GetPentest

Penetration testing glossary

The vocabulary a testing firm uses in a proposal is the vocabulary you have to argue in. These are the terms that appear in Canadian scopes, quotes and reports, defined the way a practitioner uses them rather than the way a marketing page does.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Grouped by where you will meet the word: engagement types in a proposal, standards in a methodology section, finding names in a report, scoring terms in a ticket, and credentials on a team page. Where a term is contested in the industry, this says so.

Engagement types, which appear in the proposal

Black box
Testing with no information beyond what an outsider could find. Realistic for an external perimeter, wasteful for an application, because you pay day rate for reconnaissance you could have supplied in an email.
Grey box
Testing with credentials and some documentation, but not source code. The correct default for almost every application engagement, because it puts the budget into the authorisation model rather than into discovery.
White box
Testing with source code, architecture documents and full access. Finds the most per day. Chosen less often than it should be, usually because buyers think withholding information makes the test more honest.
Assumed breach
Testing that starts from a position an attacker would reach after initial access, such as a standard domain account or a foothold on one workstation. The premise is that perimeter compromise is a question of time, so the useful question is what happens next. See network penetration testing.
Red team
A goal-oriented, adversarial exercise testing detection and response as much as vulnerabilities, usually over weeks and usually without the defenders knowing. Sold to organisations that do not yet have anything to detect with, which is the most common mis-purchase in this market. See red team assessment.
Purple team
Offensive and defensive staff working together, running known techniques deliberately to check whether the detection fires. Cheaper than a red team and more useful for a team building detection coverage.
VAPT
Vulnerability assessment and penetration testing, sold as one product. The term is not wrong, but most VAPT sold in Canada is the assessment half with the penetration testing half named in the title. Ask which days go to which. See vulnerability assessment against penetration test.
Pentest as a service, PTaaS
Testing sold as a subscription with findings delivered in a platform as they are discovered. Suits teams shipping continuously. Confirm it also produces a scoped annual report your auditor will accept. See pentest as a service.
Bug bounty
Paying independent researchers per valid finding. Complementary to testing, not a substitute: it gives no coverage guarantee, no scope statement and no date, which are the three things a compliance requirement asks for.
Retest, remediation verification
A short engagement where the original tester re-attempts each finding against the fixed system and records it closed, partially remediated or risk accepted. See retest and remediation verification.

Standards and methodologies, which appear in the method section

PTES
The Penetration Testing Execution Standard, a seven-phase process frame from pre-engagement interactions through to reporting. Widely referenced as a structure for network and general engagements.
OWASP WSTG
The OWASP Web Security Testing Guide. The reference test set for web applications, organised by category. A firm that names it should be able to say which categories apply to your application.
OWASP MASTG and MASVS
The Mobile Application Security Testing Guide and the verification standard that goes with it. The mobile equivalent of the WSTG. See mobile penetration testing.
OWASP Top 10
An awareness document listing the most critical categories of web application risk. It is a list of categories, not a test methodology, and a report scoped only to "the OWASP Top 10" is narrower than most buyers realise.
OWASP API Security Top 10
The API-specific equivalent, whose top entry is broken object level authorisation. See API penetration testing.
NIST SP 800-115
The Technical Guide to Information Security Testing and Assessment. A process frame covering planning, discovery, attack and reporting, often cited in Canadian public-sector scopes.
OSSTMM
The Open Source Security Testing Methodology Manual. Older, more formal, and still named in some procurement documents.
MITRE ATT&CK
A catalogue of adversary tactics and techniques. Used to describe what a red team did and to map detection coverage, rather than as a testing methodology for a scoped engagement.
Rules of engagement
The signed document authorising the test and setting its boundaries. See penetration test rules of engagement.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Finding names, which appear in the report

