Authentication & session security — Assess login flows, session handling, password controls, MFA-related flows, and authentication weaknesses.
Authorization & access control — Test whether users can access functions or data beyond their intended permissions.
Input & output handling — Assess injection risks, unsafe processing, file handling, output encoding, and related attack paths.
Business logic — Look for abuse cases and workflow weaknesses that automated scanners may miss.
Configuration & exposure — Review relevant security headers, exposed functionality, error handling, and application-level configuration.