Ethical Hacking: All the Terms You Need to Know

Ethical Hacking Cosa Sapere

For our clients, who often do not possess an in-depth technical background, the jargon used in the field of ethical hacking can seem like an incomprehensible maze. Understanding the meaning of concepts such as vulnerability, exploit, payload, and TTPs will not only facilitate communication with our security experts but will also provide you with greater awareness of the risks and defense strategies adopted.

This guide was created with the specific goal of making the most common technical terms in the field of ethical hacking accessible, bridging the communication gap between you and security service providers.

Keep reading, and in just a few minutes, that ‘mysterious jargon’ will become an ally for your security!


Let’s analyze some of the fundamental terms you will encounter most frequently: we will try to explain them in a simple and intuitive way, also using analogies to facilitate understanding.

A

Brute Force Attack: an attempt to guess a password, an encryption key, or find a hidden webpage by systematically trying all possible combinations. Ethical hackers use automated tools to simulate brute force attacks on passwords and other authentication mechanisms to assess their robustness.

Active Directory (AD): a directory service developed by Microsoft for domain networks. It is a critical target for attackers and often the subject of specific ethical hacking techniques. For an in-depth look at the most common offensive techniques, consult the guide on Active Directory and ethical hacking techniques.

Advanced Persistent Threat (APT): a sophisticated and prolonged attack, conducted by an actor (often state-sponsored or well-organized) with the goal of infiltrating a system and remaining hidden for a long period, stealing sensitive information. Specific training on APTs is an important security measure.

AS-REP Roasting: an attack that aims to obtain the passwords of users who do not require Kerberos pre-authentication. Ethical hackers look for users configured in a vulnerable way to attempt to crack their passwords offline.

Audit: a systematic and independent process to evaluate the effectiveness of an organization’s security controls. Auditing is crucial in analyzing the results of ethical hacking to reconstruct attack paths.

Authentication: the process of verifying the identity of a user, device, or application before granting access to resources or services. Out-of-band authentication uses two separate communication channels for increased security.

B

Backdoor: a secret method to bypass normal authentication procedures and access a system or application. It can be intentionally inserted for legitimate purposes (e.g., maintenance) or maliciously by an attacker to ensure future access.

Blue Team: the internal defense team of an organization, responsible for maintaining system security and incident response. During a TIBER-EU test, the Blue Team creates a report on their actions.

Botnet: a network of computers (or other Internet-connected devices) infected with malware and controlled by a single attacker (the “bot herder”) without the owners’ knowledge. Botnets are often used to launch DDoS attacks or to distribute spam and malware.

Bug Bounty: a program offered by some organizations that rewards external ethical hackers for discovering and reporting vulnerabilities in their systems.

Business Continuity Plan (BCP): a documented plan that describes how an organization will continue to operate in the event of a significant disruption, including natural disasters, cyberattacks, or other emergencies.

C

Certified Ethical Hacker (CEH): a recognized certification in the ethical hacking industry that attests to knowledge of the techniques and tools used by attackers.

Compromise: the result of a successful cyberattack, in which a system, account, or data has been accessed, modified, or stolen by unauthorized persons. The goal of ethical hacking is to identify the paths an attacker might follow to achieve a compromise.

Continuous Monitoring: the process of constantly monitoring the security of a system or network to detect suspicious activity or vulnerabilities. A continuous monitoring strategy is essential for security.

Access Control: the mechanisms and policies implemented to limit access to resources and information only to authorized users.

Control Team (CT): in a TIBER-EU test, the CT is responsible for overseeing and controlling the entire testing process. The Control Team Guidance (CTG) provides instructions for the establishment and operation of the CT.

Encryption: the process of transforming information into an unreadable format (ciphertext) to protect its confidentiality. Encryption is a fundamental security measure mentioned in the context of ICT security requirements.

Cybersecurity: the set of practices and technologies aimed at protecting computer systems, networks, programs, and data from unauthorized access, damage, modification, or destruction. Ethical hacking is an integral part of a broader cybersecurity strategy.


Cyber Threat Intelligence (CTI):
the set of information collected, processed, and analyzed regarding existing and potential cyber threats, including threat actors, their motivations, their capabilities, and their TTPs. CTI is fundamental for ethical hacking based on real threats such as TLPT (Threat-Led Penetration Testing).

