Recon & mapping
- Enumerate subdomains, endpoints, and technologies
- Map every input, parameter, and authentication boundary
- Note roles and where trust decisions are made
Content & endpoint discovery
- Directory and parameter brute-forcing
- Mine JavaScript for hidden endpoints and secrets
- Pull historical URLs for forgotten routes
Vulnerability hunting
- Access control & IDOR, auth / session / JWT flaws
- Injection: SQLi, SSTI, command, SSRF
- Client-side: XSS, CSRF; then business logic
Exploitation & reporting
- Minimal reproducible PoC
- Chain low-severity bugs into real impact
- Clear write-up with remediation