Vulnetic Change Log August 2025

With summer coming to an end, we are excited to post about our first biweekly changelog. In this article we will discuss what is now available to use.

The most exciting feature we are releasing is findings. No longer do you need to scrape through the session outputs or view the full report to see what was critical. When our agent finds a vulnerability, it will populate the findings field with the proof of concept, reproduction steps and remediation.

This feature is currently in its initial release and thus can make mistakes.

We posted our first public trace last week, but now all users across pricing plans can easily view and create traces of their assessments.

This allows for internal storage of assessments, and we think can be a super valuable tool for collaboration. Every command, output, comment and event can be viewed in these comprehensive traces.

We have expanded the toolset of Sable by giving it access to tools such as Playwright and Katana which enhances the web pentesting capability by making dynamic analysis of JavaScript possible from the shell.

Sable using Playwright for Dynamic Analysis

With the added playwright ability, Sable will now take screenshots of the browser as a form of collecting evidence.

This feature is currently in its initial release and thus can make mistakes.

We had an interesting request while at Defcon for a mechanism to upload custom payloads as well as view the directory tree that the agent sees. We thought this was a great idea and built a file tab.

This not only makes it easier to see what the agent sees but allows you to also upload custom payloads.

Individual assessments can now be sorted into larger projects. This is available to all users and is a great way to keep pentests sorted properly for either bug bounties or clients.

To learn more, visit our website: https://vulnetic.ai

As always, email me personally at danielk@vulnetic.ai with any questions.