patch&proof.
← Research library

Testing / Research chapter

Penetration Testing and Ethical Hacking: An Authorized-Practice Guide

Scope statement for the site — publish this, or something like it, on every page in this section. Everything below describes authorized, legal security assessme

From the supplied September 2026 research package. Historical figures and evolving policy require source review; see the correction record.

Research date: September 14–15, 2026.

Scope statement for the site — publish this, or something like it, on every page in this section. Everything below describes authorized, legal security assessment, professional practice, and education in self-contained training environments. Tools are named only with their purpose and licensing. This material contains no exploitation procedures, no attack code, and no evasion techniques. Testing any system you do not own, without written authorization from someone with authority over it, is a criminal offense in most jurisdictions regardless of intent.


1. The distinction buyers get wrong most often

Vulnerability assessment Penetration test
Method Largely automated scanning plus triage; breadth-first Human-led, hypothesis-driven testing that validates and chains weaknesses; depth-first
Output A prioritized list of potential weaknesses, with false positives Verified findings with demonstrated business impact, attack narratives, and remediation guidance
Cadence Continuous, monthly, or quarterly Point-in-time (annual or semi-annual), or continuous via PTaaS
Cost Often $1,000–$5,000, or bundled into a scanning subscription Typically $5,000–$50,000+ depending on scope
When appropriate Hygiene, patch validation, compliance scanning, asset discovery Before major launches, for compliance (PCI DSS, SOC 2, HIPAA, DORA, NIS2), after architecture changes, to test detection and response assumptions

The rule of thumb for learners: a scan finds possible problems; a penetration test proves actual, exploitable problems and their business impact — in a controlled, authorized way, with evidence. Conflating the two is the most commonly abused sales tactic in this market.


2. Assessment types, purposes, and 2025–26 cost ranges

Ranges below synthesize multiple 2026 buyer's guides. Complexity, tester seniority, compliance driver, and geography all move prices substantially.

Web application testing. Authentication, authorization, session handling, input handling, and business logic assessed against OWASP WSTG, the Top 10, and ASVS. $5,000–$50,000 by complexity — roles, pages, workflows. Deliverables: technical report, severity-rated findings with reproduction evidence, executive summary, retest letter or attestation.

API testing. REST, GraphQL, and gRPC endpoints: broken object-level authorization, excessive data exposure, rate limiting, authentication flaws. $5,000–$30,000, scaling with endpoint count. Increasingly bought separately from web-app tests because APIs power mobile and partner integrations.

Mobile application testing. iOS and Android assessed against OWASP MASVS using the MASTG: insecure storage, transport security, platform API misuse, reverse-engineering resilience. $5,000–$40,000 depending on platforms.

Cloud security assessments. Configuration review plus identity and permission analysis plus, where provider policy allows, authorized testing in AWS, Azure, or GCP: IAM privilege paths, storage exposure, segmentation, logging gaps. $5,000–$50,000. Cloud providers no longer require pre-approval for most customer-owned-resource testing, but acceptable-use policies still constrain scope — notably prohibiting denial-of-service testing.

External network testing. Internet-facing infrastructure. Often priced per asset at roughly $150–$1,000 per device, with engagements commonly $5,000–$20,000.

Internal network testing. Assumed-breach perspective from inside the LAN: segmentation, Active Directory weaknesses, lateral-movement paths, credential hygiene. Usually $10,000–$40,000, more than external because scope is larger.

Wireless testing. Enterprise Wi-Fi configuration, rogue-AP detection, guest segmentation, WPA-Enterprise deployment review. Typically the cheapest infrastructure test: low thousands to roughly $15,000 per site.

Social-engineering assessments. Authorized phishing, vishing, smishing, and pretexting exercises measuring awareness-program effectiveness, always under written rules of engagement with HR and legal sign-off. Consultant-run campaigns commonly $4,000–$20,000; phishing-simulation platforms price per user per year.

Physical-security assessments. Authorized testing of badge controls, tailgating resistance, visitor management, and sensitive-area access, with authorization letters carried on-site. Often combined with social engineering; commonly $10,000+ depending on site count.

