Cybersecurity Insights & Research

Threat reports, research papers, webinars and whitepapers from the Mercurius security team — staying ahead of the adversary.

The main types of penetration test external, internal, application, and social engineering

Types of Pentest and when to use each

Not all penetration tests are the same, and asking for “a pentest” without specifying the type is like asking a doctor for “a test” without saying what you are worried about. Each type simulates a different adversary and examines a different part of your exposure. This guide explains the main types by target, external, internal, application, and social engineering, along with the knowledge levels that shape any of them, so you can choose the test that actually answers your question. It is written to help you scope and buy the right assessment, not to teach attack techniques.

The two ways pentests are categorized

Pentests are classified along two independent dimensions, and understanding both prevents confusion when scoping a project.

The first dimension is by target: what part of the organization is being tested. This is where external, internal, application, and social engineering live. The second dimension is by knowledge level: how much information the tester is given before starting, which is where black box, gray box, and white box come in. These two dimensions combine. You might commission a gray box application pentest, or a black box external pentest. The target defines what is being tested, and the knowledge level defines how realistically it simulates an outsider versus how thoroughly it audits from the inside.

The main types of pentest at a glance

The table below summarizes the main types by target. Each section that follows explains one in depth.

Types of pentest at a glance (responsive)
Type What it tests Simulates Best when
External Internet-facing assets: websites, VPN, mail, public servers An outside attacker with no prior access You need to know your real exposure from the internet
Internal Systems reachable from inside the network An insider, or an attacker who breached the perimeter You want to test segmentation and contain lateral movement
Application Web apps, APIs, and mobile apps An attacker abusing application logic and inputs You are launching or depend on a critical application
Social engineering People and processes An attacker manipulating employees You want to test the human layer and awareness

External pentest

An external pentest assesses everything your organization exposes to the internet, and it simulates the most common starting point for a real attack: an outsider with no prior access probing your perimeter from outside.

The targets include public websites and web applications, VPN and remote access gateways, mail servers, and any other public-facing infrastructure. The goal is to answer a direct question: what can an attacker reach and compromise starting from the open internet, with nothing but your public footprint to work from. The categories of weakness this test surfaces typically include exposed or misconfigured services, weak authentication on internet-facing systems, outdated software with known vulnerabilities, and information leakage that helps an attacker plan.

An external pentest is the right starting point for most organizations, because the perimeter is where attacks usually begin. It is also frequently the type required to satisfy compliance obligations and cyber insurance questionnaires. If you only run one kind of test, the external pentest is usually the one that maps most directly to real-world risk.

Internal pentest

An internal pentest assesses what an attacker could do once they are already inside the network, whether through a phished employee, a compromised device, or a malicious insider. It answers a different and equally important question: if the perimeter is breached, how bad does it get.

This test focuses on the systems, services, and privileges reachable from within the corporate network. The central concerns are lateral movement, how easily an attacker can spread from one foothold to other systems, and privilege escalation, how easily they can gain higher access, ideally up to full domain control. It also tests segmentation, meaning whether sensitive parts of the network are properly isolated from the rest. The findings often reveal that a single compromised laptop could lead to control of critical systems, which is precisely the scenario ransomware exploits.

An internal pentest matters because perimeter breaches are not a matter of if but when. An organization with a strong external posture but a flat, unsegmented internal network is one phishing email away from a major incident. Testing internally is how you measure and reduce that blast radius.

Application pentest

An application pentest focuses on the software an organization builds or relies on, rather than on the infrastructure around it. As business moves into web and mobile applications and the APIs that connect them, this has become one of the most important types of test.

There are three closely related targets. Web application testing examines websites and web platforms, guided by the OWASP Top 10, the widely used list of the most critical web application risks such as injection, broken authentication, and broken access control. API testing examines the interfaces that applications use to communicate, guided by the OWASP API Security Top 10, and matters because APIs now carry much of the sensitive data flowing between systems. Mobile application testing examines iOS and Android apps and the way they store data and communicate, guided by standards such as the OWASP MASVS.

What sets application testing apart is that it targets business logic and how the application handles input and access, things an infrastructure scan cannot see. A well-configured server can still run an application with a flaw that exposes every customer record. An application pentest is essential whenever you launch a new application, make significant changes to an existing one, or depend on an application that handles sensitive data or transactions.

Social engineering

A social engineering assessment tests the human layer, which is consistently one of the most exploited paths into an organization. Instead of attacking technology, it simulates an attacker manipulating people into granting access or revealing information.

Conducted under strict rules of engagement and with proper authorization, this type of test can include controlled phishing campaigns that measure how employees respond to deceptive emails, pretexting where a tester poses as a trusted party to request access or information, and vishing, the voice-based equivalent conducted by phone. The purpose is never to embarrass individuals. It is to measure, at the organizational level, how susceptible the workforce is and how well existing awareness training and processes hold up under a realistic attempt.

