Learn more about the language of software security.
:::info If you don’t see a term defined on this page, refer to one of the governmental or industry standards cited in the References.
:::
The definitions included in this page may vary from the cited standards, based on how we configure and use Cobalt software.
An AWS account is a container for your AWS resources. For more information, see Amazon AWS documentation.
Aggregated Risk is the sum of the risks of individual findings discovered in a pentest.
The risk of an individual finding is the likelihood multiplied by the impact (Risk = Likelihood * Impact).
An allowlist explicitly lets identified systems access. In networks, an allowlist can specify IP addresses. You can typically find allowlists and denylists in files like /etc/hosts.allow and /etc/hosts.deny.
An endpoint is typically a URL used to allow two software applications to communicate with each other. For example, https://api.cobalt.io/orgs is one endpoint that you can find at https://api.cobalt.io.
When scoping a pentest for an API asset, ignore specific parameters and HTTP methods for each endpoint. For example, these are two different HTTP requests for the same endpoint:
Some RESTful API endpoints include additional information that may make them seem different. For example, the following two URLs are in fact the same endpoint, as the content after the ampersand (&) describes an action on data sent from that URL:
GraphQL operates on a single API endpoint. Functionally, GraphQL queries and mutations are similar to RESTful GET, POST, PUT, and other commands.
See API Endpoint for how we look at RESTful and GraphQL APIs. To scope our work, when we need information about your API, we need numbers for either:
An asset is a either a software component of value, such as a web application or API, or a network environment. Cobalt can perform pentests on assets in the following categories:
An asset tag is customer-defined metadata associated with a Cobalt asset.
Learn how to use asset tags.
Application security is the practice of using security software, hardware, techniques, best practices, and procedures to protect computer applications from external security threats. Source: TechTarget.
The OWASP Application Security Verification Standard (ASVS) relates to pentests of web application technical security controls.
Sometimes also known as a threat actor, malicious hacker, “black hat hacker,” or “cracker.” May be an individual, a group, or even a nation-state. Specified as “attacker” in Cobalt pentest reports.
A one-page report suitable for external stakeholders. Includes the following:
Learn more about pentest reports.
A report similar to Customer Letter, with additional details:
Learn more about pentest reports.
A system-generated report for an Agile Pentest intended for internal use. Includes the following sections:
You can’t customize an Automated Report. Learn more about pentest reports.
Where the pentester has no knowledge of the internal details of the asset. Contrast with gray-box and white-box testing.
Also known as “opaque-box testing.”
The Center for Internet Security is an independent nonprofit organization which develops and refines best practice security solutions.
One of the test criteria used by our pentesters is CIS Controls v8, released in 2021.
Cobalt Average for a given year is the average of the Aggregated Risk of all pentests conducted across all customers in that year.
Learn more about the Insights page and using this metric to analyze your assets.
As defined by NIST, Common Platform Enumeration (CPE) is a structured naming scheme for information technology systems, software, and packages. The official CPE Dictionary is hosted and maintained by NIST.
As defined by NIST, a comprehensive review of an organization’s adherence to governing documents such as whether:
An executive summary of the pentest. May be used as a certificate of completion. Great for external stakeholders. Includes:
Learn more about pentest reports.
A systematic process for identifying, analyzing, and prioritizing potential threats and vulnerabilities from an attacker’s perspective within an organization’s digital ecosystem.
A unique web page that facilitates user interaction, such as submitting data, entering parameters, or uploading content. Contrast with Static Web Pages.
In the context of a Cobalt pentest, you can specify one of three options for an environment:
A finding is a vulnerability that a pentester reports during a pentest. We include findings in vulnerability reports, as something that a threat actor can exploit.
When you select Full Report + Finding Details, we add a detailed list of findings to your report, which includes:
A report that contains comprehensive information about the pentest. Includes the following sections:
Learn more about pentest reports.
A report that adds details of every test finding to the Full Report. Learn more about pentest reports.
Per https://graphql.org, GraphQL is a query language for your API. A GraphQL API is designed with a single endpoint.
For pentests of a GraphQL API, Cobalt needs the number of queries and mutations that you’ve configured. Also see API Endpoint.