Red teaming. Objective-based, multi-week covert exercises emulating a realistic adversary end to end, to test people, process, and technology — especially detection and response — rather than enumerate every bug. Appropriate only for organizations with a mature program and a functioning SOC. $10,000 for small scoped engagements to $100,000+ for full-scope multi-week operations.

Blue teaming. The defensive discipline, bought as SOC assessments, detection-capability reviews, tabletop exercises, and IR-readiness assessments.

Purple teaming. Collaborative exercises in which attackers execute known techniques, mapped to MITRE ATT&CK, while defenders tune detections in real time. Better learning per dollar than covert red teaming for organizations at middling maturity — and the single best recommendation for most mid-market readers who think they want a red team.

Bug-bounty programs. Crowdsourced, continuous, pay-per-valid-finding programs on platforms (HackerOne, Bugcrowd, Intigriti, YesWeHack) or self-hosted. Complementary to, not a replacement for, scoped tests. HackerOne's 2025 report cited $81M in bounties paid over the year and a 210% spike in AI-vulnerability reports. Program cost equals platform fees plus bounty pool. The correct sequence for a new program is vulnerability disclosure policy first, then a private bounty, then public — running a public bounty before you can triage findings produces a backlog and a reputation problem.

Secure code review. Manual plus tool-assisted source review, strongest for logic flaws, cryptographic misuse, and authorization bugs that black-box testing misses. Priced by codebase size and criticality; often bundled with threat modeling.

Threat modeling. Structured design-stage analysis, commonly using STRIDE, identifying threats before code ships — the cheapest place to fix anything. Deliverables: data-flow diagrams, a ranked threat register, and mitigations.

Adversary simulation and breach-and-attack simulation. Platforms that continuously and safely execute known attacker techniques, mapped to ATT&CK, against production defenses to validate controls. Commercial: Picus, Cymulate, SafeBreach, AttackIQ, Pentera. Open source for lab and defense-validation use: MITRE Caldera and Red Canary's Atomic Red Team. These belong to blue-team and purple-team validation and are subject to the same authorization rules as any test.


3. Tools named in lawful assessments — purpose and licensing only

  • Burp Suite (PortSwigger) — web and API testing proxy. Community edition free; Professional roughly $449 per user per year.
  • OWASP ZAP — free, open-source web application scanner and proxy; common in education.
  • Nmap — free, open-source network discovery and service enumeration; the standard for authorized network mapping.
  • Wireshark — free protocol analyzer for authorized traffic analysis and teaching.
  • Metasploit Framework — open-source exploitation framework used in authorized tests and labs; Metasploit Pro adds reporting and automation.
  • Kali Linux — free Debian-based distribution bundling assessment tools; the default lab and teaching OS.
  • Nessus / Qualys / OpenVAS (Greenbone) — vulnerability scanners. Nessus Professional roughly $4,790 per year; OpenVAS free.
  • MITRE Caldera / Atomic Red Team — free adversary-emulation and detection-validation tooling.

All of these are lawful to possess and to learn. What is regulated is use against systems without authorization — the US Computer Fraud and Abuse Act, the UK Computer Misuse Act, and equivalents elsewhere. Any page naming these tools should carry the authorization rules in section 4 on the same page, not behind a link.


4. Professional practice: authorization, scope, rules of engagement

Written authorization is the non-negotiable foundation. The signed authorization letter — colloquially the "get-out-of-jail letter" — must name the authorized testers, the client signatory with authority over the tested assets, the exact scope (IP ranges, domains, applications, facilities), dates and windows, permitted techniques, and emergency contacts. Physical testers carry it on their person. Third-party-hosted assets require the host's authorization too, which means cloud providers and managed service providers.

Scoping defines the target inventory, test type (black, grey, or white box), credentials provided, environments (production versus staging), exclusions, and success criteria. A scoping questionnaire and a kickoff call are marks of a serious provider.

Rules of engagement codify testing windows, throttling and safety controls (no destructive testing, no denial of service unless explicitly agreed, stop conditions), handling of discovered live compromises (immediate escalation — if a tester finds an actual intruder, the engagement becomes an incident), social-engineering guardrails, and out-of-scope systems such as safety systems, medical devices, and third parties.

