24/7 SOC monitoring & incident responsesales@bugfoe.com
BestPentestingby BugFoe
Reference

Penetration Testing Glossary

Plain-English definitions of the terms you'll meet when buying, scoping or reading a penetration test.

Updated October 20264 min readBy the BestPentesting Security Research Team

Security proposals and pentest reports are full of acronyms. This glossary explains the terms you're most likely to meet when buying, scoping or reading a penetration test — in plain English, with links to deeper guides.

A–C

Active Directory (AD)
Microsoft's directory service that manages users, computers and permissions on Windows networks. The main target in most internal penetration tests.
Attack surface management (ASM)
Continuous discovery and monitoring of your internet-facing assets — domains, IPs, cloud services — to find unknown or risky exposure.
Attestation letter
A short letter from a testing firm confirming the scope, dates and outcome of a test, shared with customers instead of the full report.
Black-box testing
Testing with no prior knowledge or credentials, simulating an outside attacker. See also grey-box and white-box.
BOLA / IDOR
Broken Object Level Authorization / Insecure Direct Object Reference — accessing another user's data by changing an identifier. The most common serious API flaw. See API testing.
Bug bounty
A program paying independent researchers for valid vulnerabilities they report. Complements, but doesn't replace, structured penetration testing.
C2 (command and control)
Infrastructure attackers — and red teams — use to remotely control compromised systems.
CERT-In
India's national computer emergency response team. Maintains a list of empanelled security auditing organisations.
Chaining
Combining several lower-severity issues into one high-impact attack. A hallmark of skilled manual testing.
CREST
An international accreditation body for security testing companies and individuals. See certifications guide.
CSRF
Cross-Site Request Forgery — tricking a logged-in user's browser into performing actions without their intent.
CVE
Common Vulnerabilities and Exposures — a public identifier for a known vulnerability, e.g. CVE-2024-XXXX.
CVSS
Common Vulnerability Scoring System — a 0–10 score for technical severity. Used as a starting point for risk ratings in reports.
CTEM
Continuous Threat Exposure Management — an ongoing program to discover, prioritise and validate exposures, often combining ASM with regular testing.

D–I

DAST
Dynamic Application Security Testing — automated scanning of a running application. Fast and broad, but misses business logic and authorization flaws.
EDR / XDR
Endpoint (or extended) detection and response tools that monitor devices for malicious activity. Red teams test whether these detect them.
Exploit
A technique or code that takes advantage of a vulnerability. In pentesting, exploitation is done safely to prove impact.
External penetration test
Testing internet-facing systems from the outside. See internal vs. external.
False positive
A reported issue that isn't real. Common in scanner output; good pentest reports validate every finding.
Grey-box testing
Testing with partial knowledge, usually user accounts and documentation. The most cost-effective approach for most applications.
IAM
Identity and Access Management — in the cloud, the policies and roles that control who can do what. Misconfigured IAM is a top cloud risk.
Internal penetration test
Testing from inside the network, assuming an attacker already has a foothold.

L–P

Lateral movement
Moving from one compromised system to others within a network, towards higher-value targets.
MASVS / MASTG
OWASP's mobile application security standard and testing guide. See mobile pentesting.
MITRE ATT&CK
A public knowledge base of real-world adversary tactics and techniques, used to plan red teams and measure detection.
Multi-tenancy testing
Checking that customers of a SaaS product cannot access each other's data. The most important test for SaaS platforms.
OSINT
Open-Source Intelligence — information gathered from public sources during reconnaissance.
OWASP
The Open Worldwide Application Security Project, a non-profit publishing widely used security standards. See OWASP Top 10:2025.
Phishing simulation
Sending realistic, authorised phishing emails to staff to measure and improve resilience.
Pivoting
Using a compromised system as a stepping stone to reach otherwise inaccessible networks.
Proof of concept (PoC)
Evidence that a vulnerability is real and exploitable — requests, screenshots or scripts included in a report.
Privilege escalation
Gaining higher permissions than intended — from user to admin, or from one cloud role to a more powerful one.
PTaaS
Penetration Testing as a Service — testing ordered and delivered through a platform. See PTaaS vs. traditional.
PTES
Penetration Testing Execution Standard — a framework describing the phases of a professional penetration test.
Purple team
A collaborative exercise where attackers and defenders work together to improve detection. See red vs. pentest.

R–Z

RAG
Retrieval-Augmented Generation — feeding documents to an LLM at query time. Introduces data-isolation risks. See AI/LLM testing.
Red team
An objective-based, stealthy adversary simulation testing an organisation's detection and response.
Retest
A follow-up check confirming that reported vulnerabilities have been fixed.
Rules of engagement (RoE)
The agreed scope, timing, methods, exclusions and contacts for a test — the legal and operational boundaries.
SAST
Static Application Security Testing — automated analysis of source code for vulnerabilities.
Segmentation testing
Verifying that network zones are properly isolated, e.g. that a card-data environment is unreachable from the office network. Required by PCI DSS where segmentation reduces scope.
SIEM
Security Information and Event Management — a platform collecting and analysing logs to detect threats.
SOC
Security Operations Center — the team (internal or managed) that monitors and responds to security alerts, often 24/7.
Social engineering
Manipulating people — by email, phone or in person — into revealing information or granting access.
SQL injection
Inserting malicious SQL through application inputs to read or modify a database.
SSRF
Server-Side Request Forgery — making a server send requests to internal systems or cloud metadata services.
Threat modelling
A structured review of what could go wrong in a system's design, ideally done before building and before testing.
VAPT
Vulnerability Assessment and Penetration Testing — broad scanning combined with manual exploitation. See VA vs. pentest.
White-box testing
Testing with full knowledge, including source code and architecture. Highest assurance per tester-day for critical systems.
WSTG
OWASP Web Security Testing Guide — the detailed testing methodology most web pentests follow.
XSS
Cross-Site Scripting — injecting scripts that run in other users' browsers.
Zero-day
A vulnerability unknown to the vendor, with no patch available.

Missing a term? Suggest it and we'll add it.

BestPentesting Security Research Team
Written and technically reviewed by practising penetration testers and SOC analysts. Last reviewed October 2026. See our methodology.

Ready to find your risks before attackers do?

Tell us what you need tested or monitored. A senior consultant replies within one business day with a scoped, fixed-price proposal.

  • Fixed-price proposal
  • Reply within 1 business day
  • NDA on request