Pentesting (Penetration Testing)
Pentesting (penetration testing) is the controlled, authorized simulation of attacks on IT systems, applications or networks in order to uncover exploitable vulnerabilities before real attackers do.
A test begins with a clearly defined assignment (scope, period, rules) and follows different approaches depending on prior knowledge: black box without internal information, white box with full insight, grey box in between. Unlike automated scans, testers try to actually exploit and chain the vulnerabilities found – the result is a prioritized report with traceable attack paths and concrete recommendations. This is precisely what distinguishes it from Vulnerability Management: the latter identifies and manages vulnerabilities continuously and automatically, whereas a pentest checks real exploitability selectively and manually.
Since snapshots quickly become outdated, many organizations combine regular pentests with continuous, automated attack simulation (Automated Security Validation) in order to check the effectiveness of their defenses on an ongoing basis.