Types of penetration testing: a guide to every method and target
The main types of penetration testing are grouped two ways: by target (what is being tested, such as networks, web applications, wireless, cloud, physical facilities, people, or AI systems) and by knowledge level (how much the tester knows in advance, split into black box, white box, and grey box). Most organizations use a mix, choosing the target based on their attack surface and the knowledge level based on the depth and realism they want. This guide covers each type, when a business needs it, and how they fit together.
Choosing the right combination matters because a penetration test only proves what it actually exercises. A pristine network report tells you nothing about a vulnerable web app, and a clean web app test says nothing about whether an employee will hand over credentials to a convincing phishing email. Understanding the categories helps you scope coverage that matches how attackers would really come after you. For a full walkthrough of the discipline, see our overview of penetration testing services.
Penetration testing by knowledge level
Before choosing a target, decide how much information the tester starts with. This determines how realistic the engagement feels and how efficiently it uses the testing budget.
- Black box testing: the tester gets little or no internal information, only what a real external attacker could find. It closely mirrors an opportunistic outsider and is strong for validating your perimeter, but it can miss deeper issues because time is spent on reconnaissance rather than exploitation.
- White box testing: the tester receives full context, including architecture diagrams, source code, and credentials. This produces the most thorough coverage per dollar and is ideal for finding logic flaws and deep configuration issues, though it is less representative of a blind external attack.
- Grey box testing: a middle ground where the tester has partial knowledge, such as standard user credentials or a network diagram. It balances realism and efficiency by simulating an attacker who already has a foothold or an insider with limited access, which is why most engagements land here.
Knowledge level is not a substitute for target selection. You still pick what to test, then decide how much the tester should know going in.
Network penetration testing
Network penetration testing targets your servers, firewalls, routers, VPNs, and other infrastructure to find exposed services, weak configurations, missing patches, and paths an attacker could use to move laterally once inside. It splits into external testing, which probes your internet-facing perimeter, and internal testing, which simulates an attacker or malicious insider already on the network. Nearly every organization needs it because the network underpins everything else, and it is often the first engagement a business commissions. Learn more about our network penetration testing service.
Web application penetration testing
Web application penetration testing focuses on the software your users interact with: portals, dashboards, APIs, and customer-facing sites. Testers hunt for issues like injection, broken authentication, access-control flaws, and business-logic errors that automated scanners routinely miss. If your application handles customer data, payments, or sensitive workflows, this test is essential and should run after any major release. Explore our web application penetration testing service.
Social engineering testing
Social engineering testing targets people rather than systems, measuring how employees respond to phishing emails, pretext phone calls, and other manipulation designed to extract credentials or access. Because the human layer is the most common entry point in real breaches, this test reveals gaps that no technical control can close on its own. Businesses with distributed teams or high staff turnover benefit most from running it regularly. See our social engineering penetration testing service.
Wireless penetration testing
Wireless penetration testing examines your Wi-Fi networks, access points, and the devices that connect to them, looking for weak encryption, rogue access points, and segmentation failures that let an attacker jump from the guest network to sensitive systems. It matters most for offices, retail locations, warehouses, and any site where an attacker within physical range could intercept traffic or gain a foothold. Review our wireless penetration testing service.
Physical penetration testing
Physical penetration testing evaluates the real-world security of your premises: locks, badge readers, reception controls, and whether a tester can tailgate through a door or reach a network port inside the building. It is critical for organizations with data centers, sensitive facilities, or valuable on-site assets, since a determined attacker who gets inside can bypass many digital defenses entirely. Learn about our physical penetration testing service.
Cloud penetration testing
Cloud penetration testing targets your AWS, Azure, and Google Cloud environments, focusing on misconfigured storage, over-permissioned identities, exposed management interfaces, and insecure architecture that attackers chain together to escalate access. Because cloud environments change constantly and shared-responsibility gaps are easy to miss, any business running significant workloads in the cloud needs this test. Explore our cloud penetration testing service.
Red team assessments
A red team assessment is a goal-oriented, multi-vector attack simulation that blends network, application, social engineering, physical, and cloud techniques to test not just your defenses but your detection and response. Rather than cataloging every vulnerability, a red team pursues a specific objective, such as reaching sensitive data, the way a real adversary would. It suits mature organizations that already run regular scoped tests and want to validate how their people and processes hold up under a realistic attack. See our red team assessments service.
Talk to a SubRosa security engineer
Get a straight answer on where your defenses actually stand — no pitch, no obligation.
Book a consultationLLM and AI penetration testing
LLM and AI penetration testing targets the large language models and AI features increasingly embedded in products, probing for prompt injection, data leakage, insecure model integrations, and ways to manipulate the system into unsafe behavior. As businesses ship chatbots, copilots, and AI-driven workflows, these systems introduce a new attack surface that traditional tests do not cover. Any organization deploying generative AI in a customer-facing or sensitive context should test it. Learn about our penetration testing for large language models service.
How to choose the right type of penetration test
Start with your attack surface. Map where your sensitive data lives and how someone could reach it, then match each path to the target that tests it: internet-facing infrastructure to network testing, customer software to web application testing, staff to social engineering, and so on. Compliance requirements often set a baseline, but real risk should drive the rest. Newer organizations usually begin with network and web application testing, add social engineering and cloud as they grow, and graduate to a red team assessment once individual controls are solid. On knowledge level, grey box is a sensible default for most engagements, with white box reserved for deep coverage and black box for validating the perimeter. For help sequencing your program, see our full penetration testing services overview, and request a scoped quote so testing maps to your actual environment.
Frequently asked questions
How many types of penetration testing are there?
There is no single fixed number, but the field is best understood in two dimensions. By target there are around eight common types: network, web application, social engineering, wireless, physical, cloud, red team, and LLM or AI testing. By knowledge level there are three: black box, white box, and grey box. Most organizations combine several targets at the knowledge level that fits each engagement.
What is the difference between black box, white box, and grey box testing?
The difference is how much the tester knows before starting. Black box gives the tester almost no internal information, mimicking an outside attacker. White box provides full access, including documentation and source code, for the most thorough coverage. Grey box sits in between with partial knowledge, such as a standard user login, simulating an attacker who already has a foothold. Grey box is the most common because it balances realism and efficiency.
Which type of penetration test do I need?
It depends on your attack surface and risk. Most organizations start with network and web application testing because those cover the systems attackers reach most often. Add social engineering if people handle sensitive data, cloud testing if you run significant workloads in AWS, Azure, or GCP, and a red team assessment once your individual controls are mature. Compliance obligations may also dictate specific tests. When in doubt, a scoping conversation will match the right combination to your environment.
What is the difference between a penetration test and a vulnerability scan?
A vulnerability scan is an automated tool that lists known weaknesses across your systems, and it is fast, cheap, and best run frequently. A penetration test is a manual, expert-led engagement where a skilled tester actively exploits weaknesses, chains them together, and demonstrates real business impact. Scans tell you what might be wrong; a penetration test proves what an attacker could actually do. The two are complementary, not interchangeable.
How often should each type of penetration test be performed?
A good baseline is at least annually and after any significant change, such as a major release, infrastructure migration, or new office. High-risk web applications and cloud environments often warrant more frequent testing, while social engineering benefits from a regular cadence to keep staff awareness sharp. Many organizations move to a continuous or penetration testing as a service model so coverage keeps pace with change rather than lapsing between annual reviews.