Web App Penetration Testing
Manual testing on live bug bounty programs — GraphQL mutation abuse, IDOR/BOLA, JWT and session flaws, CSRF, rate-limit bypasses. Recon-first workflow with Burp Suite, ffuf, subfinder and Wappalyzer before a single request is sent with intent.