Data handling. Testers minimize collection of real data, encrypt evidence in transit and at rest, agree retention and destruction timelines, and never exfiltrate more than needed to demonstrate impact. The report itself is sensitive and should be distributed on a need-to-know basis.

Communication plans. Named contacts on both sides, daily or milestone check-ins, an out-of-band emergency channel, and immediate notification for critical findings — do not wait for the report.


5. Reporting, severity, remediation, and disclosure

Report quality separates real penetration tests from repackaged scans. A good report has an executive summary in business language, a stated methodology, per-finding evidence, realistic impact, root cause, and actionable remediation — not scanner boilerplate.

Severity in 2025–26 is moving from raw CVSS to blended, risk-based scoring. CVSS v4.0 (FIRST, November 2023) is the default base-severity standard, with better granularity and explicit threat and environmental supplemental metrics. EPSS estimates the probability that a vulnerability will be exploited in the wild within 30 days and is used to prioritize among high-CVSS findings. CISA's SSVC decision-tree model is the leading "decision, not score" alternative. Good reports contextualize all of these with business context; single-metric ranking is increasingly criticized.

Remediation and retesting. Professional engagements include a remediation-verification window, often 30 to 90 days, and a retest letter or attestation confirming fixes — essential for compliance evidence. Ask up front whether retesting is included or billed separately.

Evidence preservation. Testers keep timestamped logs of all activity, which protects both parties if an unrelated incident occurs during the testing window, preserve finding evidence for the retest, then destroy client data per contract.

Coordinated vulnerability disclosure. When researchers find flaws in vendor products, coordinated disclosure through the vendor or a coordinator is the professional norm. CISA, NSA, and international partners published joint guidance on establishing CVD programs in July 2026 — the current reference for organizations building programs with safe-harbor language for good-faith researchers. The norms beneath it: ISO/IEC 29147 (disclosure) and 30111 (handling), the CERT/CC guide, and RFC 9116's security.txt for publishing contact points. CISA's Binding Operational Directive 20-01 requires every US federal civilian agency to publish a vulnerability disclosure policy with legal safe-harbor language. In the EU, NIS2 Article 12 established the European vulnerability database, and the Cyber Resilience Act makes vulnerability-handling processes a legal product requirement.

What safe harbor actually is. A contractual promise by one organization not to sue or refer researchers acting within its policy, standardized by disclose.io and platform terms. It cannot authorize testing third-party systems, and it does not bind prosecutors — though the US DOJ's 2022 charging policy plus documented authorization makes federal prosecution of in-scope good-faith work very unlikely. Teach it as a promise, not immunity.


6. How to buy a good penetration test — and spot a bad one

Green flags. Named, credentialed testers (OSCP/OSCP+, CPTS, CRT/CCT, GPEN/GWAPT) you can vet — ask who will actually do the work. Firm-level accreditation such as CREST membership, which is internationally recognized and mandatory for some UK and Australian government and financial work, plus SOC 2 for the provider itself. A real scoping call. A methodology mapped to standards (WSTG, PTES, NIST SP 800-115). A sanitized sample report before purchase. Manual-testing hours explicitly quoted. Findings with reproduction evidence. Free or clearly priced retesting. A debrief call.

Red flags. A price far below market — a "$500 pentest" of a full web application is a scan with a template. Twenty-four to forty-eight-hour turnaround on a complex scope. A report that is clearly raw scanner output with unverified false positives and generic remediation text. No named testers, no methodology, refusal to share a sample report. "Unlimited penetration testing" with no defined human hours. And the most telling: no rules-of-engagement or authorization paperwork discipline — a provider careless with legal basics will be careless with your systems.

Provider certification landscape. CREST accredits both companies and individuals (CPSA → CRT → CCT) and runs an equivalency recognition programme through which OSCP holders can gain CRT equivalence in some regions.


