concept Updated 2026-10-06

Vectors

The specific mechanisms that turn observed behavior into a reachable attack.

What a vector is

A vector is the specific way in — the mechanism that turns observed behavior into a reachable attack: SVG upload, an SSRF-prone webhook fetcher, path traversal in file handling, OAuth redirect manipulation, mass assignment.

A vector is a mechanism, not a payload. SVG upload is a vector; the payload you deliver through it is an exploit, and that belongs in the playbook that uses it — not in the library.

Vectors are rarely asset-wide. They are usually scoped inside the parent that produces them — the functionality or technology where the mechanism was observed:

File Upload             (functionality)
  └─ SVG upload         (vector)

Webhook Configuration   (functionality)
  └─ SSRF-prone fetcher (vector)

Scoped matches rank higher in the engine. The more precisely a vector is anchored, the more trustworthy the suggestion it appears in.

Record the endpoint

When you know where a vector was observed, record the endpoint on the link. Endpoints are how the engine decides whether two capabilities actually meet — a vector without one can still match, but any playbook with a co-location requirement will not.

Library hygiene

One mechanism per component. Split "SVG upload with stored XSS" into SVG upload (vector) and stored XSS (quirk) — the playbook is where they combine.

What's next

Quirks — the behaviors that change what a vector can do.