OWASP Top 10, business logic flaws, and API security testing.
Manual + automated testing across authentication, session management, injection points, and access control — backed by Burp Suite (incl. Autorize, Turbo Intruder), sqlmap, ffuf, Nuclei, and custom exploitation tooling.
- Auth & session vulnerabilities
- SQLi, XSS, SSRF, IDOR
- API & business logic abuse
