Testing approaches

Black Box Penetration Testing, and When Grey or White Box Is Better

Black box penetration testing starts with no internal knowledge, just like an external attacker. It shows what someone on the internet can find and exploit. This page explains how black box testing works, how it compares with grey box and white box testing, and how to choose the approach that gives you the most value for your budget.

Last reviewed 2026-09-28 by the Scantra Security testing team

Black box testing

Testers receive only a target, such as a domain or IP range. They discover the attack surface, find exposed services and attempt to break in. It is realistic, but time spent on discovery means less time testing authenticated functionality.

Grey box testing

Testers receive user accounts and basic documentation. This is the most common choice for web apps and APIs because it allows deep testing of access control and business logic, where most serious flaws are found.

White box testing

Testers receive source code, architecture diagrams and sometimes admin access. It gives the most complete coverage and pairs well with a source code review.

How to choose

  • Choose black box to measure external exposure or simulate an opportunistic attacker
  • Choose grey box for most application and API testing
  • Choose white box for high-risk systems, before major launches, or for fintech and payments
  • Combine approaches when regulators require an external view plus authenticated testing

Our black box process

  1. 1. Reconnaissance

    Subdomains, exposed services, leaked credentials and public code.

  2. 2. Vulnerability discovery

    Automated and manual checks on everything found.

  3. 3. Exploitation

    Safe proof of concept to confirm impact.

  4. 4. Report and free retest

    CVSS-rated findings with evidence and fixes, then a free retest and updated report once your team has remediated.

Frequently asked questions

Is black box testing more realistic?

It mirrors an outsider, but real attackers have unlimited time. Grey box compensates for the limited time of an engagement.

Which approach is cheapest?

Cost depends on scope, not approach. Grey box usually gives the best value per day.

Do regulators require a specific approach?

Most do not, but some ask for external testing. We will advise during scoping.

Related services

Get started

Ready to find what attackers will?

Talk to a senior pentester. Get a tailored scope, sample report and timeline within 24 hours.