For more information, see https://graphql.org/learn/queries/
Where the pentester has limited knowledge of the internal details of the asset. Contrast with white-box and black-box testing.
Also known as “translucent-box testing.”
Graylisting is a method of protecting email users from spam. A Mail Transfer Agent (MTA) using graylisting temporarily rejects emails from senders that they don’t recognize. The originating server tries to resend the email after a delay. If the email is legitimate, the MTA accepts it.
An In-House Pentest is a pentest that an organization performs on the Cobalt platform without involving Cobalt pentesters. You can launch In-House Pentests using the Pentest Management Platform (PMP).
Also known as a jump host or a jump server, a jump box is a system (typically) on an internal network or a DMZ. Jump boxes are used to access and manage devices in a separate security zone.
Where the pentester has limited knowledge of the internal details of the asset. Contrast with white-box and black-box testing.
A “well-known” security vulnerability. Documented in a security bulletin or a CVE (Common Vulnerabilities and Exposures) from MITRE.
In Cobalt pentest reports, you may see this as a published or documented vulnerability.
To apply preventative measures. Based on problems identified by a pentest or incident report. Examples:
Contrast with remediate. This reflects how we use mitigate at Cobalt, and differs slightly from the NIST definition of mitigate.
A mobile screen is what you see on a mobile device, such as an iPhone or an Android system. As described by Codepath, mobile screens fall into several archetypes.
You may have multiple screens of an archetype. For example, you may have 10 mobile screens for the onboarding archetype.
For pentests of a mobile asset, we need the number of screens that you have, for each operating system that you support.
Authentication which uses two or more different factors, which may include:
OWASP is a nonprofit foundation with “Top 10” security issues for different asset types, including Web apps, APIs, and Cloud systems.
The OSSTMM tests the operational security of physical locations, human interactions, and all communications on the network, whether they be wireless, wired, analog, or digital.
Operations Security, commonly known as OpSec, identifies critical information, and if/how it may be used by opponents or enemies. OpSec measures can reduce security risks.
Short for penetration test. As described in the Getting Started Guide, you can draft a pentest. Once you submit it for review, Cobalt reviews your pentest and assigns pentesters who then test the asset specified in your pentest.
Combines manual and human testing with a modern delivery platform to deploy penetration testing programs.
A summary of all vulnerability reports, including observations on positive security measures. Target audiences: executives, security engineers, and developers. Includes:
Executive Summary
Executive Analysis
Scope of Work
The scope of work for a pentest includes:
Summary of Findings
Summary of Recommendations
Post-Test Remediation
Finding Details
Within Cobalt, this is also known as a Report or a Final Report. For more information, see Pentest Reports.
Pentest identifier on the Cobalt platform that starts with #. You can see the tag on the pentest page under the title.
All resources included in your cloud asset. For example, AWS defines a project as a collection of resources associated with an asset.
A pentest that Cobalt pentesters perform on the Cobalt Pentest as a Service (PtaaS) platform for a customer. This includes the following pentest types:
Contrast with In-House Pentest that a customer runs on the Cobalt Pentest Management Platform (PMP) with their In-House Pentesters.
An Agile Pentest performed by Cobalt pentesters focuses on code changes or a specific area of an asset and comes with an Automated Report intended for internal use. Learn more about the pentest types.
You may want an Agile Pentest for:
A Comprehensive Pentest is performed by Cobalt pentesters for security audit, compliance audit, or customer attestation and includes comprehensive reports intended for external stakeholders. Learn more about Comprehensive Pentests.
You may want a Comprehensive Pentest for:
A summary of all vulnerability reports, including observations on positive security measures. Target audiences: executives, security engineers, and developers. Includes:
Executive Summary
Executive Analysis
Scope of Work
The scope of work for a pentest includes:
Summary of Findings
Summary of Recommendations
Post-Test Remediation
Finding Details
Within Cobalt, this is also known as a Report or a Final Report. For more information, see Pentest Reports.
A user assigned as the point of contact on a pentest may be contacted by Cobalt Staff members with questions regarding the pentest.
Learn more about assigning a point of contact.
