// GLOSSARY

Offensive security glossary

There is no shortage of cybersecurity glossaries; this one differs in one thing: the entries are written by people who use these techniques on engagements. Each term therefore says what it means in a real test and, where possible, links to the primary source so the claim can be verified. It’s useful when a report has landed on your desk and you need to understand what it says, or when you’re writing an inquiry and want the scope named correctly. If you care more about how it works in practice than about the definition, browse the services where these terms meet or the articles and write-ups on the blog.

You won’t find prices or effort figures here; the entries explain terms, they don’t sell a service. How much work hides behind each type of test is covered in the breakdown of an engagement into preparation, testing, and the report, and which companies the law regulates and from when has its own page on NIS2 and the Czech Cybersecurity Act.

Penetration testing

Four entries worth reading before you start writing an inquiry. They explain what a penetration test is, how it differs from a scan and from an audit, and what types of tests exist, so you don’t end up with a scan labeled as a test. Useful when someone has told you that you need a pentest and you want to know what to picture.

OWASP standards

OWASP publishes several documents that are easy to mix up. Top 10 is a list of risks, WSTG is a testing guide, and ASVS is a catalog of requirements for an application, so a sentence about testing under OWASP can mean three widely different scopes. Read these when you’re comparing proposals, or when you want the brief to say what the testing should follow.

Methodologies and frameworks

This is where the frameworks live that a test is run by and documented against afterward. PTES describes the phases of an engagement, MITRE ATT&CK names the attacker’s techniques, the choice between black, gray, and white box decides how much the tester knows at the start, and ISO 27001 decides which of it an auditor will want to see. Tester certifications belong here too, meaning the question of what the acronym in a vendor’s proposal actually documents. Their practical effect is mainly on scope and on whether the deliverable holds up as evidence.

Terms from practice

Terms you run into in a report or in an incident notice. CVE names a specific vulnerability, CVSS assigns it a severity, and the remediation priority is built from that. The other entries mainly cover what happens around an attack, from the roles in a security exercise and the forms of phishing to reconnaissance before an attack, credentials that have already leaked, and the control of an attack that is under way. Useful when you’re reading a test deliverable and need to know what a given abbreviation or term means.

// NEXT STEP

Test your company before hackers do.

Tell us what you want tested. We’ll get back to you and schedule a call to pin down scope, timing, and price.