D

Data Breach: a security incident in which sensitive, confidential, or protected information is copied, transmitted, viewed, used, or stolen by unauthorized individuals. The experience derived from security incidents or breaches must be integrated into training. Indicators of Compromise (IOCs) can reveal a data breach.

Design Weaknesses: flaws in the logic of a system’s operation that can be abused.

Defense in Depth: a security strategy that implements multiple layers of security controls, so that if one control fails, the others can still provide protection.

Denial of Service (DoS): a type of attack that aims to make a system, service, or network resource unavailable to legitimate users, by overloading it with traffic or exploiting vulnerabilities.

Digital Operational Resilience: the ability of an organization to build, secure, and review its digital operational integrity, maintaining the ability to provide services during and after disruptions. The Digital Operational Resilience Act (DORA) is a relevant regulatory framework.

DORA (Digital Operational Resilience Act): a European regulation aimed at strengthening the digital operational resilience of the financial sector. The TLPT requirements of DORA can be met with the TIBER-EU framework.

E

Configuration Errors: systems or applications that are not correctly configured, leaving access ports open or using insecure default settings.

Programming Errors: bugs in software code that can be exploited to execute arbitrary code.

Ethical Hacking: the act of simulating cyberattacks to identify vulnerabilities in a system or network, with the owner’s permission and with the goal of improving security. Ethical hacking is distinguished by its proactive nature. If you want to understand how a structured ethical hacking service can be applied to your organization, the ISGroup team works with a Tiger Team that analyzes infrastructure, procedures, and physical security by simulating realistic scenarios.

Exploit: an exploit is a piece of code, a sequence of commands, or a technique that takes advantage of a specific weakness or vulnerability present in a computer system, software application, or hardware. Imagine a faulty lock (the vulnerability) on a door. During ethical hacking, the goal is often to identify vulnerabilities and, in some cases, demonstrate their exploitability through the creation or use of exploits. This allows the client to understand the real impact a specific weakness could have if exploited by a malicious attacker.

F

Firewall: a security system that monitors and controls incoming and outgoing network traffic, blocking unauthorized communications based on predefined rules.

Follow-up: the term ‘follow-up’ refers to actions taken after an initial event, assessment, feedback, or recommendation, to ensure that necessary measures are completed, problems are resolved, and expected results are achieved.

Framework: a conceptual structure or set of guidelines that provide a structured approach to addressing a problem or implementing a process. In ethical hacking, there are various frameworks such as MITRE ATT&CK, TIBER-EU, NIST SP 800-53, and CBEST that guide testing and security assessment activities.

G

GDPR (General Data Protection Regulation): this is mentioned in the context of ensuring that the procurement process for threat intelligence providers complies with data protection regulations.

Golden ticket: a forged Kerberos ticket that allows the attacker to authenticate to any service within the Active Directory domain. Ethical hackers look for ways to create or steal these tickets to assess the robustness of the authentication system.

H

Hacker (Ethical/White Hat): a cybersecurity expert who uses their skills to identify and exploit vulnerabilities in computer systems with the owner’s permission, in order to improve security. They are distinguished from “black hat” hackers (cybercriminals) and “grey hat” hackers (who operate in a grey area between ethics and illegality).

HUMINT (Human Intelligence): information collected from human sources. In ethical hacking, it can include the analysis of social engineering interactions or information obtained from industry experts.

I

Incident Response: the set of procedures and actions taken to identify, contain, eliminate, and recover from a cybersecurity incident. A formal follow-up process is necessary in ICT incident management.

Indicator of Compromise (IOC): an artifact or signal that indicates that a system or network may have been compromised by a cyberattack. IOCs can include malicious IP addresses or suspicious traffic patterns.

Information Security: the protection of information and computer systems from unauthorized access, use, disclosure, interruption, modification, or destruction. An information security plan is a key element.

Social Engineering: the art of manipulating people to obtain confidential information or to induce them to perform actions that could compromise security. Phishing attacks are a common example of social engineering. Ethical hackers simulate these techniques to assess an organization’s “human firewall.” To understand how much the human factor affects the attack surface, read the in-depth look at the role of social engineering in ethical hacking.

