All services
02
Grey Box Penetration Test
A partial-knowledge engagement that combines authenticated context with adversarial techniques. Because we start with credentials and architecture detail, more of the budget goes into depth rather than discovery.

Scope
- Authenticated testing across every user role you provide
- Business logic abuse and authorisation bypass testing
- Privilege escalation, both horizontal and vertical
- Internal network lateral movement scenarios
- Source-informed review of high-risk functionality where available
Deliverables
- Executive summary and risk narrative per user role
- Detailed findings with impact, likelihood, and reproduction steps
- Attack path diagrams for chained vulnerabilities
- Remediation guidance mapped to your stack
- Free retest of critical and high findings
Typical timeline
1–3 days
Scope call & NDA
Role matrix, credentials, and test accounts agreed.
8–15 business days
Testing window
Depth-focused testing with daily updates.
3–5 business days
Reporting
Draft, QA review, and final report delivery.
Within 30 days
Debrief & retest
Technical walkthrough plus verification retest.