Penetration Testing
An authorized simulated attack on a system to find exploitable security weaknesses before real attackers do.
Penetration testing↗, often called a "pen test," is an authorized, simulated attack on a system, network, or application, carried out specifically to find exploitable security weaknesses before real attackers do. Unlike an automated vulnerability↗ scan, a pen test is performed by skilled human testers who think and act like an actual adversary.
Pen testers use many of the same tools and techniques as criminal hackers, but under a legal agreement that defines exactly what they're allowed to test and how findings will be reported and fixed. Regular penetration testing is a standard requirement in many security frameworks and compliance regimes, precisely because it reveals real-world exploitability that theoretical risk assessments alone can miss.