Broken object level authorisation, BOLA, IDOR
The server checks that you are logged in but not that the record you asked for is yours. The most common serious finding in web and API testing and the one automation reliably misses, because a scanner does not know which records belong to you.
Broken function level authorisation
The same failure applied to actions rather than records: an ordinary user can call an administrative function because the check lives in the interface rather than on the server.
Business logic flaw
Abuse of a workflow that behaves exactly as coded, such as applying a refund twice or skipping a step to gain something. No tool finds these, because nothing except your team knows what the workflow was for.
Server-side request forgery, SSRF
Making the server fetch a URL of the attacker's choosing, often to reach internal services or cloud metadata endpoints. A frequent route from a web finding to a cloud compromise.
Privilege escalation
Moving from lower to higher privilege. Vertical means gaining more rights, horizontal means reaching another user's data at the same level.
Lateral movement, pivoting
Using access on one system to reach another. What internal and assumed breach engagements exist to measure. See Active Directory penetration testing.
Proof of concept
The demonstration that a finding actually works. A report that says a flaw "may allow" something without proving it has identified a weakness rather than demonstrated a vulnerability, and it should be rated accordingly.
False positive
A reported issue that is not exploitable in your environment. A defining difference between a scan and a test is that a tester has removed these before you see them.

Scoring terms, which appear in the ticket

CVSS
The Common Vulnerability Scoring System. Describes a vulnerability's intrinsic characteristics, not your risk. Always record the vector string beside the number, because the vector can be checked and the number cannot. Score one in the CVSS calculator, and see v3.1 against v4.0 for which version to specify.
CVE
A unique identifier for a publicly known vulnerability in a specific product. Findings in your own code do not get CVE identifiers, which is why a report where every item has one was probably produced by a tool.
CWE
The Common Weakness Enumeration, a taxonomy of weakness types. Describes the class of mistake rather than a specific instance.
EPSS
The Exploit Prediction Scoring System, estimating the probability a vulnerability will be exploited in the wild. A better prioritisation input than severity alone for known product vulnerabilities.
KEV
The Known Exploited Vulnerabilities catalogue, a list of vulnerabilities with confirmed exploitation. If something you have is on it, ordering arguments are over.
Attestation letter
A one-page letter from the testing firm naming the dates, scope, methodology and remediation status. The document to send a customer or an insurer instead of the report. See report against attestation letter.

Credentials, which appear on the team page

OSCP, OSWE, OSEP
Offensive Security certifications earned by passing a long practical exam against live machines. Hands-on evidence that somebody can test.
GPEN, GWAPT, GXPN
SANS and GIAC certifications for network, web application and advanced exploitation testing. Respected, and more expensive to hold, so common at larger firms.
CREST
An accreditation held by the firm as well as by individuals, assessing methodology, quality and data handling. The recognised mark for UK and EU buyers and increasingly named in procurement. Uncommon among small Canadian firms and its absence is not disqualifying here.
CISSP
A management-level credential covering security governance broadly. It says nothing about whether the holder can test, and a team page that leads with it for a testing engagement is answering a different question.

The one term to insist on in writing

Authenticated. A quote that does not say whether testing is authenticated, and as how many roles, is not comparable to one that does. That gap is most of the price difference buyers cannot explain. Put the role count in the scope document before you ask anyone for a number, which is what the scoping questionnaire is for.

Put the vocabulary to work

One written scope, in front of Canadian firms, so the quotes describe the same engagement.

Get matched

Common questions

What is the difference between black box, grey box and white box testing?

Black box gives the tester no information, grey box gives credentials and some documentation, white box gives source code and architecture. Grey box is the right default for applications, because black box spends your budget on reconnaissance you could have supplied and white box is rarely offered because buyers are reluctant to share code.

What does VAPT actually mean?

Vulnerability assessment and penetration testing sold together. The term is legitimate, but a great deal of what is sold as VAPT in Canada is automated assessment with a small amount of manual work attached. Ask how many tester days go to each half. If the answer is not available, you are buying the assessment.

Is CREST accreditation necessary in Canada?

No. It is the recognised mark for UK and EU buyers and it appears in some procurement documents, so it matters if your customer is over there or the bid names it. For a Canadian buyer with Canadian and US customers it is not required, and a redacted sample report tells you more about a firm than any accreditation does.

What is an assumed breach test?

An engagement that starts from a position an attacker would hold after initial access, typically a standard user account or a foothold on one machine. It answers what happens after somebody gets in, which is a more useful question than whether they can, and it is bought far less often than external testing despite finding more.