Pentest Methodology: Black Box, Grey Box and White Box
When requesting a penetration test, you quickly run into terms like black box, grey box and white box. What’s the difference? Which approach fits your situation? And how does MonkeysICT carry out a pentest?
Black box pentest
In a black box pentest, the tester has no prior knowledge of the system’s internal workings. The approach simulates an external attacker trying to break in purely from the outside — just like a cybercriminal who doesn’t know your organisation.
- What you test: how robust are your external defensive layers?
- Suitable for: realistic attack scenarios, periodic external validation
- Advantage: the most authentic simulation of an external attack
- Disadvantage: more time-intensive — the tester has to do their own reconnaissance
Grey box pentest
In a grey box pentest, the tester has limited information: for example, credentials of a regular user, but no admin access or source code. This simulates an attacker with partial knowledge — an employee, former employee, or someone who has obtained an account.
- What you test: how far can an authenticated but unauthorised user get?
- Suitable for: web applications, portals, SaaS environments, APIs
- Advantage: more efficient than black box, more realistic than white box
- Disadvantage: tests external defences less thoroughly
Grey box is the most commonly used approach for web application pentests and API pentests.
White box pentest
In a white box pentest, the tester has complete information: access to source code, architecture documentation, network diagrams and sometimes administrator accounts too. This enables an in-depth, thorough assessment.
- What you test: deep analysis of code, configuration and architecture
- Suitable for: software developers, SaaS companies, ISO 27001 programmes, DigiD assessments
- Advantage: the most complete coverage — little can go unnoticed
- Disadvantage: a less realistic simulation of an external attacker
White box is often combined with an ISO 27001 pentest or a DigiD IT security assessment.
Which approach does MonkeysICT choose?
We always determine the approach together with the client, based on:
- The purpose of the test (compliance, risk management, development)
- The scope (web application, API, infrastructure, internal network)
- Available time and budget
- Any applicable regulations (NIS2, DigiD, PCI DSS, ISO 27001)
In practice, we often choose a grey box approach for web applications and APIs, and white box for SaaS environments or compliance-driven tests.
Our process, step by step
- Scoping — Together we determine what’s tested, which systems are in scope, and which approach fits.
- Reconnaissance — Passive and active information gathering about the target.
- Vulnerability analysis — Identification of potential weaknesses through automated scans and manual inspection.
- Exploitation — Proof of abuse: we demonstrate how an attacker could actually exploit a vulnerability.
- Post-exploitation — What’s the scope of the damage? Lateral movement, data exposure, privilege escalation.
- Reporting — A clear report with a management summary, technical findings with CVSS scores, and concrete recommendations.
- Presentation & debrief — We walk through the report and answer questions from the team.
Standards and methodologies
MonkeysICT works in accordance with recognised standards:
- OWASP Testing Guide — for web applications and APIs
- PTES (Penetration Testing Execution Standard) — for infrastructure
- OSSTMM — for broad security assessments
- NIST SP 800-115 — used for government and compliance programmes
FAQ
Which approach is best for a small web application?
Grey box is the best choice in most cases: efficient, realistic and focused. We simulate an attacker with basic access and test what could go wrong with real user sessions.
Is white box the same as a code review?
No. A white box pentest tests the running system with source code as context. A code review analyses the code statically. Both can complement each other, but they’re not identical.
How long does a grey box web application pentest take?
Usually 3 to 5 business days, depending on the size of the application and the number of use cases. You always receive a fixed time and price quote in advance.
Can I have a pentest performed on my production environment?
Yes, this is possible and often recommended for a realistic picture. We schedule outside peak hours and communicate transparently about the approach to minimise disruption.
What’s the difference between a pentest and a vulnerability scan?
A vulnerability scan is automated and detects known weaknesses. A pentest goes further: an ethical hacker actively attempts to break in and also finds logic and business-layer vulnerabilities that scanners miss. More on this at vulnerability scan vs. pentest.
Ready to get started? Request a quote or see our penetration testing services.