A recovery option, with 2FA enabled, to regain entry into your account if you lose access to your device and/or authenticator app.
A set of resources in a cloud asset. For more information, see Google GCP documentation.
To fix a vulnerability identified by a pentest or incident report. Examples:
Contrast with mitigate. This reflects how we use remediate at Cobalt, and differs slightly from the NIST definition of remediation.
Per TechTarget, “A RESTful API is an architectural style for an application program interface (API) that uses HTTP requests to access and use data.” Also see API Endpoint.
As defined by Manning, in software, it’s a system for resource navigation. If you’re working in the browser, you might be familiar with routing as it relates to:
If you’re working on the server, matching incoming request paths to resources from a database.
Single sign-on (SSO) is an authentication method that allows users to access multiple independent systems with a single set of credentials.
SSO based on the SAML 2.0 protocol works by passing authentication data in the form of digitally signed XML files (assertions) between two systems: a service provider (SP) and an identity provider (IdP).
Depending on where the authentication workflow starts, SAML SSO can be of the following types:
SAML SSO provides a secure experience because user credentials are never transmitted during authentication.
In the service provider-initiated (SP-initiated) SAML SSO, the authentication workflow starts on the service provider side.
In the identity provider-initiated (IdP-initiated) SAML SSO, the authentication workflow starts on the identity provider side.
A Secure Code Review is the human-led examination of software’s source code in order to identify security vulnerabilities that are the result of design flaws, but proven to be valid security issues. It is an important part of any organization’s software development life cycle (SDLC) and helps improve the overall quality and security of the software and an organization’s overall security posture.
As defined by the Organization for the Advancement of Structured Information Standards (OASIS), the Security Assertion Markup Language (SAML) SAML is an XML-based framework for communicating user authentication, entitlement, and attribute information.
As defined by NIST, an independent review and examination of a system’s records and activities to determine the adequacy of system controls, ensure compliance with established security policy and procedures, detect breaches in security services, and recommend any changes that are indicated for countermeasures.
Sender Policy Framework (SPF) is an email authentication method.
An SPF record is a type of record that a domain owner uses to specify which mail servers are authorized to send email on behalf of their domain.
Original sponsor of a set of standards for testing networks. SANS stands for SysAdmin, Audit, Network, and Security. The SANS Top 20 has been migrated to CIS Controls Version 8.
Cobalt may refer to this as the “scope” of your pentest. The scope of work for a pentest includes:
For more information, see https://developer.mozilla.org/en-US/docs/Glossary/SPA
Contrast with Traditional Web Application.
Specialized pentests, as seen in the Cobalt UI, are custom engagements, not standard self-service offerings.
A web page with static content that doesn’t change depending on the user or location. Contrast with Dynamic Web Pages.
A logical container for your resource groups in a cloud asset. For more information, see Azure documentation.
A web application that consists of a web browser on the client side and a web server. Most of the application logic is performed on the server side.
May also be referred to as multi-page application (MPA). Contrast with Single-Page Application.
A User Role is a user group within an application with specific permissions, such as an administrator, manager, or guest.
When scoping a pentest, specify the number of roles that you want to test.
A security issue discovered during a pentest. Also a specific weakness which can be exploited by a threat actor, such as an attacker who crosses privilege boundaries (and performs unauthorized actions) within a computer system.
Contrast with Known Vulnerability. A vulnerability may be part of a finding.
The cyclical practice of identifying, classifying, remediating, and mitigating vulnerabilities. At Cobalt, we focus on manual pentests (enhanced with automated tools). Also see Vulnerability Assessment and Management, as defined by the US Cybersecurity and Infrastructure Agency (CISA).
A document that provides information about one specific finding. Cobalt vulnerability reports are based on manual tests. Such reports include:
A document created by an automated scanning tool. Primarily used to list known vulnerabilities associated with specific code patterns.
How Cobalt classifies the vulnerability. Examples include:
A hypertext document on the web. Web applications typically include static and dynamic web pages.
Where the pentester has full knowledge of the internal details of the asset. Contrast with black-box and gray-box testing.
Also known as “clear-box testing.”
