We use cookies to understand how the site is used and to improve your experience. Privacy policy

    Skip to main content

    5 October 2026 · 9 min read · By Michael van Mameren, Lead Penetration Tester (OSCP)

    Types of Penetration Testing: By Target, by Position and by Knowledge Level

    Most lists of pentest types mix three different questions: what is tested, from where, and with how much information. Separate them and the choice becomes simple. This guide does that, and says which combination fits which situation.

    Scope the right type of test

    Three axes, not one list

    A penetration test is defined by three independent choices. The target: which system or layer is being attacked. The position: where the attacker starts. The knowledge level: how much the tester knows in advance. Every engagement is a combination, for example an internal, grey-box network test, or an external, black-box web application test. Vendors who sell a menu of ten test types are usually listing combinations of these three axes, which is why the menu looks longer than it is.

    Axis 1: by target

    What is being tested. Each target needs different skills, tooling and scoping.

    Network and infrastructure penetration testing

    Servers, network devices, identity systems (Active Directory, Entra ID), segmentation and remote access. The test that answers how far an attacker gets from a foothold. Usually split into a perimeter test from the internet and an internal test from inside the network.

    Web application penetration testing

    Customer portals, SaaS platforms, e-commerce and internal web tools, tested per user role against OWASP WSTG and ASVS. The home of access-control and business-logic findings.

    API penetration testing

    REST, GraphQL and gRPC services tested directly, independent of any frontend: object-level authorisation, mass assignment, rate limiting, token handling, and the integrations behind them.

    Mobile application penetration testing

    iOS and Android apps plus the backend APIs they call: local storage, certificate pinning, reverse engineering of the binary, and the same authorisation flaws as web applications.

    Cloud penetration testing and configuration review

    AWS, Azure and Google Cloud: IAM, network exposure, storage permissions, serverless and container configuration, and the paths from a compromised credential to the whole account.

    Wireless penetration testing

    Wi-Fi authentication and segmentation, rogue access points, guest network isolation, and the step from the car park to the internal network.

    Hardware, IoT and embedded testing

    Physical devices down to firmware and silicon: debug interfaces, firmware extraction, fault injection and side-channel analysis. A separate discipline with its own lab work.

    Social engineering and physical testing

    Phishing, vishing, pretexting and physical entry, testing people and processes rather than systems. Usually part of a red team engagement rather than a standalone pentest.

    Axis 2: by position

    Where the attacker starts determines what the test can prove.

    PositionStarting pointAnswers the question
    External (perimeter)The internet, no accessWhat can anyone in the world reach and exploit?
    InternalA network position inside the organisationWhat can an attacker on the LAN, or a malicious insider, reach?
    Assumed breachA standard user account or a workstation, as if phishing succeededHow far does one compromised user get, and how fast?
    Authenticated (application)A valid account per roleWhat can a customer, partner or employee do beyond their role?
    Tenant (SaaS)One customer account in a multi-tenant platformCan one tenant reach another tenant's data?

    Axis 3: by knowledge level

    How much the tester knows before starting. This is the black, grey and white box choice.

    Knowledge levelWhat the tester receivesBest forTrade-off
    Black boxNothing beyond the target name or IP rangeSimulating an anonymous external attacker; perimeter testsDays spent on discovery that could go into testing; misses what the attacker would find with time you did not pay for
    Grey boxCredentials per role, architecture overview, documentationMost application and internal tests; best findings per daySlightly less realistic for an outside attacker, far more thorough
    White boxSource code, configuration, infrastructure diagramsCritical applications, cryptographic code, compliance requiring code review (PCI DSS 6.2.4)Needs reviewers who read code; more preparation on your side

    Which combination fits which situation

    The combinations we scope most often, and why.

    • First test ever, limited number of days: external black-box perimeter plus grey-box test of the one application that handles customer data
    • SaaS platform before an enterprise deal or SOC 2: grey-box web application and API test per role, including tenant isolation
    • ISO 27001 or NIS2 evidence: annual external perimeter plus internal assumed-breach network test, grey box
    • PCI DSS: external and internal network tests, application-layer test against Requirement 6.2.4, segmentation test, all documented to 11.4.1
    • After a phishing incident or for ransomware readiness: internal assumed-breach from a standard workstation, with Active Directory focus
    • Connected product before launch: hardware and firmware test plus the cloud and mobile layers as one system
    • Mature programme asking whether detection works: red team engagement rather than another pentest

    Penetration test, vulnerability scan, red team: not interchangeable

    A vulnerability scan is automated identification of known weaknesses, run continuously. A penetration test is a scoped, manual exploitation of a defined target to find and prove what an attacker could do. A red team engagement is an objective-based simulation of a real adversary across people, processes and technology, usually covert, designed to test detection and response rather than to enumerate vulnerabilities. Organisations need all three at different maturity levels; what they should not do is buy one and call it another.

    Frequently asked questions

    Not sure which type you need?

    A 20-minute scoping call settles target, position and knowledge level, and gives you a written scope with day count. Talk to an expert.