Deselect any area to be excluded from this engagement.
Reconnaissance and information gathering Directory and parameter discovery, subdomain enumeration, JavaScript analysis, technology fingerprinting, exposed files
Injection SQL, NoSQL, command, XSS, XPath, LDAP, XXE, SSTI, CRLF, CSV, HTML, LFI and RFI, header injection, prototype pollution
Broken access control IDOR, horizontal and vertical privilege escalation, forced browsing, JWT attacks, CSRF, cookie tampering, path traversal, open redirection
Cryptographic failures SSL/TLS ciphers and protocols, certificate validity, plaintext transmission, weak hashing, key management, hardcoded secrets
Security misconfiguration CORS, clickjacking, security headers, CSP, cookie attributes, verbose errors, banner disclosure, request smuggling, CAPTCHA bypass, subdomain takeover
Insecure design Unrestricted file upload and RCE, account lockout gaps, race conditions, weak input validation, client-side trust, payment flow flaws, postMessage and WebSocket issues
Vulnerable and outdated components Components with known CVEs, unpatched dependency chains, unmaintained libraries
Authentication, session management and MFA OAuth, SSO and SAML weaknesses, OTP brute force and reuse, session fixation, predictable or non-expiring sessions, password policy, username enumeration
Software and data integrity failures Missing integrity checks, insecure deserialization, functionality included from untrusted sources
Security logging and monitoring Log injection and forging, sensitive data in logs, missing security event logging
Server-side request forgery (SSRF) Internal resource access, cloud metadata escalation, non-HTTP protocols, SMTP relay via SSRF
Business logic testing Approval bypass, workflow step skipping, price and quantity tampering, coupon and link reuse, transaction replay, identifier manipulation, race conditions