Gadgets
Extra capabilities that ride along with a target, beyond its intended purpose.
What a gadget is
A gadget is an extra capability that rides along with the target — not the purpose of the system, but a surface it exposes anyway: a GraphQL endpoint, an admin panel, a metrics endpoint, a debug console, auto-generated API docs, a feature-flag surface.
In CAVET terms, gadgets are unintended capabilities — mechanisms built for legitimate purposes that attackers repurpose into force multipliers.
Why they matter
Gadgets are where "it also does this" turns into attack surface. They are frequently discovered while mapping something else — you are testing the API and notice the debug console — and each one seeds its own vectors and quirks. Left unrecorded, they are invisible to the engine.
How they link
Directly on the asset, or scoped inside the technology that exposes them (GraphQL endpoint inside Apollo Server). If a gadget exists only because of a specific parent component, scope it there.
Functionality vs. gadget
A functionality is what the product is for — password reset. A gadget is what came along with it — the metrics endpoint the reset service happens to expose. When in doubt: if users are supposed to use it, it is a functionality; if it is a side door, it is a gadget.
In the app
Create one from Gadgets with Add Gadget: Name (required), Category (required), Description, and Tags.
Link gadgets directly to an asset, or scoped inside the technology that exposes them. In playbooks they play three roles: requirements (often optional — gadgets vary by implementation and resist black-box confirmation), nested children (Add CLGV / Add CLGQ on a gadget link), and yields (toggle Yields on success to mark a gadget as a playbook output — see Declare Yields).
What's next
Vectors — the specific ways in.