Mediaspace scheduled maintenance: Aug 25, 2026 07:00 - 12:00 AM. During this time, videos will be temporarily unavailable. Check status updates.
A penetration test, colloquially known as a pentest or ethical hacking, is an authorized simulated cyberattack on a computer system, performed to evaluate the security of the system; this is not to be confused with a vulnerability assessment. The test is performed to identify weaknesses (or vulnerabilities), including the potential for unauthorized parties to gain access to the system's features and data, as well as strengths, enabling a full risk assessment to be completed. The process typically identifies the target systems and a particular goal, then reviews available information and undertakes various means to attain that goal. A penetration test target may be a white box (about which background and system information are provided in advance to the tester) or a black box (about which only basic information other than the company name is provided). A gray box penetration test is a combination of the two (where limited knowledge of the target is shared with the auditor). A penetration test can help identify a system's vulnerabilities to attack and estimate how vulnerable it is. Security issues that the penetration test uncovers should be reported to the system owner. Penetration test reports may also assess potential impacts to the organization and suggest countermeasures to reduce the risk. The UK National Cyber Security Center describes penetration testing as: "A method for gaining assurance in the security of an IT system by attempting to breach some or all of that system's security, using the same tools and techniques as an adversary might." The goals of a penetration test vary depending on the type of approved activity for any given engagement, with the primary goal focused on finding vulnerabilities that could be exploited by a nefarious actor, and informing the client of those vulnerabilities along with recommended mitigation strategies. Penetration tests are a component of a full security audit. For example, the Payment Card Industry Data Security Standard requires penetration testing on a regular schedule, and after system changes.
Olivier Sauter, Martinus Adela Maria Gijs, Jonathan Graves, Ambrogio Fasoli, Stefano Coda, Basil Duval, Henri Weisen, Richard Pitts, Yves Martin, Javier García Hernández, Duccio Testa, Miguel Fernández Ruiz, Nicola Vianello, Robin Humphry-Baker, Sun Hee Kim, Federico Nespoli, Patrick Blanchard, Alessandro Pau, David Pfefferlé, Davide Galassi, Jonathan Marc Philippe Faustin, Cristian Sommariva, Hamish William Patten, Samuel Lanthaler, Jan Horacek, Yann Camenen, Bruno Emanuel Ferreira De Sousa Correia, José Pedro Rebelo Ferreira Marques, Mikhail Maslov, Marco Wischmeier, Dalziel Joseph Wilson, Liang Yao, Daniel Scott Alessi, Arnout Lodewijk M Beckers, Ana Francisca Leal Silva Soares, Jonnathan Cesar Hidalgo Acosta, Antonio José Pereira de Figueiredo, Partha Dutta, Pierre-Thomas Paul Brun, Pedro Camilo de Oliveira e Silva, Alberto Hernando de Castro, Julio Rodriguez, Vlad Trifa, Li Shuai, Rebecca Hill