VVenstap
Category

Penetration Testing

13 articles

The Ethics and Legality of Penetration Testing

The legal and ethical foundations that separate authorized penetration testing from criminal computer intrusion, and the safeguards every engagement should have in place.

Building an Internal Penetration Testing Team

When it makes sense to build an internal penetration testing capability instead of relying solely on external vendors, and how to structure, staff, and scope that team well.

Retesting After Remediation: Why It Matters

Why a fix that hasn't been retested is just an assumption, what a rigorous retest actually verifies, and how to build retesting into a testing program rather than skipping it.

Social Engineering in Penetration Testing Engagements

Why social engineering remains one of the most effective attack vectors, how it's tested responsibly within a penetration testing engagement, and how to act on the results without blaming employees.

Network Penetration Testing: A Methodology Overview

A structured walkthrough of network penetration testing methodology, from reconnaissance through exploitation and lateral movement, and what distinguishes a rigorous test from a scan.

Common Findings in Web Application Penetration Tests

A tour of the vulnerability classes that show up most often in web application penetration tests, why they persist despite being well documented, and how to prioritize fixes.

How to Scope a Penetration Test Correctly

A practical guide to scoping penetration tests properly, covering asset inventory, timing, exclusions, and the common scoping mistakes that quietly waste testing budget.

Red Team vs Penetration Test: Which Do You Need

How red team engagements differ from penetration tests in objective, scope, and cost, with guidance on which one matches your organization's actual security maturity.

Internal vs External Penetration Testing

How internal and external penetration testing differ in scope, threat model, and value, and why most mature security programs need a regular cadence of both.

What Makes a Good Penetration Test Report

What separates a genuinely useful penetration test report from raw scanner output, covering structure, severity rating, evidence, and remediation guidance that engineers can act on.

How to Choose a Penetration Testing Vendor

Practical criteria for evaluating penetration testing vendors beyond price, including certifications, methodology, reporting quality, and how to spot a scan-and-relabel operation.

Black Box vs White Box vs Gray Box Testing

A breakdown of black box, white box, and gray box penetration testing approaches, with guidance on which model fits different goals, budgets, and timelines.

Penetration Testing 101: What to Expect from Your First Engagement

A practical walkthrough of what actually happens before, during, and after a first penetration test, so security teams can prepare and get real value from the engagement.