Functionalities
What a target does for its users — and where most attack surface lives.
What a functionality is
A functionality is something the target does for its users: file upload, password reset, signup, search, exports, invitation flows, webhook configuration, billing management.
In CAVET terms, functionalities are trust boundaries: places where the application accepts outside input and makes a promise about what it will do with it. Vulnerabilities are broken promises.
Why they matter
Most attack surface is functionality-shaped. Playbook requirements frequently start from a functionality, and the vectors you find while testing one almost always belong to it — which makes functionalities the natural parent for scoped observations.
How they link
Usually directly to the asset, with vectors and quirks hanging off them as scoped children:
File Upload (functionality)
└─ SVG upload (vector)
└─ size limit bypass (quirk)
Scoping a vector inside the functionality that produces it is what makes a suggestion specific. The engine can tell "this asset has an SVG upload vector somewhere" apart from "this asset has one inside its avatar uploader" — and only one of those is usually worth acting on.
Library hygiene
Name the capability, not the endpoint. File Upload is a component; POST /api/avatar on admin.example.com is where you recorded it — the endpoint belongs on the link, not in the name.
In the app
Create one from Functionalities with Add Functionality: Name (required), Category (required), Aliases (alternate names like Upload or File Transfer, so the same thing is findable under different wording), Description, and Tags.
Functionalities link directly to assets, and they're usually the first type you map — the bones of the target's attack surface. They're also where scoped children accumulate: vectors live inside the functionality that produces them, quirks where the behavior was observed. Playbook requirements for those children demand the exact parent (exact-parent rule), so linking a child to the right functionality matters twice.
What's next
Gadgets — the capabilities that ride along.