- Getting Started
- Glossary
Glossary
This glossary defines the terms used across the Ostorlab docs, in alphabetical order. Each entry links to the page that explains the term.
Terms
| Term | Meaning | Where to read more |
|---|---|---|
| Agent | A unit of scanning work; scan profiles are built from agents, and you can add your own or public agents to a scan. | Scan with extra custom agents, Agent store |
| Aggregation (tickets) | Ticket aggregation groups similar vulnerabilities across scans and assets into single tickets, by platform group or by application group. | Ticket aggregation: how it works |
| AI pentest | An AI-driven pentest that the MCP reference also calls an agentic deep scan, and whose results it calls risks rather than vulnerabilities. | AI pentests (MCP), Use IDE: AI Pentest |
| API (GraphQL) | The GraphQL API lets you create scans, follow their progress and list vulnerabilities, from the GraphiQL sandbox or from scripts. | GraphQL API |
| API key | A key you create under Integrations/API, then API Keys, to authenticate the API, the MCP server, CI integrations and on-prem scanners. | API key authentication, API keys |
| Archive (scan) | A scan action in the three-dot Actions menu of the Scans list; the MCP server can still list archived scans. | Archive a scan |
| Asset | Something Ostorlab tracks and scans, such as a domain, an IP address or a mobile app, which you add under an owner. | Add assets, Attack surface discovery |
| Attack surface | Your organisation's internet-facing assets and their known connections, which attack surface discovery monitors continuously to find missing and rogue assets. | Attack surface discovery, Attack surface data |
| Automation rule | A rule in Policies that runs an action, such as assigning an owner, setting tags or sending a notification, on the items its filter matches in a chosen context. The contexts are Attack surface, Inventory and Remediation. The items are assets, or tickets in the Remediation context. | Automation rules |
| BYOK | Bring Your Own Key: use your own LLM provider key when you run AI-powered scans. | BYOK |
| Call Coverage | The UI flow of a mobile app: the sequence of screens the Ostorlab robots went through during the scan. | Check call coverage, IDE: Call coverage |
| Copilot | An AI-powered assistant that helps you find information about the platform, such as documentation, scans, vulnerabilities and remediation. | How to use Copilot |
| Cyber Models | The prepaid option for Deep Agentic Scans: you buy tokens for your workspace wallet instead of bringing your own AI provider key. | Cyber Models overview |
| Deep Agentic Scan | An AI-powered scan that chains vulnerabilities into attack paths and validates findings with a proof-of-concept exploit. | Scan types comparison, Mobile Deep Agentic Scan, Web Deep Agentic Scan |
| DNA | An internal attribute that uniquely identifies a vulnerability, so later occurrences of it are aggregated in the same ticket. | Ticket lifecycle, Vulnerabilities (MCP) |
| Effort | The setting that decides how deeply an AI scan investigates and how many tokens it uses: Core 50, Advanced 200 or Elite 400. | Scan effort |
| Exception and false positive | Ticket statuses; a ticket marked as an exception or a false positive is kept as it is when new occurrences are found. | Vulnerabilities and tickets management, Ticket lifecycle |
| Finding / vulnerability | An issue a scan reports in its Vulnerabilities section, with a risk rating, description, recommendation, references and technical details. | Understand scan results, IDE: Vulnerabilities |
| IDE | The analysis environment you open from a scan with Analysis, built for manual assessment and for writing custom checks. | Use IDE: Search and Analysis |
| Inventory | Your confirmed assets; a discovered asset joins it when you confirm it. | Attack surface discovery, Discover assets |
| KB (Knowledge Base) | Ostorlab's own reference data, the same for every organisation, which the Detection page points to for the full list of checks. | Knowledge base (MCP), Detection |
| MCP server | A server that lets AI assistants and agent frameworks work with your scans, vulnerabilities, tickets and assets directly. | MCP server |
| Mobile Shielding Scan | A scan of how well an app's hardening holds up, such as obfuscation, anti-tampering and root detection; it is not a vulnerability scan. | Mobile Shielding Scan |
| Monitoring rule | A rule that scans assets of one type on a CRON schedule or, in continuous mode, when a change is detected. | Create a monitoring rule, Monitoring |
| Multi-asset scan | A scan that combines assets such as mobile apps, web apps, network ranges, code repositories and files, with shared settings and one report. | Run a Multi Asset scan, Multi Asset scan profile |
| Organisation | The group your users belong to; it holds your scans, assets and tickets, and it can have a parent organisation. | Create an organisation, Ostorlab remediation system |
| Owner | A team that is assigned to assets and in charge of fixing them, and the boundary Owner-Based RBAC uses to control access. | Managing inventory asset owners, Owner-Based RBAC |
| Patching policy (SLO) | A policy that sets SLOs for fixing confirmed vulnerabilities and hardening recommendations, by risk rating or by ticket priority. | Configure patching policy, Ostorlab remediation system |
| Potential asset | An asset that discovery proposes as possibly yours, ranked High, Moderate or Low confidence until you confirm or reject it. | Discover assets |
| Priority (ticket) | A ticket setting from P0, the most urgent, to P3, the least urgent. | Urgency and priority |
| Risk rating | The category assigned to each vulnerability, such as Critical, High, Medium, Low, Potentially or Hardening; you can change it. | Risk rating, Change risk rating |
| SBOM | A Software Bill of Materials, a detailed list of the components in an application, which you can upload to extend dependency detection. | Scans with SBOM or lockfile |
| Scan | A security test of an asset that you create from the New Scan menu; it is queued, then running, then done. | Getting started |
| Scan profile | The scan type you pick, such as Fast Scan, Full Scan or Mobile Deep Agentic Scan, which sets a scan's depth and techniques. | Supported scan profiles, Mobile scan profiles |
| Scanner (on-prem) | An Ostorlab scanner you deploy on infrastructure you control; scanner groups spread a scan across several scanners. | On-prem scanners |
| Single Vulnerability Assessment | A re-test of one reported finding after a fix, without a full rescan, that uses no AI tokens. | How do I check that a fix worked?, Supported scan profiles |
| Stream | A group of related tickets, with a lead, members and target dates, that you track together. | Streams |
| Test credentials | Credentials, such as login and password, 2FA, certificates or a Puppeteer script, that you add to a scan to run authenticated tests. | Authenticated scans, Test credentials |
| Ticket | The record that tracks a vulnerability through its lifecycle; Ostorlab creates one automatically for each newly detected issue. | Ticket lifecycle |
| Token (AI) | A unit of prepaid AI spend, held in your workspace wallet and debited when a Cyber Models scan starts. | What is a token?, Purchase tokens |
| Token (API) | A token linked to a user, retrieved with a username and password, that authenticates API scripts in an Authorization header. | Token based authentication |
| UI prompt | A natural-language instruction, created under Policies, UI Rules, that tells the AI Monkey Tester how to navigate an app. | UI prompts |
| Web API scan | A scan of an API endpoint that uses an API schema file in GraphQL, WSDL or OpenAPI format. | Scan a web API with a schema file |