All services

02

Grey Box Penetration Test

A partial-knowledge engagement that combines authenticated context with adversarial techniques. Because we start with credentials and architecture detail, more of the budget goes into depth rather than discovery.

Grey Box Penetration Test

Scope

  • Authenticated testing across every user role you provide
  • Business logic abuse and authorisation bypass testing
  • Privilege escalation, both horizontal and vertical
  • Internal network lateral movement scenarios
  • Source-informed review of high-risk functionality where available

Deliverables

  • Executive summary and risk narrative per user role
  • Detailed findings with impact, likelihood, and reproduction steps
  • Attack path diagrams for chained vulnerabilities
  • Remediation guidance mapped to your stack
  • Free retest of critical and high findings

Typical timeline

1–3 days

Scope call & NDA

Role matrix, credentials, and test accounts agreed.

8–15 business days

Testing window

Depth-focused testing with daily updates.

3–5 business days

Reporting

Draft, QA review, and final report delivery.

Within 30 days

Debrief & retest

Technical walkthrough plus verification retest.