Skip to content

Product Overview

Sable is Vulnetic’s agentic penetration testing platform. You define an authorized target and scope. Sable plans, executes, validates, and documents the assessment like an operator, not a scanner, while you stay in control.

How it works

  1. Connect a Shell Server (Docker, relay mode) so Sable has a sandboxed runtime with pentest tools.
  2. Start from Chat or the Dashboard: set the target, scope, methodology, and optional Skill Group.
  3. Choose Autonomous or User-approve mode (switch anytime).
  4. Sable enumerates, reasons, chains actions, and runs tools in the Shell Server.
  5. Findings are validated, scored (CVSS), and backed with evidence (including screenshots).
  6. You review results, retest fixes on Targets, generate reports, or pull data via the API.

What you get

Capability What it means
Operator-style testing Enumerates, adapts, and chains actions instead of stopping at static signatures
Validated findings Automatic validation tasks; High Confidence or False Positive with rationale
CVSS scoring v3.1 and v4.0 scores with a breakdown view; included in reports and CSV export
Evidence PoC detail, screenshots, files, and downloadable session traces
Operator control Approve commands, add tasks, steer, skip, pause, or stop
Chat Start sessions, inspect state, transition findings, and generate reports from conversation
Search Find sessions, findings, documents, event analysis, and chats across the account
Skills Reusable operating guidance organized into selectable Skill Groups
Scheduling Future or recurring pentests created from reusable templates
Finding analysis Automated triage plus charts for severity, status, age, trends, and affected targets
Retests Track assets on Targets, retest findings, and produce remediation reports
Methodologies Reusable prompts and starter tasks that shape how Sable tests
Mobile Monitor and steer a live session from a phone omni-panel layout
Integration API Projects, sessions, findings, and documents for Team / Enterprise (beta)

Supported targets

  • Web applications and APIs (including REST and GraphQL)
  • Cloud infrastructure (AWS, Azure, GCP)
  • Internal networks and Active Directory
  • Android applications

Who it is for

  • Security teams (AppSec, SecOps) running repeatable pentests
  • Consultants and red teams accelerating assessments and validation
  • Engineers integrating Sable into internal workflows via the API

Typical timelines

Assessment type Typical duration
Web application 6–10 hours
Network Up to 36 hours, depending on size

Session time limits apply; long-running assessments can consume usage faster. See Usage Limits.

Prerequisites

  1. Create an account at app.vulnetic.ai/signup.
  2. Install Docker.
  3. Connect a Shell Server with relay mode. See Connect / Troubleshoot.

Product map

Topic Doc
First assessment Getting Started
Workspace surfaces Features
Chat Sable Chat
Prior assessment context Account-wide Search
Autonomy, steer, tasks Controlling Sable
Reusable playbooks Methodologies
Reusable procedures Skills and Skill Groups
Future and recurring tests Scheduled Pentests
Retests and remediation Targets (Retests)
Cross-target risk trends Finding Analysis
Plans and consumption Usage Limits
Programmatic access API Overview

Next

Run your first assessment: Getting Started