The Offensive Security Glossary
The language of security testing is changing fast. Terms that barely existed three years ago - AI-driven attacks, continuous penetration testing, autonomous red teaming, and LLM vulnerabilities - are now central to how security leaders must think about risk.
The Equixly glossary has been built to be a clear, jargon-free guide to the latest concepts and approaches in the space. So whether you’re here to learn about the latest innovations in API security testing, or how to mitigate AI chatbot vulnerabilities, our explainers will give you enough depth to be genuinely useful.
Each page goes beyond a one-line definition, so you can use the glossary as a CISO building the case for continuous testing, a security engineer evaluating tools, or a developer trying to understand the risks in the code you ship. You will find how each concept works in practice, why it matters for your security program, and how it connects to the broader landscape of threats and frameworks shaping the industry in 2026.
A
AI Penetration Testing
AI-driven security testing that uses autonomous systems to identify and validate exploitable vulnerabilities across applications, APIs, and infrastructure at a speed and scale that manual testing cannot replicate.
Read more →AI Red Teaming
Adversarial testing of LLMs, AI agents, and AI-integrated systems using the techniques real attackers use - identifying exploitable vulnerabilities in AI behaviour before they reach production.
Read more →API Security
The discipline of protecting application programming interfaces from unauthorized access, exploitation, and abuse, covering authentication, authorization, data exposure, and business logic across every endpoint an application exposes.
Read more →Autonomous Exploitation
The ability of an AI system to identify a weakness, plan an attack path, execute it, and confirm impact without a human directing each step, separating an adversary that reasons from a tool that runs a script.
Read more →B
C
Continuous Offensive Security Testing (COST)
A proactive security discipline that continuously simulates real-world attacks against applications, APIs, and AI infrastructure - closing the gap between when vulnerabilities are introduced and when they are found.
Read more →Continuous Penetration Testing
Always-on security testing that validates your attack surface as it changes - replacing the annual engagement with continuous, automated validation that reflects your environment as it exists today.
Read more →