7. Methodologies and standards

  • NIST SP 800-115 — the US government's Technical Guide to Information Security Testing and Assessment: planning, discovery, attack, and reporting phases. Published 2008 and never revised, but still the compliance backbone for US federal-aligned testing.
  • OWASP WSTG — the de facto web-application testing checklist and methodology.
  • OWASP MASVS / MASTG — the mobile verification standard and testing guide, with assessment and certification profiles.
  • OWASP ASVS 5.0 — released May 2025 with restructured chapters, a clearer three-level model, and modernized cryptography and authorization requirements. This is the reference bar for "how secure should this application be" and for verification-style assessments.
  • PTES — a seven-phase engagement lifecycle from pre-engagement through reporting; widely cited for engagement structure.
  • OSSTMM (ISECOM) — quantitative, operational-security-metrics methodology; less common commercially now but historically influential.
  • CREST — the accreditation body whose standards define engagement quality for member firms; CBEST and TIBER-EU intelligence-led red-team frameworks in financial services build on it, and DORA's threat-led penetration testing requirements for significant entities sit in the same family.
  • MITRE ATT&CK in assessments — the shared taxonomy: red and purple teams map executed techniques to ATT&CK IDs so defenders can map detections and gaps.

PTaaS and continuous validation — the defining 2024–26 trend. Penetration Testing as a Service platforms (Cobalt, Synack, HackerOne Pentest, Bugcrowd, BreachLock, Astra and others) deliver tests through a portal: launch in days rather than weeks, real-time findings with ticketing integration, on-demand retesting, and vetted bench testers. This is shifting the market away from annual PDF reports toward continuous validation, which combines PTaaS with breach-and-attack simulation and exposure management under Gartner's CTEM framing. The trade-off: PTaaS excels at web, API, and cloud breadth and speed; deep bespoke work — red teams, embedded systems, complex business logic — still favors specialist consultancies.


8. Training and education

All platforms below are legal, self-contained lab environments. The golden rule to state plainly: everything in the lab, nothing outside it.

Hands-on platforms

Hack The Box. Labs: free tier for active machines; VIP+ $25/month or roughly $223/year; Pro Labs $49/month. HTB Academy is separate: Student plan $96/year with an .edu email, Silver $490/year including an exam voucher, Gold $1,260/year. Certifications: CPTS (Certified Penetration Testing Specialist) and CDSA (Certified Defensive Security Analyst) exams at roughly $210 each, CWEE and CAPE around $350. CPTS is a ten-day full-engagement exam requiring a commercial-grade report and is widely regarded as technically harder and more realistic than OSCP — though it remains a weaker HR filter. Best for intermediate to advanced learners.

TryHackMe. Guided rooms with browser-based VMs; the gentlest on-ramp. Free tier; Premium $16.99/month or roughly $126/year with a student discount. Structured career paths (Pre-Security, SOC Level 1 and 2, Junior Penetration Tester). Best for absolute beginners through early intermediate, and for blue-team fundamentals.

PortSwigger Web Security Academy. Free, built by the Burp Suite vendor, and the best structured web-application security curriculum available, with hands-on labs for every major vulnerability class and a path to the Burp Suite Certified Practitioner exam (roughly $99). Universally respected and frequently named in job postings.

OverTheWire. Free wargames played over SSH — Bandit for Linux fundamentals, Natas for web. The traditional first step for command-line skills.

CyberDefenders. Blue-team practice with DFIR and SOC challenges using real artifacts (packet captures, memory images). Free challenges plus a paid subscription and the Certified CyberDefender credential. Strong reputation for SOC-analyst interview preparation.

Blue Team Labs Online. Security Blue Team's defensive platform with free and paid tiers, companion to the well-regarded BTL1 certification (roughly $399), focused on triage, DFIR, and detection.

Certification tracks

OffSec OSCP → OSCP+. The HR-recognized standard for penetration-test hiring. Since November 1, 2024, passing grants both the lifetime OSCP and a three-year-expiring OSCP+, renewable through continuing education or re-examination; the ten bonus points were eliminated, making the 24-hour practical exam strictly performance-based. 2026 pricing: Course and Cert bundle $1,749 (90-day lab access, one attempt), Learn One $2,749/year (two attempts), retakes $249. Advanced track: OSEP (evasion), OSWE (web, source-driven), OSED (exploit development).

TCM Security. PJPT (junior, internal AD focus, roughly $249) and PNPT (Practical Network Penetration Tester) at $499 including training, a five-day practical exam plus two-day report and live debrief, and one free retake. Non-expiring. TCM now requires AI-tool disclosure in exam reports. Excellent value and realism; recognition below OSCP but rising.