Learn more about the language of software security.
:::info If you don’t see a term defined on this page, refer to one of the governmental or industry standards cited in the References.
:::
The definitions included in this page may vary from the cited standards, based on how we configure and use Cobalt software.
An AWS account is a container for your AWS resources. For more information, see Amazon AWS documentation.
Aggregated Risk is the sum of the risks of individual findings discovered in a pentest.
The risk of an individual finding is the likelihood multiplied by the impact (Risk = Likelihood * Impact).
An allowlist explicitly lets identified systems access. In networks, an allowlist can specify IP addresses. You can typically find allowlists and denylists in files like /etc/hosts.allow and /etc/hosts.deny.
An endpoint is typically a URL used to allow two software applications to communicate with each other. For example, https://api.cobalt.io/orgs is one endpoint that you can find at https://api.cobalt.io.
When scoping a pentest for an API asset, ignore specific parameters and HTTP methods for each endpoint. For example, these are two different HTTP requests for the same endpoint:
Some RESTful API endpoints include additional information that may make them seem different. For example, the following two URLs are in fact the same endpoint, as the content after the ampersand (&) describes an action on data sent from that URL:
GraphQL operates on a single API endpoint. Functionally, GraphQL queries and mutations are similar to RESTful GET, POST, PUT, and other commands.
See API Endpoint for how we look at RESTful and GraphQL APIs. To scope our work, when we need information about your API, we need numbers for either:
An asset is a either a software component of value, such as a web application or API, or a network environment. Cobalt can perform pentests on assets in the following categories:
An asset tag is customer-defined metadata associated with a Cobalt asset.
Learn how to use asset tags.
Application security is the practice of using security software, hardware, techniques, best practices, and procedures to protect computer applications from external security threats. Source: TechTarget.
The OWASP Application Security Verification Standard (ASVS) relates to pentests of web application technical security controls.
Sometimes also known as a threat actor, malicious hacker, “black hat hacker,” or “cracker.” May be an individual, a group, or even a nation-state. Specified as “attacker” in Cobalt pentest reports.
A one-page report suitable for external stakeholders. Includes the following:
Learn more about pentest reports.
A report similar to Customer Letter, with additional details:
Learn more about pentest reports.
A system-generated report for an Agile Pentest intended for internal use. Includes the following sections:
You can’t customize an Automated Report. Learn more about pentest reports.
Where the pentester has no knowledge of the internal details of the asset. Contrast with gray-box and white-box testing.
Also known as “opaque-box testing.”
The Center for Internet Security is an independent nonprofit organization which develops and refines best practice security solutions.
One of the test criteria used by our pentesters is CIS Controls v8, released in 2021.
Cobalt Average for a given year is the average of the Aggregated Risk of all pentests conducted across all customers in that year.
Learn more about the Insights page and using this metric to analyze your assets.
As defined by NIST, Common Platform Enumeration (CPE) is a structured naming scheme for information technology systems, software, and packages. The official CPE Dictionary is hosted and maintained by NIST.
As defined by NIST, a comprehensive review of an organization’s adherence to governing documents such as whether:
An executive summary of the pentest. May be used as a certificate of completion. Great for external stakeholders. Includes:
Learn more about pentest reports.
A systematic process for identifying, analyzing, and prioritizing potential threats and vulnerabilities from an attacker’s perspective within an organization’s digital ecosystem.
A unique web page that facilitates user interaction, such as submitting data, entering parameters, or uploading content. Contrast with Static Web Pages.
In the context of a Cobalt pentest, you can specify one of three options for an environment:
A finding is a vulnerability that a pentester reports during a pentest. We include findings in vulnerability reports, as something that a threat actor can exploit.
When you select Full Report + Finding Details, we add a detailed list of findings to your report, which includes:
A report that contains comprehensive information about the pentest. Includes the following sections:
Learn more about pentest reports.
A report that adds details of every test finding to the Full Report. Learn more about pentest reports.
Per https://graphql.org, GraphQL is a query language for your API. A GraphQL API is designed with a single endpoint.
For pentests of a GraphQL API, Cobalt needs the number of queries and mutations that you’ve configured. Also see API Endpoint.
