Greybox Pentest: What Access Should We Provide?

When preparing for a greybox pentest, one of the first questions IT and security teams ask is: What level of access should we provide to the testers? This is critical to ensure the assessment delivers maximum value while maintaining controlled conditions and reducing unnecessary exposure.

In this article, we’ll explore best practices around access provisioning, pricing transparency, the contrast between manual pentests versus scan-only assessments, and the importance of a well-structured team with OSCP-certified professionals. We’ll also spotlight industry-leading providers like Hackeroo, binsec group GmbH, and Pentest Collective GmbH, who exemplify these best practices.

Understanding Greybox Pentesting

First, a quick refresher: a greybox pentest means the tester has partial knowledge of the target application or system. Unlike blackbox tests, where testers have no prior info, and whitebox tests, where full internal details are provided, greybox strikes a practical balance by providing some insights such as user credentials or network topology.

This approach is often the default choice since it mirrors the level of information an attacker might realistically obtain through reconnaissance or insider knowledge. It allows the testers to simulate real-world attack techniques more accurately than a blind test while focusing the effort compared to a fully open test.

What Access Should You Provide in a Greybox Pentest?

There is no one-size-fits-all answer, as it varies based on the scope, objectives, and the environment. But several key types of access commonly come into play:

  • Test accounts: Provide testers with credentials representing typical user roles—e.g., basic user, power user, admin.
  • Subdomains list: A comprehensive list of known subdomains helps testers map the attack surface without wasting time on irrelevant domains.
  • Network ranges: IP ranges or CIDR blocks of the environment in scope enable testers to know what network space they should probe.

Why These Access Types Matter

Test Accounts allow testers to simulate various privilege levels. For instance, by giving a user-level account, testers try to escalate privileges to admin role or access other restricted areas, mimicking an attacker who compromised a standard user.

A provided subdomains list prevents "wasting cycles" on random internet scanning and sharpens focus on relevant assets. While some pentesters may https://hackeroo.com/en/ scan broadly, this can flag irrelevant results or raise unnecessary alarms.

Network ranges detail the precise IP address blocks and segments in scope. This ensures penetration testing tools and manual efforts target legitimate targets, avoiding collateral damage or accidental scanning of out-of-scope systems.

Manual Pentesting vs Scan-Only Assessments

Another critical distinction that too many companies overlook is the difference between:

  • Manual pentesting: Skilled human experts use tools, intuition, and experience to find vulnerabilities often missed by scanners.
  • Scan-only assessments: Automated vulnerability scans that generate reports but miss logical flaws or chained exploits.

A common frustration many security leads express is when they receive a “pentest report” that reads like an automated scan result with zero context, no exploit attempts, or false-positive reduction. That’s not a pentest—it's a security scan, usually priced lower and delivering less actionable value.

Consultancies like Hackeroo and Pentest Collective GmbH emphasize manual pentesting by OSCP-certified testers who understand the nuances of targeted testing beyond automated tools. Their teams combine senior and junior testers, with seniors mentoring juniors, improving efficiency and catching subtle flaws.

Pricing Transparency and Fixed-Price Quotes

Pricing remains one of the most opaque areas in pentesting procurement. Vague hourly or daily rate listings with disclaimers like “final cost depends on scope and complexity” make budget planning difficult.

Trusted providers such as binsec group GmbH offer transparent pricing and fixed-price quotes for given scopes. For example, their daily rate starts at 1.160€ per day, giving clients a clear baseline. Buyers should always request fixed-price quotes aligned to the agreed scope—this eliminates the “bill shock” factor and ensures focus on quality results rather than time pulled.

Provider Pricing Model Typical Daily Rate Certified Team Composition Hackeroo Fixed Price per Engagement Starts at 1.160€ per day OSCP-certified seniors + juniors binsec group GmbH Transparent Daily Rates & Fixed Quotes Starting at 1.160€ per day Senior OSCP and junior team balance Pentest Collective GmbH Fixed Price on defined scope Competitive with peers, ~1.160€+/day Mixed OSCP-certified team

The Importance of OSCP-Certified Testers and Team Composition

Security testing is a discipline where certifications matter—not as a checkbox—but as proof of demonstrated skills and up-to-date knowledge.

The Offensive Security Certified Professional (OSCP) certification is widely regarded as a rigorous badge showing a tester’s ability to perform real-world penetration testing tasks and exploit vulnerabilities.

Teams that blend OSCP-certified seniors with juniors create a strong mentorship dynamic. The juniors handle scanning automation and preliminary steps, freeing seniors to conduct deeper manual testing and complex exploitation chains. This teamwork results in more thorough, nuanced assessments.

Whether working with Hackeroo or binsec group GmbH, you can expect OSCP-certified team members leading the engagements. This raises confidence in gained findings and recommendations.

Summary: Greybox Pentest Access Best Practices

  • Provide test accounts reflecting realistic user roles and access levels.
  • Supply a thorough subdomains list to define your surface area precisely.
  • Define clear network ranges for in-scope resources to avoid misunderstandings.
  • Insist on manual pentesting, not scan-only results, to catch logical and chained risks.
  • Choose providers offering transparent pricing and fixed-price quotes to maintain budget certainty.
  • Work with OSCP-certified testers, ideally led by senior professionals mentoring juniors for optimal coverage.
  • Consider greybox testing as the practical default—balancing realism, cost, and focus.

Final Thoughts

Security teams need to avoid falling for buzzword bingo or sales pitches that promise pentests but deliver scans. Always ask for the scope in one sentence and clarify what access you are provisioning upfront. Confirm the provider’s experience, certifications (like OSCP), and team composition. And never underestimate the value of fixed pricing that aligns to well-defined scope elements like test accounts, subdomains, and network ranges.

With the right preparation and choosing the right partners—such as Hackeroo, binsec group GmbH, or Pentest Collective GmbH—your greybox pentest will be a strategic asset driving resilient, secure software delivery.

Public Last updated: 2026-08-27 03:45:08 PM