Definition · External Attack Surface Management

What is Penetration Testing?

A penetration test is a deliberate attempt to break into something you own, with permission, within a defined scope and timeframe. The distinguishing feature against automated scanning is that a human chains findings together: two low-severity issues that a scanner reports separately may combine into full compromise, and only a tester will demonstrate that.

Common types

  • External network testing against internet-facing infrastructure
  • Web application and API testing, usually the largest category
  • Internal or assumed-breach testing, starting from a foothold inside the network
  • Wireless, physical, and social engineering engagements
  • Cloud configuration reviews, often as much audit as attack

Scope may be black box (no information provided), grey box (partial), or white box (full documentation and source), which changes what the test can realistically cover in the time available.

How a test runs

Engagements follow a broadly standard shape: scoping and rules of engagement, reconnaissance, vulnerability identification, exploitation, post-exploitation and pivoting, then reporting and a retest of fixes. Written authorisation and clear escalation contacts are part of the definition, not paperwork around it.

What a point-in-time test cannot do

A test describes your exposure on the days it ran, against the scope it was given. It will not see the service exposed the following month, the certificate that expires in the summer, or the subsidiary that was out of scope. Nor can a scope list include assets nobody knew about — which is why an accurate external inventory both improves scoping and covers the period between tests. Continuous monitoring and periodic testing answer different questions: what changed, versus how far can a skilled attacker get.

Penetration testing is narrower and more goal-directed than a red team engagement, complements automated DAST and CVE detection, and feeds findings into vulnerability management.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.