For more information, see https://graphql.org/learn/queries/
Where the pentester has limited knowledge of the internal details of the asset. Contrast with white-box and black-box testing.
Also known as “translucent-box testing.”
Graylisting is a method of protecting email users from spam. A Mail Transfer Agent (MTA) using graylisting temporarily rejects emails from senders that they don’t recognize. The originating server tries to resend the email after a delay. If the email is legitimate, the MTA accepts it.
An In-House Pentest is a pentest that an organization performs on the Cobalt platform without involving Cobalt pentesters. You can launch In-House Pentests using the Pentest Management Platform (PMP).
Also known as a jump host or a jump server, a jump box is a system (typically) on an internal network or a DMZ. Jump boxes are used to access and manage devices in a separate security zone.
Where the pentester has limited knowledge of the internal details of the asset. Contrast with white-box and black-box testing.
A “well-known” security vulnerability. Documented in a security bulletin or a CVE (Common Vulnerabilities and Exposures) from MITRE.
In Cobalt pentest reports, you may see this as a published or documented vulnerability.
To apply preventative measures. Based on problems identified by a pentest or incident report. Examples:
Contrast with remediate. This reflects how we use mitigate at Cobalt, and differs slightly from the NIST definition of mitigate.
A mobile screen is what you see on a mobile device, such as an iPhone or an Android system. As described by Codepath, mobile screens fall into several archetypes.
You may have multiple screens of an archetype. For example, you may have 10 mobile screens for the onboarding archetype.
For pentests of a mobile asset, we need the number of screens that you have, for each operating system that you support.
Authentication which uses two or more different factors, which may include:
OWASP is a nonprofit foundation with “Top 10” security issues for different asset types, including Web apps, APIs, and Cloud systems.
The OSSTMM tests the operational security of physical locations, human interactions, and all communications on the network, whether they be wireless, wired, analog, or digital.
Operations Security, commonly known as OpSec, identifies critical information, and if/how it may be used by opponents or enemies. OpSec measures can reduce security risks.
Short for penetration test. As described in the Getting Started Guide, you can draft a pentest. Once you submit it for review, Cobalt reviews your pentest and assigns pentesters who then test the asset specified in your pentest.
Combines manual and human testing with a modern delivery platform to deploy penetration testing programs.
A summary of all vulnerability reports, including observations on positive security measures. Target audiences: executives, security engineers, and developers. Includes:
Executive Summary
Executive Analysis
Scope of Work
The scope of work for a pentest includes:
Summary of Findings
Summary of Recommendations
Post-Test Remediation
Finding Details
Within Cobalt, this is also known as a Report or a Final Report. For more information, see Pentest Reports.
Pentest identifier on the Cobalt platform that starts with #. You can see the tag on the pentest page under the title.
All resources included in your cloud asset. For example, AWS defines a project as a collection of resources associated with an asset.
A pentest that Cobalt pentesters perform on the Cobalt Pentest as a Service (PtaaS) platform for a customer. This includes the following pentest types:
Contrast with In-House Pentest that a customer runs on the Cobalt Pentest Management Platform (PMP) with their In-House Pentesters.
An Agile Pentest performed by Cobalt pentesters focuses on code changes or a specific area of an asset and comes with an Automated Report intended for internal use. Learn more about the pentest types.
You may want an Agile Pentest for:
A Comprehensive Pentest is performed by Cobalt pentesters for security audit, compliance audit, or customer attestation and includes comprehensive reports intended for external stakeholders. Learn more about Comprehensive Pentests.
You may want a Comprehensive Pentest for:
A summary of all vulnerability reports, including observations on positive security measures. Target audiences: executives, security engineers, and developers. Includes:
Executive Summary
Executive Analysis
Scope of Work
The scope of work for a pentest includes:
Summary of Findings
Summary of Recommendations
Post-Test Remediation
Finding Details
Within Cobalt, this is also known as a Report or a Final Report. For more information, see Pentest Reports.
A user assigned as the point of contact on a pentest may be contacted by Cobalt Staff members with questions regarding the pentest.
Learn more about assigning a point of contact.
