[ Testing models ]
Black Box Penetration Testing
- Typical duration
- 3-5 days
- Starting price
- $700
- You provide
- Target name only
[ 01 / The engagement ]
You give us a name. We give ourselves everything after that. Black box testing is the closest honest simulation of an opportunistic attacker: no credentials, no architecture diagram, no source, no hints. It answers the question every board eventually asks, what can somebody do to us from the open internet, starting from zero?
[ 02 / Coverage ]
What we test, in practice.
This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.
Methodology
- 01Passive and active reconnaissance across your public footprint
- 02Subdomain discovery, forgotten hosts and shadow infrastructure
- 03Service and version enumeration on every reachable port
- 04Authentication, session and access-control testing on exposed apps
- 05Credential stuffing and password spraying against public login surfaces
- 06Exposed secrets in public repositories, JS bundles and CI artefacts
- 07Chained exploitation to prove real, demonstrable impact
[ 03 / What you get ]
Four things land at the end of every engagement.
Technical report
Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.
Executive summary
Two pages your board can read. Risk in business terms, with the three things that matter most called out.
Letter of attestation
A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.
Free retest
Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.
[ 04 / Questions ]
Before you commit.
Yes, for a small, single-domain external scope with a handful of live hosts. Price moves with the number of live hosts and applications in scope, not with a sales conversation. You see the scope sheet and the number before you commit.
Usually, yes, and that is the point. Black box measures exposure from outside. If you want depth behind the login, run grey box. Most teams start black box and move to grey box the following year.
Often scoped together
All services →Grey Box Penetration Testing
Standard user credentials, no source code. The best coverage per pound spent.
White Box Penetration Testing
Source code, architecture and admin access. Maximum depth, nothing held back.
Web Application Penetration Testing
Manual testing of the application your customers actually log in to.
Scope a black box penetration testing.
Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.