K

Kerberoasting: an attack technique targeting Service Principal Names (SPNs) in Active Directory to obtain service account passwords.

Keylogger: software or hardware that secretly records keystrokes typed on a keyboard, allowing an attacker to steal passwords, personal information, or other sensitive data.

L

Lateral Movement: the techniques used by an attacker after compromising an initial system to move through the network and access other valuable systems. Ethical hackers simulate lateral movement to assess how easy it is for an attacker to expand their presence within the infrastructure.

Logging: the detailed recording of events that occur in a computer system or network. Logs are fundamental for analyzing ethical hacking results and for operational resilience. The protection of audit information is a security control.

M

Malware: software designed to cause damage to a computer system, steal information, or gain unauthorized access. It includes viruses, worms, trojans, ransomware, and spyware. Ethical hacking aims to identify vulnerabilities that could be exploited to install malware.

Man-in-the-Middle (MitM) attack: an attack in which a malicious actor secretly positions themselves between two communicating parties, intercepting and potentially altering the exchanged information. Ethical hackers look for vulnerabilities that could allow MitM attacks to be executed to assess network communication security. Out-of-band authentication is a technique that can mitigate these attacks.

Mitigation: the set of actions taken to reduce the impact or probability of a threat or vulnerability.

N

NIST SP 800-53: a set of standards and guidelines published by the U.S. National Institute of Standards and Technology (NIST), which provide a catalog of security and privacy controls for federal information systems and organizations. This framework supports risk management and compliance.

O

OSINT (Open Source Intelligence): intelligence obtained from publicly available information sources, such as websites, social media, and news articles. OSINT is used in the reconnaissance phase of ethical hacking and in threat intelligence.

P

Password Spraying: a “light” brute force attack that consists of trying a small number of common passwords against a large number of accounts. Ethical hackers simulate this attack to verify if corporate password policies are effective in preventing compromises.

Payload: the payload is the part of an exploit that contains the malicious code or instructions that the attacker wishes to execute on the target system after successfully compromising it (take a lock, for example: the exploit is the lockpick, while the payload is what the thief does once inside, i.e., stealing information, installing malicious software, or taking control of the system).

In the context of ethical hacking, the payload used during tests is generally safe and controlled, designed to demonstrate the compromise without causing real damage. The goal is to show the client what actions an attacker could take once access to the system is obtained.

Penetration Testing (Pentest): an active security test in which ethical hackers attempt to exploit vulnerabilities in a system or network to assess its security. Penetration testing is a core methodology of ethical hacking.

Phishing: a type of social engineering attack in which attackers send fraudulent emails, messages, or phone calls in an attempt to deceive victims and induce them to reveal sensitive information or perform harmful actions.

Privilege escalation: a technique used by attackers to gain a higher level of access than initially compromised, allowing them to perform more harmful actions.

Provenance: the history of the origin, development, ownership, location, and changes made to a system or component. Provenance is an important aspect of supply chain risk management.

R

Red Team: a team of cybersecurity experts that simulates the attack tactics and techniques of real adversaries to test an organization’s defense capability (the blue team). Red teaming exercises are more complex and realistic attack simulations than simple penetration tests. The Red Team Test Plan (RTTP) describes the operational modes of the red team in a TIBER-EU test, while the Red Team Test Report (RTTR) documents their activities and results.

Remediation: the process of correcting identified vulnerabilities to reduce the risk of exploitation. A Remediation Plan (RP), such as the one provided for in the TIBER-EU framework, outlines the actions necessary to resolve the weaknesses found.

Digital Operational Resilience: the ability of an organization to maintain its operations and recover quickly from cyber incidents. Ethical hacking helps improve operational resilience by identifying and helping to correct weaknesses. The Digital Operational Resilience Act (DORA) is a European regulation that aims to strengthen digital operational resilience in the financial sector.

Risk (Cyber): the probability that a threat may exploit a vulnerability, causing a negative impact on the organization. Ethical hacking helps to better assess and understand cyber risks.

Risk Management Strategy: a comprehensive plan to identify, assess, and mitigate risks. Ethical hacking provides valuable information to inform an organization’s risk management strategy.

