Resources / Glossary

Offensive security glossary.

Short, plain-English definitions of the penetration testing and AI security terms that come up in scoping calls, audits and our research.

Agentic penetration testing
Penetration testing performed by AI agents that plan multi-step attacks, observe results and adapt — recon, hypothesis, exploit, report — without a human scripting each step. Read the guide →
Attack surface
Every point where an attacker could interact with your systems: domains, IP ranges, APIs, mobile apps, cloud accounts, third-party integrations and AI endpoints.
Attack surface management (ASM)
The continuous discovery, inventory and testing of your external attack surface, so new or forgotten assets are found before attackers find them. Continuous ASM explained →
BOLA / IDOR
Broken object-level authorization, also called insecure direct object reference: an API or page returns another user’s data because it does not check who owns the requested object. API penetration testing →
DAST
Dynamic application security testing: testing a running application from the outside by sending requests and analysing responses, without access to source code.
SAST
Static application security testing: analysing source code or binaries for vulnerable patterns without running the application.
Exploit chain
A sequence of individually minor weaknesses combined into a high-impact attack — for example, an information leak plus a missing authorization check leading to account takeover.
False positive
A reported vulnerability that is not actually exploitable. Validation — reproducing each finding before it is reported — is the main defence.
Jailbreak
Input crafted to make an LLM ignore its safety instructions or system prompt and produce output it was designed to refuse. LLM red teaming →
OWASP Top 10
The Open Worldwide Application Security Project’s list of the most critical web application security risks, widely used as a baseline for testing and compliance.
OWASP Top 10 for LLM Applications
OWASP’s list of the most critical risks specific to applications built on large language models, including prompt injection, sensitive information disclosure and excessive agency. The 2026 list, explained →
Penetration test
An authorised, simulated attack against a system to find and prove exploitable vulnerabilities, ending in a report with evidence and remediation guidance.
Prompt injection
An attack where instructions hidden in user input or retrieved content override an LLM application’s intended behaviour. Indirect prompt injection arrives through documents, emails or web pages the model reads. LLM red teaming →
Red teaming
An objective-driven adversarial exercise that tests an organisation’s ability to detect and respond to a realistic attack, rather than enumerating every vulnerability.
SSRF
Server-side request forgery: tricking a server into making requests on the attacker’s behalf, often to reach internal services or cloud metadata endpoints.
Vulnerability scanner
A tool that checks systems against a database of known vulnerabilities and misconfigurations. Fast and broad, but it does not prove exploitability. AI pentesting vs scanners →