Functionalities
What a target does for its users — and where most attack surface lives.
What a functionality is
A functionality is something the target does for its users: file upload, password reset, signup, search, exports, invitation flows, webhook configuration, billing management.
Why they matter
Most attack surface is functionality-shaped. Playbook requirements frequently start from a functionality, and the vectors you find while testing one almost always belong to it — which makes functionalities the natural parent for scoped observations.
How they link
Usually directly to the asset, with vectors and quirks hanging off them as scoped children:
File Upload (functionality)
└─ SVG upload (vector)
└─ size limit bypass (quirk)
Scoping a vector inside the functionality that produces it is what makes a suggestion specific. The engine can tell "this asset has an SVG upload vector somewhere" apart from "this asset has one inside its avatar uploader" — and only one of those is usually worth acting on.
Library hygiene
Name the capability, not the endpoint. File Upload is a component; POST /api/avatar on admin.example.com is where you recorded it — the endpoint belongs on the link, not in the name.
What's next
Gadgets — the capabilities that ride along.