Types of Penetration Testing
The types of penetration testing, explained
Penetration tests get grouped by knowledge level, by target, and by how they are run. Here is what each type means - and, honestly, which ones TurboPentest runs automatically for $99 and which need a separate, manual engagement.
By knowledge level: black, white, and grey-box
How much the tester knows going in shapes what they can find. This is the split most people mean when they say "type" of pentest.
Black-box testing
Covered automaticallyThe tester starts with no inside knowledge - just a target, the way a real external attacker would. Everything is discovered by probing the live system from the outside.
This is how every TurboPentest run works by default. Prove you own the target and the agents attack it from the outside, no code or credentials required.
Black-box penetration testing→White-box testing
White-box (connect a repo)The tester has full inside knowledge - source code, architecture, sometimes credentials - so weaknesses can be traced to the exact file and line rather than only inferred from the outside.
Connect a GitHub repo (read-only) and TurboPentest adds a source-code layer: Opengrep SAST, Gitleaks secrets, and Grype SCA, all validated by the Paladin AI. Same $99 per target.
White-box penetration testing→Grey-box testing
White-box (connect a repo)A middle ground: the tester has partial knowledge, such as a low-privilege account or limited documentation, to simulate an attacker who already has a foothold.
TurboPentest covers the two ends - pure black-box by default, full white-box when you connect a repo. It does not currently run credentialed grey-box sessions with a supplied test account.
By target: what is being tested
A pentest is often named for the layer it attacks. TurboPentest runs all five of these automatically in a single run.
Network penetration testing
Covered automaticallyFinds exposed services, open ports, and misconfigured hosts across your infrastructure, then checks detected versions against known CVEs.
Run automatically. Naabu maps open ports, then web ports go to HTTPX and non-web services to Nuclei for service and version fingerprinting and CVE matching.
Network penetration testing→Web application penetration testing
Covered automaticallyTests your live application for injection, broken access control, authentication flaws, and the rest of the OWASP Top 10.
Run automatically against your live app with OWASP ZAP, Nuclei, Nikto, and FFUF, then AI-validated for real exploitability.
Web application penetration testing→API penetration testing
Covered automaticallyDiscovers endpoints with their methods, parameters, and auth requirements, then tests for broken object-level authorization and data exposure.
Run automatically as part of every test. Endpoints are cataloged in your attack surface map and probed for access-control and data-exposure flaws.
API security testing→Cloud penetration testing
Covered automaticallyMaps cloud-native assets that passive scanners miss across AWS, Azure, GCP, and DigitalOcean, and risk-scores each one.
Connect a cloud account read-only and TurboPentest discovers assets for free, then offers a one-click agentic pentest per asset.
Cloud penetration testing→External attack surface testing
Covered automaticallyDiscovers the internet-facing assets you forgot you had - subdomains, staging boxes, and shadow infrastructure - where a real attacker often starts.
Run automatically. Subdomain discovery and external scanning map your full internet-facing footprint before anything is tested.
External penetration testing→By execution: automated vs. manual
The other big divide is who does the work: AI agents running start to finish, or a human red team going deep by hand.
Automated / agentic testing
Covered automaticallyAI agents drive the whole engagement - discovery, scanning, exploitation attempts, and validation - start to finish with no human in the loop.
This is TurboPentest. The Paladin AI orchestrates 14 scanning tools, validates each candidate finding for exploitability, and writes the report - results in hours.
Agentic penetration testing→Manual human red team
Separate engagementExperienced operators test by hand, chaining subtle logic flaws and creative attack paths that automation is not designed to find.
TurboPentest is fully autonomous, not a manual red-team engagement. Its STRIDE threat model hands you prioritized manual-testing recommendations if you want a human to go deeper.
Types TurboPentest does not do
Being autonomous means some kinds of testing are genuinely out of scope. These need a separate, largely manual engagement - we will not pretend otherwise.
Physical penetration testing
Not coveredTesting physical controls - badge access, locks, tailgating, on-site social entry. Requires people on the ground and is out of scope for an automated remote platform.
Social engineering / phishing
Not coveredPhishing campaigns, pretext calls, and other human-targeted attacks. TurboPentest tests systems, not people, and does not run social-engineering engagements.
Mobile app penetration testing
Not coveredReverse-engineering and testing iOS or Android binaries. TurboPentest classifies findings to MASVS where relevant, but does not run a full mobile app pentest.
Internal-network testing (from inside the perimeter)
Not coveredAssumed-breach testing launched from inside your network - lateral movement, Active Directory, internal pivoting. TurboPentest tests your external attack surface, not the internal LAN.
What a single TurboPentest run covers
You do not pick a type and pay per test. Every $99 target gets the full black-box sweep - external attack surface, network, web application, API, and cloud - with 14 scanning tools and the Paladin AI validating what is actually exploitable. Connect a GitHub repo read-only and the same run adds the white-box source-code layer. That is most of the type matrix on this page, in a few hours, in one report.
For the whole picture of how these pieces fit together, see the security assessment overview or the full penetration testing services page.
Types of penetration testing FAQ
What are the main types of penetration testing?+
Penetration tests are usually grouped three ways. By knowledge level: black-box (no inside information), white-box (full source and architecture access), and grey-box (partial access). By target: network, web application, API, cloud, and external attack surface. And by execution: automated/agentic versus a manual human red team. Most engagements combine several of these.
Which types of penetration testing does TurboPentest run automatically?+
Every run is a black-box external, network, web app, API, and cloud pentest, fully automated and AI-validated. Connect a GitHub repo read-only and it also runs a white-box source-code layer (SAST, secrets, and SCA). All of it is $99 per target with results in a few hours.
What is the difference between black-box, white-box, and grey-box testing?+
Black-box means the tester has no inside knowledge and attacks from the outside like a real attacker. White-box means full access to source code and architecture, so weaknesses trace to the exact file and line. Grey-box sits between them, with partial knowledge such as a low-privilege account. TurboPentest covers black-box by default and white-box when you connect a repo.
Which types of penetration testing does TurboPentest NOT do?+
TurboPentest does not perform physical penetration testing, social engineering or phishing, mobile app penetration testing, or internal-network testing from inside your perimeter. Those need a separate, largely manual engagement. TurboPentest focuses on automated testing of your external attack surface and applications.
Do I need to pick a type before I start?+
No. TurboPentest runs the black-box external, network, web, API, and cloud coverage automatically on every target. The only choice is whether to connect a GitHub repo to add the white-box source-code layer. Same flat $99 per target either way.
Most of the matrix. One run. $99.
Black-box external, network, web, API, and cloud - automatically, plus white-box when you connect a repo. See pricing
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.