White-Box Penetration Testing
White-box penetration testing that reads your code
Connect a GitHub repo read-only and TurboPentest adds source-code, secret, and dependency analysis on top of the live external test - Opengrep SAST, Gitleaks, and Grype, all AI-validated - in hours, for $99 per target.
What is white-box penetration testing?
White-box penetration testing gives the tester access to the source code, not just the running application. Because the code is readable, a vulnerability can be traced to the exact file and line and to the dependency that introduced it - detail a black-box test has to infer from the outside. It is the difference between knowing an app is exploitable and knowing precisely which line to change.
On TurboPentest, white-box turns on when you connect a GitHub repository read-only. It adds three source-aware layers to the standard black-box run - Opengrep static analysis, Gitleaks secret scanning, and Grype software composition analysis - and the Paladin AI validates each finding and classifies it to an OWASP ASVS level. You get a short list of confirmed, triaged issues instead of a wall of raw scanner output.
325
tuned SAST rules across 7 languages, each with true-positive and true-negative tests
IntegSec rule pack
3 layers
SAST, secret scanning, and SCA added on top of the black-box external test
White-box run
$99
per target, flat - the white-box layer is included when you connect a repo
TurboPentest pricing
How white-box testing runs on TurboPentest
Connect your GitHub repo (read-only)
Connecting a repository switches on the white-box layer. The black-box external test still runs against your live target at the same time.
SAST, secrets, and SCA scan the source
Opengrep runs the 325-rule IntegSec pack across 7 languages, Gitleaks hunts committed secrets, and Grype matches your dependencies against known-vulnerable versions.
Paladin AI validates and classifies
Each source-code finding is validated and classified to an OWASP ASVS level (mobile findings to MASVS), aligned to the OWASP Code Review Guide, with false positives dropped.
Get your report
Findings with file-and-line locations, proof-of-concept where the code is reachable live, remediation, a Fix with AI prompt, and retest commands.
What the white-box layer adds
Every SAST rule is documented on the public Security Checks catalog with vulnerable-vs-safe code examples and CWE/OWASP/ASVS mappings.
Opengrep SAST
The LGPL engine run with IntegSec's own MIT rule pack - 325 rules across 7 languages covering the CWE Top 25 and OWASP Code Review Guide, each tagged CWE, OWASP, and ASVS, with true-positive and true-negative unit tests.
Gitleaks secret scanning
Hardcoded credentials, tokens, and private keys committed to your repository history - flagged with the file and location so you can rotate and remove them.
Grype software composition analysis
Your dependency tree matched against known-vulnerable package versions (SCA), so a vulnerable library surfaces even when your own code is clean.
Paladin AI classification
Every source-code finding is validated and classified to an OWASP ASVS level (mobile findings to MASVS), aligned to the OWASP Code Review Guide - triaged results, not raw scanner output.
White-box is the black-box run, plus your source
Black-box tests what an attacker can reach from the outside. White-box adds what the source reveals - the exact vulnerable line, the committed secret, the vulnerable dependency. TurboPentest runs both in one $99 engagement when you connect a repo.
White-box penetration testing FAQ
What is white-box penetration testing?+
White-box penetration testing (also called clear-box or full-knowledge testing) gives the tester access to the application's source code, not just its running surface. Because the code is readable, weaknesses can be traced to the exact file and line - things black-box testing has to infer from the outside. On TurboPentest, white-box turns on when you connect a GitHub repo read-only, adding source-code, secret, and dependency analysis on top of the live external test.
How does white-box testing work on TurboPentest?+
Connect your GitHub repository read-only when you start a pentest. That switches on the white-box layer: Opengrep runs static application security testing with IntegSec's 325-rule pack, Gitleaks hunts for committed secrets, and Grype checks your dependencies for known-vulnerable versions. The black-box external test still runs at the same time, so you get both source-code findings and live exploit validation in one run.
Is white-box testing a manual human code audit?+
No. White-box on TurboPentest is automated source-code and dependency analysis added to the external test - SAST, secret scanning, and SCA, with Paladin AI validating and classifying each finding to an OWASP ASVS level. It is not a manual, line-by-line human code review by a consultant. It is available only when a GitHub repo is connected; the default TurboPentest run is black-box.
Which languages does the source-code analysis cover?+
The SAST rule pack covers JavaScript/TypeScript, Python, Java, Go, PHP, Ruby, and C# - 325 rules across the CWE Top 25 and OWASP Code Review Guide, plus secrets, PII/PHI, and insecure-config checks. Every rule is documented on the public Security Checks catalog with vulnerable-vs-safe examples and CWE/OWASP/ASVS mappings.
How much does white-box penetration testing cost?+
$99 per target, flat - the same price as a black-box run. The white-box layer (SAST, secrets, and SCA) is included at no extra charge when you connect a repo, and results come back in a few hours.
Connect a repo. Read the code. $99.
White-box SAST, secret scanning, and SCA plus a live pentest in one run. See pricing
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.