Grey-Box
Penetration Testing

Testing with limited information and standard user accounts — the approach we recommend for most applications, balancing the realism of black-box with the coverage of white-box for the best value.

Overview

The best coverage for your budget.

Grey-box penetration testing is the pragmatic middle ground. We work with standard user accounts and limited documentation — enough to test authenticated functionality and authorisation thoroughly, while still exercising the realism of an attacker who has gained a foothold.

For most web, API, and mobile applications it delivers the most issues found per day of effort, which is why it is our default recommendation.


Approach

What grey-box covers.

Limited-knowledge, authenticated testing that balances realism and depth.

Methodologies: OWASP WSTG OWASP API Top 10 PTES CVSS v3.1

FAQ

Grey-box penetration testing FAQ

The questions we're asked most about scope, cost, and timing.

How much does grey-box penetration testing cost?
Grey-box testing typically starts around €2,000 and is scoped by application size and roles. It usually offers the best coverage-per-budget. Use our estimator for a tailored figure.
What is grey-box penetration testing?
Testing with limited information and standard user accounts — enough to thoroughly test authenticated features and authorisation while keeping an attacker’s perspective.
Why do you recommend grey-box for most applications?
It finds the most issues per day of effort: testers do not waste time on reconnaissance, yet still exercise realistic attack paths and authorisation flaws.
What is the difference between grey-box, black-box, and white-box?
Black-box has no information, white-box has full information and source, and grey-box sits in between with limited knowledge and accounts — the balance of realism and depth.
What do we receive?
A CVSS-scored report with reproduction steps, an executive summary, an attestation letter, and a free retest within 60 days.
What do you need for a grey-box test?
Standard user accounts for each role and brief documentation of key features — enough to test authenticated functionality thoroughly.
Why is grey-box your default recommendation?
It finds the most issues per day of effort, balancing the realism of black-box with the depth of white-box.
Does grey-box cover authorisation flaws?
Yes — with multiple roles we focus heavily on privilege escalation and broken access control, a top source of real-world breaches.
Can we upgrade to white-box mid-engagement?
If you provide source and documentation we can deepen coverage; we agree any scope change before proceeding.
What do we receive?
A CVSS-scored report with reproduction steps, an executive summary, an attestation letter, and a free retest within 60 days.

Related services

Explore more.

Ready for balanced, high-value testing?

A 30-minute scoping call costs nothing. A breach costs considerably more.

Book a meeting Send an email