Penetration tests are grouped two ways: by how much the tester knows going in — black, white, or grey box — and by what they target, from networks and web apps to mobile, cloud, and people. The right type, or mix of types, depends on your attack surface, your compliance needs, and where your risk actually sits. This guide maps the full landscape and points you to a deeper guide for each.
Last updated: 2026.
Key Takeaways
- Penetration tests are categorized on two axes: by how much the tester knows (black, white, grey box) and by what's being tested (the target).
- Black box means no inside knowledge, white box means full source and credentials, and grey box sits in between as a balanced, common default.
- By target, the main types are network, web application, mobile, cloud, wireless, API, social engineering, and physical — each finds different risks.
- Most organizations don't need every type; the right mix depends on your attack surface, compliance drivers, and risk.
- Autonomous black-box testing of the external perimeter and web APIs is increasingly used for continuous coverage between deeper manual engagements.
Two Ways to Categorize Penetration Tests
It's easy to get lost in a list of "types" because two different questions are being answered at once. The first is how much does the tester know? — which describes the approach, and gives you black, white, and grey box. The second is what are we testing? — which describes the target, and gives you network, web, mobile, and the rest. A real engagement always answers both: a test might be a grey-box web application test, or a black-box network test. Keep the two axes separate and the landscape gets simple. For the general concept behind all of this, see our pillar on what penetration testing is.
Types by Knowledge Level: Black, White, and Grey Box
The first axis is how much information the tester starts with. It's often called the "three types" of penetration testing, and it shapes both realism and depth.
Black Box
In black-box testing, the tester gets no inside knowledge — no source code, no credentials, no architecture diagrams. They start exactly where an external attacker would and work their way in. This is the most realistic simulation of an outside threat, and it's fast to set up, but it can miss issues buried deep in code that no outsider would ever reach. We cover it in full in our black-box penetration testing guide.
White Box
White-box testing is the opposite: the tester has full access to source code, architecture, and credentials. That visibility allows the deepest, most efficient coverage — ideal for finding business-logic flaws, cryptographic mistakes, and authentication weaknesses hidden in the code. It's the most thorough approach and the most resource-intensive, and it's less representative of a real external attacker. See our white-box penetration testing guide for the detail.
Grey Box
Grey box sits between the two, giving the tester partial knowledge — often a set of user credentials and some documentation. It balances realism with efficiency and is the common default for web application and API assessments, where testing as an authenticated user finds far more than testing blind. You get much of the depth of white box with much of the realism of black box.
A quick way to hold them in mind: black box is the outsider, white box is the insider, and grey box is the trusted user who's turned on you.
Types by Target
The second axis is what's under test. Each target type surfaces a different class of risk, and most has a dedicated guide.
Network Penetration Testing
Network testing probes your infrastructure — servers, firewalls, routers, and the services they expose — for open ports, weak credentials, and misconfigurations. It splits into external (perimeter) and internal (inside-the-LAN) testing. See our network penetration testing guide, and our external penetration testing service page for the perimeter side.
Web Application Penetration Testing
Web app testing targets the logic behind a browser: authentication, injection flaws, access control, and business logic. It's one of the most common engagements because web apps are exposed by design. Our web application penetration testing guide goes deep, and the website penetration testing page covers the service.
Mobile Application Penetration Testing
Mobile testing covers Android and iOS apps — the binary that ships to the device, local data storage, and the backend APIs behind them. Because the code runs in the user's hands, it needs its own approach, which our mobile application penetration testing guide explains.
API Penetration Testing
APIs are a target in their own right, where risk concentrates in authorization at the object level. As apps and integrations multiply, dedicated API testing has become essential; it overlaps with web testing but focuses on endpoints, tokens, and data exposure rather than a user interface.
Cloud Penetration Testing
Cloud testing examines your configuration and identity setup across providers — storage permissions, over-broad roles, exposed services — under the shared-responsibility model, where securing what you put in the cloud is your job, not the provider's.
Wireless Penetration Testing
Wireless testing assesses Wi-Fi and other radio networks for weak encryption, rogue access points, and poor segmentation that let an attacker onto your network from the parking lot.
Social Engineering
Social engineering targets people rather than systems — phishing, pretexting, and similar tactics that test whether staff can be tricked into handing over access. It measures human risk, which technology alone can't close.
Physical Penetration Testing
Physical testing checks whether someone can walk into a building, tailgate through a door, or reach a server room — because the strongest firewall means little if the hardware behind it is unguarded.
How to Choose the Right Type of Penetration Test
Few organizations need every type, and the goal isn't to buy the whole menu. Start with your attack surface: test what you actually expose. A SaaS company leads with web and API testing; a company with offices and a large workforce weighs network, wireless, and social engineering more heavily. Layer in your compliance drivers — standards like PCI DSS, SOC 2, and ISO 27001 expect specific testing, and our PCI DSS penetration testing guide shows how one requirement translates into scope. Then weigh budget and risk: put the deepest testing where a breach would hurt most. Most mature programs combine a couple of types on a schedule rather than relying on a single annual test. If you're still separating a scan from a real test, our vulnerability assessment and penetration testing guide helps.
Which Types BackDoor Covers
It's worth being clear about where an autonomous platform fits, because no single approach does everything. BackDoor runs autonomous, black-box testing of your external perimeter, web applications, and APIs — the surface an outside attacker can reach — and proves each finding with a working exploit. It does not perform physical or social-engineering tests, internal-LAN engagements that require inside access, or on-device mobile client testing; those remain specialist, often manual, work. What BackDoor adds is continuous coverage of the external surface that changes most often, so the gaps between deeper manual tests don't go unwatched. You can see the model on our external penetration testing and website penetration testing pages.
Conclusion
The types of penetration testing come down to two questions — how much the tester knows, and what they're testing. Choose by your real attack surface, layer in compliance and risk, and expect to combine a few types over time rather than relying on one. For the external surface that changes most, autonomous black-box testing keeps coverage continuous — which is where BackDoor fits, testing your perimeter, web apps, and APIs and proving each finding with a working exploit. From here, follow the links above into the deep guide for whichever type fits your needs.
Frequently asked questions
What are the main types of penetration testing?
By approach: black, white, and grey box. By target: network, web application, mobile, API, cloud, wireless, social engineering, and physical.
What are the 3 types of penetration testing?
The "three types" usually refers to the knowledge-based approaches — black box (no knowledge), white box (full knowledge), and grey box (partial knowledge).
What’s the difference between black, white, and grey box testing?
It’s how much the tester knows. Black box is the outsider’s view, white box has full source and credentials, and grey box is a trusted user with partial access.
Which type of penetration test do I need?
Match it to your attack surface first, then your compliance needs and risk. Most organizations combine a couple of types rather than choosing just one.
What is the most common type of penetration testing?
Web application and network testing are the most common, because those surfaces are exposed by design and are often required for compliance.
Can these types be automated?
Black-box testing of the external perimeter, web apps, and APIs can run continuously and autonomously. Social engineering and physical testing remain human-led.
See it on your own site
Full report with proof, exploits, and fixes — in ~5 hours, from € 5,100.
Written by

Penetration Tester & Security Researcher
Peter leads offensive security research at BackDoor — focused on autonomous black-box testing, web and API exploitation, and turning real-world attack paths into fixable, evidence-backed findings.