Black box, grey box and white box pentests differ in the information our pentesters receive in advance. We generally recommend a white box pentest: relevant source code, documentation and test accounts help us investigate more within the available time and reduce blind spots. We do not charge extra for this approach.
Black box pentest
The pentester starts without internal documentation, source code or supplied credentials. This can suit an assessment of attack opportunities from an unfamiliar external position. Discovering information takes testing time, potentially leaving less time to investigate underlying functionality.
Grey box pentest
The pentester receives some relevant information, such as test accounts for different user roles and API documentation. This enables targeted testing, for example of authorization and separation between customers, even when source code is unavailable.
White box pentest
The pentester receives the relevant information available, including source code, architecture documentation and test accounts. This helps our experts investigate attack scenarios more directly and interpret findings. The tester's knowledge is separate from the simulated attacker's permissions: source-code access still allows us to investigate what an unauthenticated visitor or regular user could achieve.
What does this mean for cost and coverage?
We do not charge extra for white box testing. The price depends on the scope, complexity and required coverage, aligned with your objectives and risk profile. More information helps us use the available testing time effectively; it does not automatically mean every component will be assessed exhaustively.
A full source code review is a separate service. Using source code to support a pentest is not the same as reviewing the entire codebase.
Which approach fits my situation?
We discuss this during scoping. To identify vulnerabilities while minimizing blind spots, we generally recommend white box testing. If the objective is to assess a specific attacker position or attack detection, we align the information, permissions and testing arrangements with that objective.
View our pentest plans and pricing or discuss your objectives and risk profile with us.
Nederlands