Social engineering testing matters because attackers know that people are often easier to compromise than well-defended systems. An organization can have excellent technical controls and still be breached through a single convincing email. Testing the human layer, and using the results to improve training and process rather than to punish, closes a gap that technology alone cannot.

Other types worth knowing

Beyond the four main types, several more specialized assessments exist for specific environments:

  • Cloud pentest: assesses configurations in AWS, Azure, or GCP, where misconfiguration is the leading cause of exposure, measured against benchmarks such as the CIS Benchmarks.
  • Wireless pentest: examines the security of Wi-Fi networks and the risk of unauthorized access through them.
  • Physical pentest: tests physical controls, such as whether someone can gain unauthorized entry to a facility or a server room.

Red team: not a single-target test but a broad, objective-based simulation of a real adversary that may combine several of the above, without warning the defense team, to test detection and response as a whole.

Black box, gray box, and white box

Independent of the target, every pentest is shaped by how much the tester is told in advance. This knowledge level is a deliberate scoping choice with real trade-offs.

Black box, gray box, white box (responsive)
Model Knowledge given Simulates Trade-off
Black box None An external attacker working blind Most realistic exposure, but time is spent on reconnaissance
Gray box Partial, such as a standard user credential An insider or an attacker who already has a foothold Best coverage for the budget, the common default
White box Full, including architecture and sometimes source code A thorough audit with complete access Most exhaustive, higher effort and cost

For most engagements, gray box offers the best balance, because giving the tester a normal user account avoids spending days on reconnaissance and lets the time go into finding real issues. Black box maximizes realism when the goal is specifically to measure external exposure. White box is reserved for the deepest assurance on the most critical applications.

How to choose the right type

The right type of pentest follows directly from the question you are trying to answer. A few practical guides:

  1. If you want to know your exposure from the internet, start with an external pentest.
  2. If you want to know how far an attacker gets after a breach, run an internal pentest and test segmentation.
  3. If you are launching or depend on a critical application, commission an application pentest of the relevant web, API, or mobile surface.
  4. If you want to measure the human layer and the value of your awareness program, add a social engineering
  5. If your controls are mature and you want to test detection and response holistically, graduate to a red team.

Most organizations do not need every type at once. A sensible program starts with external and application testing, adds internal testing as it matures, and layers in social engineering and eventually red teaming over time. The goal is coverage of the risks that matter to your business, not a checkbox for every possible test.

How Mercurius approaches pentest types

Mercurius scopes each engagement to the risk question the client actually needs answered, rather than selling a generic test. That means recommending the type or combination of types, external, internal, application, or social engineering, and the knowledge level that will produce the most useful result for the environment and the budget. Every engagement is run by certified engineers against recognized methodologies such as PTES, OWASP, and NIST SP 800-115, mapped to MITRE ATT&CK, with a report that prioritizes remediation by real business impact.

The guiding principle is fit. A new customer-facing application calls for a different test than a mature internal network, and a strong provider says so rather than applying one template to every client.

Frequently asked questions

What are the main types of pentest? The main types by target are external, internal, application, and social engineering. External tests your internet-facing exposure, internal tests what an attacker can do inside the network, application tests your web, API, and mobile software, and social engineering tests the human layer. Pentests are also categorized by knowledge level as black box, gray box, or white box.

What is the difference between an external and an internal pentest? An external pentest simulates an outside attacker probing your internet-facing systems, measuring your exposure from the open internet. An internal pentest simulates an attacker who is already inside the network, measuring lateral movement, privilege escalation, and segmentation. External answers how they get in, internal answers how bad it gets once they do.

What is the difference between black box, gray box, and white box? They describe how much the tester knows in advance. Black box gives no prior knowledge and simulates an external attacker working blind. Gray box gives partial knowledge, such as a user account, and offers the best coverage for the budget. White box gives full access, including architecture and sometimes source code, for the most thorough audit.

Which type of pentest does my company need? It depends on your question. Start with an external pentest to understand internet exposure, add an application pentest if you rely on critical software, and add an internal pentest to measure the impact of a breach. Social engineering and red teaming come later as the program matures.

Is social engineering testing ethical? Yes, when conducted with proper authorization and strict rules of engagement. The purpose is to measure organizational susceptibility and improve awareness and process, never to embarrass individuals. Results are used to strengthen training, not to punish employees.

How often should each type of pentest be run? The general guidance is at least annually and after significant changes. Application tests should follow major releases, external tests should follow changes to the perimeter, and internal tests should follow network or architecture changes. High-criticality environments often test their most exposed assets more frequently.

Did you enjoy the content? Share it with your network!

Categories

Last contents