts - That's Black Box pentesting! "
Grey Box - The Double Cross
- What is it? - You have partial knowledge - A glimpse of the network, maybe a password or two
- The Goal? - See what damage someone with limited access can do
- Usefulness? - A perfect balance between realism and depth, you never know when a disgruntled employee can strike!
" Running a top secret spy mission, you've got some intel, but not everything, as you set out on your mission - This is Grey Box Pentesting! "
White Box - The Inside Job
- What is it? - You've got full access - code, system architecture, everything!
- The Goal? - Find weak spots from inside, checking every nook and cranny
- Usefulness? - Its super thorough and helps find bugs hidden extra deep
" You built the place, you've got all the blueprints, all the secret codes... now break into it! - Introducing White Box pentesting! "

From Types to Categories - Getting More Complex!
While pentests are classified as Black, Grey or White Box, they are also organised into categories according to Target
Network - The Digital Highway
- What is Tested? - Routers, firewalls, servers and IP addresses
- Goal? - Find open doors, weak passwords and mis-configurations
- Example Attack - Scanning open ports and exploiting known server vulnerabilities
" A high speed train robbery - but on the internet! "
Web Application - The Castle Siege
- What is Tested? - Websites, login forums, web app databases
- Goal? - Trick the system with clever inputs
- Example Attack - SQL Injection or Cross-Site Scripting
" Storming the gates of a digital kingdom, looking for holes in the walls!"
Wireless - The Invisible Rope
- What is Tested? - Wi-Fi networks, access points, and wireless protocols
- Goal? - Break into the wireless network or snoop on data flying through the air
- Example Attack - Capturing a WPA2 handshake to crack the Wi-Fi password
" Stealing invisible waves out of thin air! "
Client-Side Testing - The Trojan Horse
- What is Tested? - Browsers, desktop apps and plugins
- Goal? - Find ways users can be tricked into running malicious code
- Example Attack - Creating a malicious PDF or abusing browser flaws
" I won a free Ipad? Score! Wait... "
Social Engineering - The Human Puzzle
- What is Tested? - Employee awareness and response
- Goal? - Trick someone into giving up sensitive info or private access
- Example Attack- Phishing emails or calls, sneaky USB drops
" How easily can you be fooled? "
The Emerging Target Categories - Not quite their own...
These targets can fit into the above categories, but due to their growing importance they're often acknowledged as their own categories - Lucky them!
Cloud - The Sky-High Heist
- Overlap - Network, web and physical testing
- Why its distinct - Dealing with shared infrastructure and cloud specific permissions
- What is Tested? - Cloud Storage, virtual machines ad server-less functions
- Goal? - Identify mis-configurations, exposed data and overly permissive access
- Example Attack - Gain access to buckets full of confidential files
" Look at that cloud! its shaped like... a hacker? "
Mobile Applications - The Pocket-Sized Battle
- Overlap - Web and client-side testing
- Why its Distinct - Mobile apps use different operating systems, storage and permissions
- What is Tested? - Android and iOS apps, local storage and permissions
- Goal? - Find bad coding practices, weak encryption, or exposed secrets
- Example Attack - Reverse engineering an app to steal API keys or bypass authentication
" Your favourite app might just be a snitch... "
IoT - The Ultimate Smart Device Showdown
- Overlap - Hardware, software, wireless and network testing
- Why its Distinct - IoT devices run unique operating system, software and protocols
- What is Tested? - Embedded devices, their firmware, wireless connections and cloud integrations
- Goal? - Exploit weak authentication, unsafe protocols, or unprotected local interfaces
- Example Attack - Extracting firmware from smart devices to get Wi-Fi credentials
" Thats right, your fridge has been been plotting against you! "
From Categories to Approaches - Almost there!
Passive Scanning - The Quiet Spy
What Happens?
- Watches network traffic silently, without interacting directly with systems
- Collects data from broad-casted or observed traffic
- No packets are sent to the target, so the system doesn't know its being watched
Pros
- Won't interfere or disrupt the target
- Good for initial reconnaissance and threat intelligence
Cons
- Only sees what's already visible
- Results are slow as it must wait for traffic to appear
Active / Host Scanning - The Loud Detective
What Happens?
- Sends packets to probe target for information
- Checks which ports are open, what software is running, and whether known vulnerabilities exist
Pros
- Comprehensive analysis of ports, OS versions and more
- Faster and accurate than passive scanning
- Essential for attack simulation or deeper assessment
Cons
- Disruptive for the system and interferes with targets
- Detected and blocked by firewalls
Finishing Thoughts
And with all that said and done... we have reached the end, I hope you enjoyed learning about all the different types of pentests! You should be well versed on everything to do with the different options involved in penetration testing, but if in doubt...
Thanks for sharing. Now I have a much better understanding
Very Interesting! A good, short read