All research

Check, scan, or full pentest?

Short answer: A vulnerability scan is a cheap automated list of known issues. An attack-surface check is a focused, human-reviewed first look at your exposed surface. A full penetration test is days of manual, in-depth exploitation. Run scans for regular coverage, a check for a fast honest first look, and a full pentest when you need audit-grade depth.

The word "pentest" gets stretched over three very different things, and the price tags range from free to five figures. If you are buying, that gap is confusing on purpose in some corners of the market. Here is the honest version, so you can tell what you are actually getting.

A vulnerability scan

A scanner is an automated tool that checks your systems against a database of known issues. It is fast, cheap, and worth running regularly. It is also noisy: it produces long lists, it does not understand your business logic, and it cannot chain two medium issues into one serious one. A scan tells you what is possibly wrong. It does not tell you what an attacker would actually do.

Under the hood, a scanner matches what it can see, open ports, service banners, software versions, response headers, against a database of known issues and reports every hit. That makes it repeatable and fast, and good at the unglamorous problems that pile up: missing patches, expired certificates, default configurations, an admin panel left open to the internet. Its limit is built in. It reports what matches a signature, not what is exploitable in your context, so a finding marked critical may sit unreachable behind other controls while one marked low is the exact foothold an attacker wants. Until someone with judgment triages the list, it is mostly noise.

An attack-surface check

A check sits in the middle. It looks at your exposed surface the way an attacker starts an engagement, and combines automated coverage with the judgment of a senior operator who reviews and explains the result. It is deeper than a scan because someone who has actually broken into things decides what matters. It is lighter than a full engagement because it is time-boxed and focused. This is the tier our $100 check lives in: a fast, honest first look.

A check starts by confirming what is in scope and that you own or control it, with written authorization on file before anything is tested. A senior operator then works the exposed surface the way an engagement begins: enumerating what is reachable, spotting the forgotten subdomain or the service that should never have been public, and separating the findings that matter from the ones that do not. You get a ranked list and a short human readout, not a thousand-line export. What a check will not do is spend days chaining exploits or pivoting inside your network. It is a first look, honest about being one, meant to tell you quickly whether you have a real problem and what to do next.

A full penetration test

A full engagement is a person, or a team, spending days trying to break in the way a determined attacker would. Manual testing, custom exploitation, business-logic abuse, lateral movement, the works. It produces demonstrated impact and a report an auditor or insurer will usually accept. It costs real money because it is real human time from people who are very good at this.

That means work a scanner cannot do: testing business logic (can one user reach another tenant's data, can a checkout be manipulated, can an access control fall to a single changed parameter), chaining several low-severity issues into one high-severity path, and, where scope allows, moving laterally to show how far a foothold actually reaches. The output is not a list of possibilities but demonstrated impact, with steps to reproduce and evidence attached, the version an auditor, insurer, or enterprise procurement team will usually accept. That is why a real pentest is scoped, scheduled, and priced as human time. If a quote comes back cheap and instant, you are almost certainly buying a scan with a nicer cover page.

THE SHORT VERSION Scan: cheap, broad, automated, noisy. Check: focused first look, human-reviewed. Full pentest: deep, manual, audit-grade. Different tools for different jobs.

The same finding, three answers

Take one ordinary finding and watch how each tier treats it. Suppose an old subdomain, staging.example.com, still points at a live server running an outdated web application.

Same host, three very different answers. The scan told you it existed. The check told you it mattered. The pentest told you what it costs you if you ignore it.

Which one do you need?

These are layers, not competitors, and mature programs run all three. A check before a full engagement often sharpens the scope, so the expensive human days go where they count, and watching your external attack surface between tests catches the drift a once-a-year test will miss. More on cadence in how often should you get a penetration test?

If you are not sure, tell us what is prompting the question. We will point you at the cheapest thing that actually solves your problem, even when that is not the thing we would rather sell.

Check, scan, or pentest? Quick answers

What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan is an automated check against a database of known issues: fast, cheap, repeatable, and noisy. A penetration test is manual work by a skilled operator who tries to exploit and chain issues the way a real attacker would, and proves the impact. A scan tells you what might be wrong; a pentest shows you what someone can actually do.

Is an attack-surface check the same as a penetration test?

No. A check is a focused, time-boxed first look at your exposed surface, reviewed and ranked by a senior operator and delivered with a short human readout. A full penetration test is days of manual, in-depth exploitation that produces demonstrated impact and an audit-grade report. A check is deeper than a scan and lighter than a full engagement, by design.

Do I need a full penetration test for compliance?

Usually yes, and you should confirm the exact wording of your requirement first. Frameworks such as PCI DSS require penetration testing outright, while SOC 2 and ISO 27001 are risk-based and expect it in practice. A scan or a check will not satisfy an auditor or insurer who asked specifically for a penetration test.

Can I start with a scan and a check instead of a full pentest?

Yes, and it is often the smart order: scans for cheap ongoing coverage, a check for a fast honest read that can sharpen the scope of a later engagement, and the full pentest when you need depth or someone is going to verify it. Just do not present a scan or a check as a penetration test to anyone who requires one.

Related reading

Not sure where you land? Start cheap.

The $100 check is the honest first look. If it turns out you need more, we will tell you before you spend more.

Book a $100 check