KobReySec Logo
Published Last reviewed
Published Last reviewed
Penetration Test vs. Vulnerability Scan

Scanners Are a Tool.
They're Not the Test.

Automated scanners are useful. We use them too. They can cover a lot of ground quickly and surface known weaknesses worth investigating.

A penetration test starts where the scanner stops: validating what is real, looking for what automation missed, chaining weaknesses together, and determining what an attacker could actually accomplish.

Discovery Validation Attack chaining
A Note From Us

We're Opinionated About This One. For Good Reason.

We routinely see organizations buy what they believe is a penetration test and receive little more than automated vulnerability output wrapped in a polished report.

The problem is not just wasted money. It is the false sense of security that can follow. A clean scanner report does not prove there is no attack path. It proves the scanner did not report one.

Different Work. Different Answer.

A Vulnerability Scan Finds Signals. A Penetration Test Investigates Them.

Both have value. They answer different questions.

Vulnerability Scan

What is known and detectable?

  • Automated coverage across many hosts or application components
  • Identification of known vulnerabilities and common misconfigurations
  • Version, signature, and response-based detection
  • Useful recurring visibility and prioritization data
Strong at breadth. Limited by what the tool knows how to recognize.
The Scanner Found XSS. Now What?

The Finding Is Often the Beginning of the Test.

Consider an illustrative attack path. A scanner may correctly identify cross-site scripting (XSS). A tester keeps asking what that weakness makes possible.

01Stored XSS

Automation identifies a potentially exploitable weakness.

02Privileged session

Can the payload execute in an administrator's browser and expose or abuse the session?

03Admin access

What functionality becomes available with that access?

04Persistence

Can a new privileged account or another durable foothold be created?

The scanner found a vulnerability. The tester found the consequence.

Not every XSS finding leads to this outcome. That is exactly why the weakness has to be investigated in the context of the application.

What Are You Actually Buying?

A $5,000 Week of Testing Still Has to Pass the Math Test.

If a large firm quotes $5,000 for a one-week penetration test, the price alone does not tell you whether the work is good or bad. It should make you ask where the time goes.

Illustrative example
$5,000

Divided across a 40-hour workweek, that is $125 per hour before accounting for anything else involved in delivering the engagement.

Project management, kickoff and status calls, reporting, quality assurance, internal coordination, sales and administrative overhead, tooling, benefits, and margin all have to come from somewhere.

The Question to Ask

How many hours are actually left for hands-on testing?

Cheap does not automatically mean bad. Expensive does not automatically mean good. But if the economics do not support meaningful tester time, it is reasonable to ask whether you are buying a penetration test or a vulnerability scan with a penetration-testing label.

Manual testing costs more because it takes time. So does a real attack.
Yes, AI Changes the Workflow

AI Is a Tool. It's Not the Tester.

Artificial intelligence can make security testing faster and more capable. We use it where it helps. That does not remove the need for experience, judgment, or an attacker's mindset.

Where AI Helps

Generating test ideas, creating payload variations, analyzing responses, correlating information, summarizing large data sets, and accelerating repetitive work.

Where Experience Matters

Understanding context, recognizing unusual trust relationships, deciding which hypothesis is worth pursuing, adapting when assumptions fail, and knowing how far a path can realistically go.

Think Like the Attacker

Attackers will use scanners. Attackers will use AI. They will also improvise, chain weaknesses, test assumptions, and keep going when the first technique does not work.

The strongest workflow is not human or automation. It is experienced human testing using the right tools, including automation and AI, without outsourcing judgment to them.
Why This Matters

A Clean Report Can Still Be Wrong About the Risk.

We have entered environments that had recently received what was effectively a clean bill of health from a prior assessment and reached Domain Admin roughly 15 minutes into our own testing.

That does not prove every prior tester was incompetent, and it does not mean automation has no value. It means the previous result did not identify the attack path that was actually there.

Anonymized example from our testing experience. Client and provider details are intentionally omitted.
A Scan With a Pentest Logo Is Still a Scan

Ask How the Work Really Gets Done.

Tool names and methodology language are easy to put in a proposal. The useful questions expose how much actual testing is behind them.

What parts of the engagement are manual versus automated?
How do you validate exploitability instead of repeating scanner output?
Who is actually performing the hands-on testing?
How do testers investigate and chain multiple weaknesses?
Will we have direct access to the tester during the engagement?
How many hours are allocated to hands-on testing versus project overhead?
Use Our Buyer Guide

Make the Vendor Explain the Difference.

Our penetration testing vendor guide and scorecard includes questions covering manual testing, staffing, tester access, exploitability, reporting, and post-engagement support.

The Difference Is the Work

You Are Not Paying for a List of Vulnerabilities.

You are paying to understand what an attacker can actually do with them, what the tools missed, how weaknesses connect, and what deserves your attention first.