concept Updated 2026-10-06

Functionalities

What a target does for its users — and where most attack surface lives.

What a functionality is

A functionality is something the target does for its users: file upload, password reset, signup, search, exports, invitation flows, webhook configuration, billing management.

Why they matter

Most attack surface is functionality-shaped. Playbook requirements frequently start from a functionality, and the vectors you find while testing one almost always belong to it — which makes functionalities the natural parent for scoped observations.

Usually directly to the asset, with vectors and quirks hanging off them as scoped children:

File Upload            (functionality)
  └─ SVG upload        (vector)
  └─ size limit bypass (quirk)

Scoping a vector inside the functionality that produces it is what makes a suggestion specific. The engine can tell "this asset has an SVG upload vector somewhere" apart from "this asset has one inside its avatar uploader" — and only one of those is usually worth acting on.

Library hygiene

Name the capability, not the endpoint. File Upload is a component; POST /api/avatar on admin.example.com is where you recorded it — the endpoint belongs on the link, not in the name.

What's next

Gadgets — the capabilities that ride along.