Glossary

Ethical Hacking

Request a Demo
Experience a live demo and learn more about RidgeBot®.

Key Cybersecurity Terms

Our glossary of software threat exposure management terms offers concise definitions of the evolving language of cybersecurity.

Ethical Hacking

Ethical hacking can be conducted by skilled security personnel or by automated penetration testing platforms. Both use knowledge and learned techniques to improve an organization’s security posture. Ethical hacking looks for vulnerabilities that create risk that can lead to security breaches. It attempts to gain unauthorized access to a network, system, application, or data, by using the same strategies and actions of malicious attackers. 

By identifying and confirming security vulnerabilities, organizations can fix them before discovery and exploitation by bad actors. After discovering a vulnerability, ethical hacking confirms and reports the findings and provides remediation advice. 

Ridge Security ethical hacking: acting like a real attacker, it automatically discovers active assets like applications, servers, operating systems, databases, and websites, then tests and reports on the infrastructure attack surfaces it finds, such as weak URLs, open ports, and system vulnerabilities, using actual payload to detect vulnerabilities. Using ethical hacking skills learned from human testers, it launches sophisticated, joint, and iterative attacks, confirming whether certain configurations would allow real hackers to move laterally further into the environment. Along the way, it performs a range of ethical hacking tactics, such as dumping password hashes or looking for hard-coded credentials, adding what it learns to its repertoire for the next round of testing and investigation.