S

SIEM (Security Information and Event Management): software that collects and analyzes security logs from various sources (such as operating systems, applications, and network devices) to identify threats and anomalies.

Silver ticket: a forged Kerberos ticket that allows the attacker to access a specific service within the Active Directory domain (unlike the Golden Ticket, which is valid for all services). Ethical hackers look for vulnerabilities that allow for the creation of Silver Tickets to assess the security of individual services.

Supply Chain Attack: a cyberattack that targets suppliers, partners, or other elements of an organization’s supply chain to compromise the primary target. Supply chain risk management is increasingly important.

System Inventory: a complete list of all hardware, software, and other IT components of an organization. A system inventory is a fundamental security control.

T

Threat actor: an individual or group with the intent and capability to conduct a cyberattack. Understanding threat actors and their TTPs is fundamental for effective ethical hacking.

Threat Intelligence: see Cyber Threat Intelligence (CTI).

Threat-Led Penetration Testing (TLPT): During a Threat-Led Penetration Testing (TLPT), ethical hackers simulate attacks based on threat intelligence, i.e., information about real threats and the TTPs used by specific attacker groups. It is an advanced ethical hacking methodology that uses threat intelligence to simulate realistic attacks based on the most likely threats to a specific organization.

TTPs (Tactics, Techniques, and Procedures): the specific behaviors and methods that attackers use during a cyberattack. Understanding the TTPs of threat actors is essential for simulating realistic attacks in ethical hacking.

V

Vulnerability: a vulnerability is a weakness, design flaw, or implementation error present in a computer system, software application, hardware, or even a security procedure that could be exploited by an attacker to compromise the confidentiality, integrity, or availability of that system or application.

Vulnerability assessment: the process of identifying, quantifying, and classifying security vulnerabilities in a system or network. Unlike penetration testing, vulnerability assessment does not always include the active exploitation of weaknesses.

Human vulnerabilities: errors made by users, such as falling victim to social engineering attacks (psychological manipulation to obtain information or access) like phishing.

Z

Zero-Day Vulnerability: a software vulnerability that has been discovered but has not yet been fixed with a patch by the vendor. Exploits that target zero-day vulnerabilities can be particularly dangerous because there are no immediate defenses available.

Ethical Hacking: why knowing the terms makes a difference

A better understanding of technical jargon allows you to participate in discussions in a more informed way, better assess risks, and make more conscious decisions regarding your security strategy.

Investing in understanding these terms is not just an academic exercise. A solid foundation of knowledge in the language of cybersecurity allows you to:

  • Improve communication, which facilitates the exchange of information between clients and service providers, reducing misunderstandings and inefficiencies.
  • Understand risks: that is, acquire greater awareness of the cyber threats and vulnerabilities that can expose your organization.
  • Evaluate results: correctly interpret ethical hacking reports and understand the impact of identified vulnerabilities.
  • Participate actively: be able to contribute significantly to decisions regarding security strategy and remediation plans.
  • Increase trust with cybersecurity partners, based on a mutual understanding of goals and challenges.

If you want to delve deeper into how these concepts translate into practice, you can read the real-world case of corporate ethical hacking with the Acmebank case, which shows how a structured engagement is conducted from start to finish.

Frequently asked questions about ethical hacking

  • What is the difference between ethical hacking and penetration testing?
  • Penetration testing is one of the activities that falls under ethical hacking: it focuses on the active attempt to exploit specific vulnerabilities within a defined perimeter. Ethical hacking is a broader concept that can also include social engineering simulations, physical access analysis, red teaming, and threat intelligence, with the goal of replicating the behavior of a real attacker in its entirety.
  • What happens concretely during an ethical hacking engagement?
  • A typical engagement is divided into several phases: reconnaissance (gathering information about the target), vulnerability identification, controlled exploitation attempt, documentation of attack paths, and production of a report with remediation recommendations. Everything happens with the explicit consent of the organization and within an agreed-upon perimeter.
  • Who can request an ethical hacking service?
  • Any organization that wants to proactively verify the robustness of its IT infrastructure, applications, or internal processes. It is not reserved for large companies: even SMEs with critical systems or sensitive data benefit from an assessment conducted with controlled offensive methodologies.

Protect your organisation with Ethical Hacking.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert