Penetration test (pentest)
A security assessment in which weaknesses are sought in a controlled way using a real attacker's methods, with the owner's written permission and a written scope, and reported with evidence.
- 01
Why it matters
A penetration test looks at your systems through an attacker's eyes: which weakness can really be used, and how far can it lead? The difference from automated scanning is an expert who links findings together and tests business logic. The result is a prioritised report with evidence and fix advice, followed by a retest after the fixes.
- 02
Example
The tester notices that the password reset link is predictable and shows that it can be used to reach the admin panel. The report describes the steps with screenshots and a recommended fix; after the fix, the same path is tried again.
- 03
Common mistake
Starting a test without a written scope and authorisation, or never retesting after receiving the report. A test without written permission can legally count as an attack; without a retest you cannot know the flaw is closed.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.