コンテンツにスキップ

Glossary

This glossary defines the terms used across the Ostorlab docs, in alphabetical order. Each entry links to the page that explains the term.

Terms

Term Meaning Where to read more
Agent A unit of scanning work; scan profiles are built from agents, and you can add your own or public agents to a scan. Scan with extra custom agents, Agent store
Aggregation (tickets) Ticket aggregation groups similar vulnerabilities across scans and assets into single tickets, by platform group or by application group. Ticket aggregation: how it works
AI pentest An AI-driven pentest that the MCP reference also calls an agentic deep scan, and whose results it calls risks rather than vulnerabilities. AI pentests (MCP), Use IDE: AI Pentest
API (GraphQL) The GraphQL API lets you create scans, follow their progress and list vulnerabilities, from the GraphiQL sandbox or from scripts. GraphQL API
API key A key you create under Integrations/API, then API Keys, to authenticate the API, the MCP server, CI integrations and on-prem scanners. API key authentication, API keys
Archive (scan) A scan action in the three-dot Actions menu of the Scans list; the MCP server can still list archived scans. Archive a scan
Asset Something Ostorlab tracks and scans, such as a domain, an IP address or a mobile app, which you add under an owner. Add assets, Attack surface discovery
Attack surface Your organisation's internet-facing assets and their known connections, which attack surface discovery monitors continuously to find missing and rogue assets. Attack surface discovery, Attack surface data
Automation rule A rule in Policies that runs an action, such as assigning an owner, setting tags or sending a notification, on the items its filter matches in a chosen context. The contexts are Attack surface, Inventory and Remediation. The items are assets, or tickets in the Remediation context. Automation rules
BYOK Bring Your Own Key: use your own LLM provider key when you run AI-powered scans. BYOK
Call Coverage The UI flow of a mobile app: the sequence of screens the Ostorlab robots went through during the scan. Check call coverage, IDE: Call coverage
Copilot An AI-powered assistant that helps you find information about the platform, such as documentation, scans, vulnerabilities and remediation. How to use Copilot
Cyber Models The prepaid option for Deep Agentic Scans: you buy tokens for your workspace wallet instead of bringing your own AI provider key. Cyber Models overview
Deep Agentic Scan An AI-powered scan that chains vulnerabilities into attack paths and validates findings with a proof-of-concept exploit. Scan types comparison, Mobile Deep Agentic Scan, Web Deep Agentic Scan
DNA An internal attribute that uniquely identifies a vulnerability, so later occurrences of it are aggregated in the same ticket. Ticket lifecycle, Vulnerabilities (MCP)
Effort The setting that decides how deeply an AI scan investigates and how many tokens it uses: Core 50, Advanced 200 or Elite 400. Scan effort
Exception and false positive Ticket statuses; a ticket marked as an exception or a false positive is kept as it is when new occurrences are found. Vulnerabilities and tickets management, Ticket lifecycle
Finding / vulnerability An issue a scan reports in its Vulnerabilities section, with a risk rating, description, recommendation, references and technical details. Understand scan results, IDE: Vulnerabilities
IDE The analysis environment you open from a scan with Analysis, built for manual assessment and for writing custom checks. Use IDE: Search and Analysis
Inventory Your confirmed assets; a discovered asset joins it when you confirm it. Attack surface discovery, Discover assets
KB (Knowledge Base) Ostorlab's own reference data, the same for every organisation, which the Detection page points to for the full list of checks. Knowledge base (MCP), Detection
MCP server A server that lets AI assistants and agent frameworks work with your scans, vulnerabilities, tickets and assets directly. MCP server
Mobile Shielding Scan A scan of how well an app's hardening holds up, such as obfuscation, anti-tampering and root detection; it is not a vulnerability scan. Mobile Shielding Scan
Monitoring rule A rule that scans assets of one type on a CRON schedule or, in continuous mode, when a change is detected. Create a monitoring rule, Monitoring
Multi-asset scan A scan that combines assets such as mobile apps, web apps, network ranges, code repositories and files, with shared settings and one report. Run a Multi Asset scan, Multi Asset scan profile
Organisation The group your users belong to; it holds your scans, assets and tickets, and it can have a parent organisation. Create an organisation, Ostorlab remediation system
Owner A team that is assigned to assets and in charge of fixing them, and the boundary Owner-Based RBAC uses to control access. Managing inventory asset owners, Owner-Based RBAC
Patching policy (SLO) A policy that sets SLOs for fixing confirmed vulnerabilities and hardening recommendations, by risk rating or by ticket priority. Configure patching policy, Ostorlab remediation system
Potential asset An asset that discovery proposes as possibly yours, ranked High, Moderate or Low confidence until you confirm or reject it. Discover assets
Priority (ticket) A ticket setting from P0, the most urgent, to P3, the least urgent. Urgency and priority
Risk rating The category assigned to each vulnerability, such as Critical, High, Medium, Low, Potentially or Hardening; you can change it. Risk rating, Change risk rating
SBOM A Software Bill of Materials, a detailed list of the components in an application, which you can upload to extend dependency detection. Scans with SBOM or lockfile
Scan A security test of an asset that you create from the New Scan menu; it is queued, then running, then done. Getting started
Scan profile The scan type you pick, such as Fast Scan, Full Scan or Mobile Deep Agentic Scan, which sets a scan's depth and techniques. Supported scan profiles, Mobile scan profiles
Scanner (on-prem) An Ostorlab scanner you deploy on infrastructure you control; scanner groups spread a scan across several scanners. On-prem scanners
Single Vulnerability Assessment A re-test of one reported finding after a fix, without a full rescan, that uses no AI tokens. How do I check that a fix worked?, Supported scan profiles
Stream A group of related tickets, with a lead, members and target dates, that you track together. Streams
Test credentials Credentials, such as login and password, 2FA, certificates or a Puppeteer script, that you add to a scan to run authenticated tests. Authenticated scans, Test credentials
Ticket The record that tracks a vulnerability through its lifecycle; Ostorlab creates one automatically for each newly detected issue. Ticket lifecycle
Token (AI) A unit of prepaid AI spend, held in your workspace wallet and debited when a Cyber Models scan starts. What is a token?, Purchase tokens
Token (API) A token linked to a user, retrieved with a username and password, that authenticates API scripts in an Authorization header. Token based authentication
UI prompt A natural-language instruction, created under Policies, UI Rules, that tells the AI Monkey Tester how to navigate an app. UI prompts
Web API scan A scan of an API endpoint that uses an API schema file in GraphQL, WSDL or OpenAPI format. Scan a web API with a schema file