✓ OSCP · OSWE · OSEP certified | Joost performs every test himself — no juniors | Response within 1 business day | Based in Haarlem

Pentest Methodology: Black Box, Grey Box and White Box

When requesting a penetration test, you quickly run into terms like black box, grey box and white box. What’s the difference? Which approach fits your situation? And how does MonkeysICT carry out a pentest?

Black box pentest

In a black box pentest, the tester has no prior knowledge of the system’s internal workings. The approach simulates an external attacker trying to break in purely from the outside — just like a cybercriminal who doesn’t know your organisation.

  • What you test: how robust are your external defensive layers?
  • Suitable for: realistic attack scenarios, periodic external validation
  • Advantage: the most authentic simulation of an external attack
  • Disadvantage: more time-intensive — the tester has to do their own reconnaissance

Grey box pentest

In a grey box pentest, the tester has limited information: for example, credentials of a regular user, but no admin access or source code. This simulates an attacker with partial knowledge — an employee, former employee, or someone who has obtained an account.

  • What you test: how far can an authenticated but unauthorised user get?
  • Suitable for: web applications, portals, SaaS environments, APIs
  • Advantage: more efficient than black box, more realistic than white box
  • Disadvantage: tests external defences less thoroughly

Grey box is the most commonly used approach for web application pentests and API pentests.

White box pentest

In a white box pentest, the tester has complete information: access to source code, architecture documentation, network diagrams and sometimes administrator accounts too. This enables an in-depth, thorough assessment.

  • What you test: deep analysis of code, configuration and architecture
  • Suitable for: software developers, SaaS companies, ISO 27001 programmes, DigiD assessments
  • Advantage: the most complete coverage — little can go unnoticed
  • Disadvantage: a less realistic simulation of an external attacker

White box is often combined with an ISO 27001 pentest or a DigiD IT security assessment.

Which approach does MonkeysICT choose?

We always determine the approach together with the client, based on:

  • The purpose of the test (compliance, risk management, development)
  • The scope (web application, API, infrastructure, internal network)
  • Available time and budget
  • Any applicable regulations (NIS2, DigiD, PCI DSS, ISO 27001)

In practice, we often choose a grey box approach for web applications and APIs, and white box for SaaS environments or compliance-driven tests.

Our process, step by step

  1. Scoping — Together we determine what’s tested, which systems are in scope, and which approach fits.
  2. Reconnaissance — Passive and active information gathering about the target.
  3. Vulnerability analysis — Identification of potential weaknesses through automated scans and manual inspection.
  4. Exploitation — Proof of abuse: we demonstrate how an attacker could actually exploit a vulnerability.
  5. Post-exploitation — What’s the scope of the damage? Lateral movement, data exposure, privilege escalation.
  6. Reporting — A clear report with a management summary, technical findings with CVSS scores, and concrete recommendations.
  7. Presentation & debrief — We walk through the report and answer questions from the team.

Standards and methodologies

MonkeysICT works in accordance with recognised standards:

  • OWASP Testing Guide — for web applications and APIs
  • PTES (Penetration Testing Execution Standard) — for infrastructure
  • OSSTMM — for broad security assessments
  • NIST SP 800-115 — used for government and compliance programmes

FAQ

Which approach is best for a small web application?

Grey box is the best choice in most cases: efficient, realistic and focused. We simulate an attacker with basic access and test what could go wrong with real user sessions.

Is white box the same as a code review?

No. A white box pentest tests the running system with source code as context. A code review analyses the code statically. Both can complement each other, but they’re not identical.

How long does a grey box web application pentest take?

Usually 3 to 5 business days, depending on the size of the application and the number of use cases. You always receive a fixed time and price quote in advance.

Can I have a pentest performed on my production environment?

Yes, this is possible and often recommended for a realistic picture. We schedule outside peak hours and communicate transparently about the approach to minimise disruption.

What’s the difference between a pentest and a vulnerability scan?

A vulnerability scan is automated and detects known weaknesses. A pentest goes further: an ethical hacker actively attempts to break in and also finds logic and business-layer vulnerabilities that scanners miss. More on this at vulnerability scan vs. pentest.

Ready to get started? Request a quote or see our penetration testing services.

Scroll to Top