<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>White-Box on Tolmo</title><link>https://tolmo.com/tags/white-box/</link><description>Recent content in White-Box on Tolmo</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 06 Oct 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://tolmo.com/tags/white-box/index.xml" rel="self" type="application/rss+xml"/><item><title>What is a white box penetration test?</title><link>https://tolmo.com/blog/what-is-a-white-box-penetration-test/</link><pubDate>Tue, 06 Oct 2026 00:00:00 +0000</pubDate><guid>https://tolmo.com/blog/what-is-a-white-box-penetration-test/</guid><description>&lt;p&gt;A white box penetration test (or white box pentest) gives auditors access to internal information upfront, rather than requiring them to discover it progressively.&lt;/p&gt;
&lt;p&gt;This type of pentest is done by providing or integrating with source code, documentation, product specifications, observability and telemetry systems, cloud providers, security tooling and more.&lt;/p&gt;
&lt;h2 id="why-would-you-give-away-this-information"&gt;Why would you give away this information?&lt;/h2&gt;
&lt;p&gt;To find as many exploitable vulnerabilities as possible, before attackers do. This matters more every year: attackers are becoming more efficient as they use AI, which makes even the hardest and most obscure vulnerabilities much more likely to be exploited today, than they were a couple years ago. This asymmetric access to information is key to staying ahead of attackers.&lt;/p&gt;</description></item></channel></rss>