A recovery option, with 2FA enabled, to regain entry into your account if you lose access to your device and/or authenticator app.
A set of resources in a cloud asset. For more information, see Google GCP documentation.
To fix a vulnerability identified by a pentest or incident report. Examples:
Contrast with mitigate. This reflects how we use remediate at Cobalt, and differs slightly from the NIST definition of remediation.
Per TechTarget, “A RESTful API is an architectural style for an application program interface (API) that uses HTTP requests to access and use data.” Also see API Endpoint.
As defined by Manning, in software, it’s a system for resource navigation. If you’re working in the browser, you might be familiar with routing as it relates to:
If you’re working on the server, matching incoming request paths to resources from a database.
Single sign-on (SSO) is an authentication method that allows users to access multiple independent systems with a single set of credentials.
SSO based on the SAML 2.0 protocol works by passing authentication data in the form of digitally signed XML files (assertions) between two systems: a service provider (SP) and an identity provider (IdP).
Depending on where the authentication workflow starts, SAML SSO can be of the following types:
SAML SSO provides a secure experience because user credentials are never transmitted during authentication.
In the service provider-initiated (SP-initiated) SAML SSO, the authentication workflow starts on the service provider side.
In the identity provider-initiated (IdP-initiated) SAML SSO, the authentication workflow starts on the identity provider side.
A Secure Code Review is the human-led examination of software’s source code in order to identify security vulnerabilities that are the result of design flaws, but proven to be valid security issues. It is an important part of any organization’s software development life cycle (SDLC) and helps improve the overall quality and security of the software and an organization’s overall security posture.
As defined by the Organization for the Advancement of Structured Information Standards (OASIS), the Security Assertion Markup Language (SAML) SAML is an XML-based framework for communicating user authentication, entitlement, and attribute information.
As defined by NIST, an independent review and examination of a system’s records and activities to determine the adequacy of system controls, ensure compliance with established security policy and procedures, detect breaches in security services, and recommend any changes that are indicated for countermeasures.
Sender Policy Framework (SPF) is an email authentication method.
An SPF record is a type of record that a domain owner uses to specify which mail servers are authorized to send email on behalf of their domain.
Original sponsor of a set of standards for testing networks. SANS stands for SysAdmin, Audit, Network, and Security. The SANS Top 20 has been migrated to CIS Controls Version 8.
Cobalt may refer to this as the “scope” of your pentest. The scope of work for a pentest includes:
For more information, see https://developer.mozilla.org/en-US/docs/Glossary/SPA
Contrast with Traditional Web Application.
Specialized pentests, as seen in the Cobalt UI, are custom engagements, not standard self-service offerings.
A web page with static content that doesn’t change depending on the user or location. Contrast with Dynamic Web Pages.
A logical container for your resource groups in a cloud asset. For more information, see Azure documentation.
A web application that consists of a web browser on the client side and a web server. Most of the application logic is performed on the server side.
May also be referred to as multi-page application (MPA). Contrast with Single-Page Application.
A User Role is a user group within an application with specific permissions, such as an administrator, manager, or guest.
When scoping a pentest, specify the number of roles that you want to test.
A security issue discovered during a pentest. Also a specific weakness which can be exploited by a threat actor, such as an attacker who crosses privilege boundaries (and performs unauthorized actions) within a computer system.
Contrast with Known Vulnerability. A vulnerability may be part of a finding.
The cyclical practice of identifying, classifying, remediating, and mitigating vulnerabilities. At Cobalt, we focus on manual pentests (enhanced with automated tools). Also see Vulnerability Assessment and Management, as defined by the US Cybersecurity and Infrastructure Agency (CISA).
A document that provides information about one specific finding. Cobalt vulnerability reports are based on manual tests. Such reports include:
A document created by an automated scanning tool. Primarily used to list known vulnerabilities associated with specific code patterns.
How Cobalt classifies the vulnerability. Examples include:
A hypertext document on the web. Web applications typically include static and dynamic web pages.
Where the pentester has full knowledge of the internal details of the asset. Contrast with black-box and gray-box testing.
Also known as “clear-box testing.”