DFIELDSOLUTIONS

Security

GlossaryPenetration test

An authorised, scoped attempt to break into a system, done to find out what an attacker could actually achieve.

The word that does the work is authorised. A pen test begins with a written scope: what is in, what is off limits, what happens if something falls over, and who gets the call. Without that document the same activity is a crime, and the paperwork is not a formality — it is the thing that makes the exercise possible.

What distinguishes a test from a scan is that a human tries to chain things. A scanner reports that a version is outdated and that a form reflects input; a tester notices that one gives them a session and the other gives them somebody else's, and writes up the path between them with reproduction steps. The finding that matters is usually a combination, and combinations are what automation is worst at.

Expect a report you can act on: each finding with steps to reproduce it, an honest severity, and what it means in business terms. A four-hundred-item scanner export with the informational findings left in is not a penetration test.

Related terms

The bench this belongs to

Cybersecurity

Purple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.

All termsStart a conversationMarkdown version

DField Bt. · Dunakeszi · dezso@dfieldsolutions.com
5.0
“From LinkedIn DM to live site. Two tiny tweaks, then shipped.”Michael J Ringer · Vilya ProtectionFounder · Spain