Product Overview¶
Sable is Vulnetic’s agentic penetration testing platform. You define an authorized target and scope. Sable plans, executes, validates, and documents the assessment like an operator, not a scanner, while you stay in control.
How it works¶
- Connect a Shell Server (Docker, relay mode) so Sable has a sandboxed runtime with pentest tools.
- Start from Chat or the Dashboard: set the target, scope, methodology, and optional Skill Group.
- Choose Autonomous or User-approve mode (switch anytime).
- Sable enumerates, reasons, chains actions, and runs tools in the Shell Server.
- Findings are validated, scored (CVSS), and backed with evidence (including screenshots).
- You review results, retest fixes on Targets, generate reports, or pull data via the API.
What you get¶
| Capability | What it means |
|---|---|
| Operator-style testing | Enumerates, adapts, and chains actions instead of stopping at static signatures |
| Validated findings | Automatic validation tasks; High Confidence or False Positive with rationale |
| CVSS scoring | v3.1 and v4.0 scores with a breakdown view; included in reports and CSV export |
| Evidence | PoC detail, screenshots, files, and downloadable session traces |
| Operator control | Approve commands, add tasks, steer, skip, pause, or stop |
| Chat | Start sessions, inspect state, transition findings, and generate reports from conversation |
| Search | Find sessions, findings, documents, event analysis, and chats across the account |
| Skills | Reusable operating guidance organized into selectable Skill Groups |
| Scheduling | Future or recurring pentests created from reusable templates |
| Finding analysis | Automated triage plus charts for severity, status, age, trends, and affected targets |
| Retests | Track assets on Targets, retest findings, and produce remediation reports |
| Methodologies | Reusable prompts and starter tasks that shape how Sable tests |
| Mobile | Monitor and steer a live session from a phone omni-panel layout |
| Integration API | Projects, sessions, findings, and documents for Team / Enterprise (beta) |
Supported targets¶
- Web applications and APIs (including REST and GraphQL)
- Cloud infrastructure (AWS, Azure, GCP)
- Internal networks and Active Directory
- Android applications
Who it is for¶
- Security teams (AppSec, SecOps) running repeatable pentests
- Consultants and red teams accelerating assessments and validation
- Engineers integrating Sable into internal workflows via the API
Typical timelines¶
| Assessment type | Typical duration |
|---|---|
| Web application | 6–10 hours |
| Network | Up to 36 hours, depending on size |
Session time limits apply; long-running assessments can consume usage faster. See Usage Limits.
Prerequisites¶
- Create an account at app.vulnetic.ai/signup.
- Install Docker.
- Connect a Shell Server with relay mode. See Connect / Troubleshoot.
Product map¶
| Topic | Doc |
|---|---|
| First assessment | Getting Started |
| Workspace surfaces | Features |
| Chat | Sable Chat |
| Prior assessment context | Account-wide Search |
| Autonomy, steer, tasks | Controlling Sable |
| Reusable playbooks | Methodologies |
| Reusable procedures | Skills and Skill Groups |
| Future and recurring tests | Scheduled Pentests |
| Retests and remediation | Targets (Retests) |
| Cross-target risk trends | Finding Analysis |
| Plans and consumption | Usage Limits |
| Programmatic access | API Overview |
Next¶
Run your first assessment: Getting Started