INE Security eJPT. Entry-level practical certification at roughly $249 with training bundles; the standard first offensive certification.

SANS/GIAC. The gold standard for depth and employer trust, priced accordingly: courses roughly $8,000–$10,000+ each with a GIAC attempt, or roughly $999 for a standalone exam. Relevant: GPEN (network), GWAPT (web application), GXPN (advanced), plus the blue-team line (GCIH, GCIA, GCFA, GREM). Usually employer-funded; strongest in government, defense, and large enterprise.

CREST individual certifications. CPSA, CRT, CCT — required at CREST-member firms and for UK and Australian regulated work, with OSCP equivalency routes in some regions.

CompTIA PenTest+ and Security+. Multiple-choice plus performance-based questions, valued for DoD 8140 compliance and HR baselines rather than as hands-on proof.

What employers value in 2026

Practical, proctored, report-producing certifications — OSCP and OSCP+ remain the top HR filter, with CPTS and PNPT rising fast as proof of real skill — plus demonstrable work: lab rankings, CTF results, home-lab writeups, open-source contributions, and bug-bounty acknowledgments. Multiple 2026 guides converge on the same two conclusions: hands-on beats multiple-choice, and report-writing and communication are the differentiator between candidates. That is precisely why PNPT and CPTS-style exams, which require a professional report and a debrief, are gaining employer respect.

Universities, CTFs, and home labs

In the US, look for NSA/DHS Centers of Academic Excellence designations (CAE-CD, CAE-CO). Degrees still matter most for government clearance pipelines; industry hiring increasingly weighs practical portfolios equally.

CTFtime remains the global calendar and ranking hub. picoCTF — Carnegie Mellon's beginner CTF — has rebranded as CyLab Security Academy, still free and still the standard entry point for students, and it anchors NSA GenCyber camps. Jeopardy CTFs teach breadth; attack-defense CTFs teach operations.

Home labs, legal and self-contained: virtualization (VirtualBox, VMware, Proxmox) running deliberately vulnerable targets — Metasploitable, OWASP Juice Shop, DVWA, VulnHub images — plus a Kali VM, all on an isolated host-only network. Add a small Active Directory lab and free detection tooling (Wazuh or Elastic, plus Atomic Red Team for detection validation) for purple-team practice. This is also the best portfolio material a job candidate can produce.


9. Cost cheat sheet

Item Typical range
Vulnerability assessment $1K–$5K (or a scanning subscription)
Web app pentest $5K–$50K
API pentest $5K–$30K
Mobile app pentest $5K–$40K
Cloud assessment $5K–$50K
External network $150–$1,000/device; $5K–$20K typical
Internal network $10K–$40K
Wireless Low thousands–$15K per site
Social engineering $4K–$20K per campaign
Red team $10K–$100K+
Bug bounty Platform fee plus bounty pool
OSCP bundle $1,749 (Learn One $2,749/yr)
HTB CPTS exam ~$210 (plus Academy $490–$1,260/yr)
PNPT $499 all-in
eJPT ~$249
SANS course plus GIAC ~$9K–$11K
TryHackMe / HTB VIP+ ~$126/yr / ~$223/yr
PortSwigger Academy, OverTheWire Free

10. The safety line the site must hold

Three rules, applied editorially to every page in this section:

  1. Authorization first, always. Every mention of a technique, tool, or lab is paired with the authorization requirement. Never describe how to perform an attack against a system; describe what class of weakness exists, why it matters, and how to fix or detect it.
  2. Concepts, not procedures. Readers should finish a page understanding what broken object-level authorization is, why it dominates API breaches, and how to test for and fix it in their own application under authorization — not holding a copy-pasteable exploit.
  3. Point practice at legal targets. Every skills page ends with the same routing: PortSwigger Academy, TryHackMe, Hack The Box, OverTheWire, CyberDefenders, VulnHub, or an in-scope bug-bounty program. Never toward live third-party systems.

Evidence & dates

Follow the source.

Source published
See individual source / original research
Event date
No single confirmed day assigned
Site publication
Unpublished · local review
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval