5 October 2026 · 9 min read · By Michael van Mameren, Lead Penetration Tester (OSCP)
Types of Penetration Testing: By Target, by Position and by Knowledge Level
Most lists of pentest types mix three different questions: what is tested, from where, and with how much information. Separate them and the choice becomes simple. This guide does that, and says which combination fits which situation.
Three axes, not one list
A penetration test is defined by three independent choices. The target: which system or layer is being attacked. The position: where the attacker starts. The knowledge level: how much the tester knows in advance. Every engagement is a combination, for example an internal, grey-box network test, or an external, black-box web application test. Vendors who sell a menu of ten test types are usually listing combinations of these three axes, which is why the menu looks longer than it is.
Axis 1: by target
What is being tested. Each target needs different skills, tooling and scoping.
Network and infrastructure penetration testing
Servers, network devices, identity systems (Active Directory, Entra ID), segmentation and remote access. The test that answers how far an attacker gets from a foothold. Usually split into a perimeter test from the internet and an internal test from inside the network.
Web application penetration testing
Customer portals, SaaS platforms, e-commerce and internal web tools, tested per user role against OWASP WSTG and ASVS. The home of access-control and business-logic findings.
API penetration testing
REST, GraphQL and gRPC services tested directly, independent of any frontend: object-level authorisation, mass assignment, rate limiting, token handling, and the integrations behind them.
Mobile application penetration testing
iOS and Android apps plus the backend APIs they call: local storage, certificate pinning, reverse engineering of the binary, and the same authorisation flaws as web applications.
Cloud penetration testing and configuration review
AWS, Azure and Google Cloud: IAM, network exposure, storage permissions, serverless and container configuration, and the paths from a compromised credential to the whole account.
Wireless penetration testing
Wi-Fi authentication and segmentation, rogue access points, guest network isolation, and the step from the car park to the internal network.
Hardware, IoT and embedded testing
Physical devices down to firmware and silicon: debug interfaces, firmware extraction, fault injection and side-channel analysis. A separate discipline with its own lab work.
Social engineering and physical testing
Phishing, vishing, pretexting and physical entry, testing people and processes rather than systems. Usually part of a red team engagement rather than a standalone pentest.
Axis 2: by position
Where the attacker starts determines what the test can prove.
| Position | Starting point | Answers the question |
|---|---|---|
| External (perimeter) | The internet, no access | What can anyone in the world reach and exploit? |
| Internal | A network position inside the organisation | What can an attacker on the LAN, or a malicious insider, reach? |
| Assumed breach | A standard user account or a workstation, as if phishing succeeded | How far does one compromised user get, and how fast? |
| Authenticated (application) | A valid account per role | What can a customer, partner or employee do beyond their role? |
| Tenant (SaaS) | One customer account in a multi-tenant platform | Can one tenant reach another tenant's data? |
Axis 3: by knowledge level
How much the tester knows before starting. This is the black, grey and white box choice.
| Knowledge level | What the tester receives | Best for | Trade-off |
|---|---|---|---|
| Black box | Nothing beyond the target name or IP range | Simulating an anonymous external attacker; perimeter tests | Days spent on discovery that could go into testing; misses what the attacker would find with time you did not pay for |
| Grey box | Credentials per role, architecture overview, documentation | Most application and internal tests; best findings per day | Slightly less realistic for an outside attacker, far more thorough |
| White box | Source code, configuration, infrastructure diagrams | Critical applications, cryptographic code, compliance requiring code review (PCI DSS 6.2.4) | Needs reviewers who read code; more preparation on your side |
Which combination fits which situation
The combinations we scope most often, and why.
- First test ever, limited number of days: external black-box perimeter plus grey-box test of the one application that handles customer data
- SaaS platform before an enterprise deal or SOC 2: grey-box web application and API test per role, including tenant isolation
- ISO 27001 or NIS2 evidence: annual external perimeter plus internal assumed-breach network test, grey box
- PCI DSS: external and internal network tests, application-layer test against Requirement 6.2.4, segmentation test, all documented to 11.4.1
- After a phishing incident or for ransomware readiness: internal assumed-breach from a standard workstation, with Active Directory focus
- Connected product before launch: hardware and firmware test plus the cloud and mobile layers as one system
- Mature programme asking whether detection works: red team engagement rather than another pentest
Penetration test, vulnerability scan, red team: not interchangeable
A vulnerability scan is automated identification of known weaknesses, run continuously. A penetration test is a scoped, manual exploitation of a defined target to find and prove what an attacker could do. A red team engagement is an objective-based simulation of a real adversary across people, processes and technology, usually covert, designed to test detection and response rather than to enumerate vulnerabilities. Organisations need all three at different maturity levels; what they should not do is buy one and call it another.
Frequently asked questions
Not sure which type you need?
A 20-minute scoping call settles target, position and knowledge level, and gives you a written scope with day count. Talk to an expert.