Glossary
Short, factual explanations of the terms around penetration testing and offensive security; each term points to the service where it matters in practice.
All terms
Black box, grey box and white box testing: the difference
Black box, grey box and white box describe how much prior knowledge a penetration tester receives, from nothing to full access including source code, and so determine the depth of the test.
What is a backdoor?
A backdoor is a hidden way to bypass the normal authentication of a system, left behind by an attacker after a break-in or by a developer during development.
What is a business continuity plan (BCP)?
A business continuity plan (BCP) describes how an organisation keeps its critical processes running during and after an incident, through backup and recovery, crisis management and alternative ways of working.
What is CVSS (Common Vulnerability Scoring System)?
CVSS, the Common Vulnerability Scoring System, is an open standard maintained by FIRST that expresses the severity of a vulnerability as a score from 0 to 10, divided into the bands None, Low, Medium, High and Critical.
What is a CVE?
A CVE (Common Vulnerabilities and Exposures) is a unique identifier for a publicly known vulnerability in software or hardware, so that everyone talks about the same vulnerability.
What is cloud security?
Cloud security is the set of settings, identities and controls that protect your data and systems at AWS, Azure or GCP. The provider secures the cloud itself; what you put in it is your responsibility.
What is DORA?
DORA, the Digital Operational Resilience Act (Regulation (EU) 2022/2554), has required financial entities and their ICT providers since 17 January 2025 to demonstrate digital resilience, including the testing of systems.
What is an ethical hacker?
An ethical hacker breaks into systems with permission to find and report vulnerabilities before a real attacker abuses them.
What is IDOR (insecure direct object reference)?
IDOR, insecure direct object reference, is a vulnerability in which a user reaches another user's data by changing an identifier in a URL or API call, because the server does not check authorisation for the object.
What is MFA (multi-factor authentication)?
MFA, multi-factor authentication, asks for two or more proofs from different categories at login, such as a password plus a code or a security key, so that a stolen password alone is not enough.
What is NEN 7510?
NEN 7510 is the Dutch standard for information security in healthcare, based on ISO 27001 and ISO 27002 with additional requirements for patient data; healthcare providers are legally required to apply it.
What is OSINT (open source intelligence)?
OSINT, open source intelligence, is information gathered from public sources such as DNS records, certificates, code repositories, social media and breach data; in a penetration test it is used for reconnaissance.
What is the OWASP Top 10?
The OWASP Top 10 is the list of the ten most critical security risks for web applications, published by the Open Worldwide Application Security Project; the basis of almost every web application penetration test.
What is PTaaS (Pentest as a Service)?
PTaaS, Pentest as a Service, is continuous penetration testing through a subscription with an annual allocation of testing days, so every release is tested without a new assignment each time.
What is a penetration test (pentest)?
A penetration test, or pentest, is a controlled attack on a system by ethical hackers, with the aim of finding and proving vulnerabilities before a real attacker does.
What is a penetration test report?
A penetration test report records what was tested, which vulnerabilities were found, with what evidence, and how to fix them; it is the real deliverable of a pentest.
What is phishing?
Phishing is a form of social engineering in which an attacker poses as a trusted sender, usually by e-mail, to make the recipient click a link, submit credentials or transfer money.
What is a retest?
A retest is the verification, after remediation, that a vulnerability found in a penetration test has really been fixed; a finding is closed only when the fix has been proven.
What is ransomware?
Ransomware is malicious software that encrypts files and systems and demands a ransom for the key; modern groups also steal the data and threaten to publish it.
What is red teaming?
Red teaming is an objective-based attack simulation in which a team of ethical hackers tests the detection and response of the whole organisation, not only the security of individual systems.
What is SQL injection?
SQL injection is an attack in which user input is executed as part of a database query, letting an attacker read or modify data or bypass the login.
What is security awareness?
Security awareness is the knowledge and behaviour of employees in relation to security threats such as phishing and social engineering; it is measured through tests, not assumed from training attendance.
What is social engineering?
Social engineering is the manipulation of people rather than systems; an attacker uses trust, authority or urgency to make an employee hand over information, access or money.
Vulnerability scan or penetration test: what is the difference?
A vulnerability scan is an automated search for known weaknesses that produces a list of possible issues; a penetration test is manual work by senior testers who exploit vulnerabilities and prove the impact with evidence.
What is a vulnerability scan?
A vulnerability scan is an automated check that recognises known weaknesses in systems, such as missing patches, expired certificates and default passwords. The scan produces a list; what an attacker can do with it, it does not prove.
What is XSS (cross-site scripting)?
XSS, cross-site scripting, is a vulnerability in which an attacker gets their own script executed in another user's browser, through a web application that does not properly validate and encode input.
What is a zero-day?
A zero-day is a vulnerability not yet known to the vendor, so there have been zero days to build a patch; a zero-day exploit abuses such a vulnerability.
Ready to Secure Your Environment?
Schedule a free intake call to scope your assessment. Pentrox identifies vulnerabilities in your applications, infrastructure, and cloud environments before attackers do.
Schedule an intake call