Security proposals and pentest reports are full of acronyms. This glossary explains the terms you're most likely to meet when buying, scoping or reading a penetration test — in plain English, with links to deeper guides.
A–C
- Active Directory (AD)
- Microsoft's directory service that manages users, computers and permissions on Windows networks. The main target in most internal penetration tests.
- Attack surface management (ASM)
- Continuous discovery and monitoring of your internet-facing assets — domains, IPs, cloud services — to find unknown or risky exposure.
- Attestation letter
- A short letter from a testing firm confirming the scope, dates and outcome of a test, shared with customers instead of the full report.
- Black-box testing
- Testing with no prior knowledge or credentials, simulating an outside attacker. See also grey-box and white-box.
- BOLA / IDOR
- Broken Object Level Authorization / Insecure Direct Object Reference — accessing another user's data by changing an identifier. The most common serious API flaw. See API testing.
- Bug bounty
- A program paying independent researchers for valid vulnerabilities they report. Complements, but doesn't replace, structured penetration testing.
- C2 (command and control)
- Infrastructure attackers — and red teams — use to remotely control compromised systems.
- CERT-In
- India's national computer emergency response team. Maintains a list of empanelled security auditing organisations.
- Chaining
- Combining several lower-severity issues into one high-impact attack. A hallmark of skilled manual testing.
- CREST
- An international accreditation body for security testing companies and individuals. See certifications guide.
- CSRF
- Cross-Site Request Forgery — tricking a logged-in user's browser into performing actions without their intent.
- CVE
- Common Vulnerabilities and Exposures — a public identifier for a known vulnerability, e.g. CVE-2024-XXXX.
- CVSS
- Common Vulnerability Scoring System — a 0–10 score for technical severity. Used as a starting point for risk ratings in reports.
- CTEM
- Continuous Threat Exposure Management — an ongoing program to discover, prioritise and validate exposures, often combining ASM with regular testing.
D–I
- DAST
- Dynamic Application Security Testing — automated scanning of a running application. Fast and broad, but misses business logic and authorization flaws.
- EDR / XDR
- Endpoint (or extended) detection and response tools that monitor devices for malicious activity. Red teams test whether these detect them.
- Exploit
- A technique or code that takes advantage of a vulnerability. In pentesting, exploitation is done safely to prove impact.
- External penetration test
- Testing internet-facing systems from the outside. See internal vs. external.
- False positive
- A reported issue that isn't real. Common in scanner output; good pentest reports validate every finding.
- Grey-box testing
- Testing with partial knowledge, usually user accounts and documentation. The most cost-effective approach for most applications.
- IAM
- Identity and Access Management — in the cloud, the policies and roles that control who can do what. Misconfigured IAM is a top cloud risk.
- Internal penetration test
- Testing from inside the network, assuming an attacker already has a foothold.
L–P
- Lateral movement
- Moving from one compromised system to others within a network, towards higher-value targets.
- MASVS / MASTG
- OWASP's mobile application security standard and testing guide. See mobile pentesting.
- MITRE ATT&CK
- A public knowledge base of real-world adversary tactics and techniques, used to plan red teams and measure detection.
- Multi-tenancy testing
- Checking that customers of a SaaS product cannot access each other's data. The most important test for SaaS platforms.
- OSINT
- Open-Source Intelligence — information gathered from public sources during reconnaissance.
- OWASP
- The Open Worldwide Application Security Project, a non-profit publishing widely used security standards. See OWASP Top 10:2025.
- Phishing simulation
- Sending realistic, authorised phishing emails to staff to measure and improve resilience.
- Pivoting
- Using a compromised system as a stepping stone to reach otherwise inaccessible networks.
- Proof of concept (PoC)
- Evidence that a vulnerability is real and exploitable — requests, screenshots or scripts included in a report.
- Privilege escalation
- Gaining higher permissions than intended — from user to admin, or from one cloud role to a more powerful one.
- PTaaS
- Penetration Testing as a Service — testing ordered and delivered through a platform. See PTaaS vs. traditional.
- PTES
- Penetration Testing Execution Standard — a framework describing the phases of a professional penetration test.
- Purple team
- A collaborative exercise where attackers and defenders work together to improve detection. See red vs. pentest.
R–Z
- RAG
- Retrieval-Augmented Generation — feeding documents to an LLM at query time. Introduces data-isolation risks. See AI/LLM testing.
- Red team
- An objective-based, stealthy adversary simulation testing an organisation's detection and response.
- Retest
- A follow-up check confirming that reported vulnerabilities have been fixed.
- Rules of engagement (RoE)
- The agreed scope, timing, methods, exclusions and contacts for a test — the legal and operational boundaries.
- SAST
- Static Application Security Testing — automated analysis of source code for vulnerabilities.
- Segmentation testing
- Verifying that network zones are properly isolated, e.g. that a card-data environment is unreachable from the office network. Required by PCI DSS where segmentation reduces scope.
- SIEM
- Security Information and Event Management — a platform collecting and analysing logs to detect threats.
- SOC
- Security Operations Center — the team (internal or managed) that monitors and responds to security alerts, often 24/7.
- Manipulating people — by email, phone or in person — into revealing information or granting access.
- SQL injection
- Inserting malicious SQL through application inputs to read or modify a database.
- SSRF
- Server-Side Request Forgery — making a server send requests to internal systems or cloud metadata services.
- Threat modelling
- A structured review of what could go wrong in a system's design, ideally done before building and before testing.
- VAPT
- Vulnerability Assessment and Penetration Testing — broad scanning combined with manual exploitation. See VA vs. pentest.
- White-box testing
- Testing with full knowledge, including source code and architecture. Highest assurance per tester-day for critical systems.
- WSTG
- OWASP Web Security Testing Guide — the detailed testing methodology most web pentests follow.
- XSS
- Cross-Site Scripting — injecting scripts that run in other users' browsers.
- Zero-day
- A vulnerability unknown to the vendor, with no patch available.
Missing a term? Suggest it and we'll add it.