Full WSTG-aligned web application pentest — 12-phase methodology from information gathering through reporting, with concrete commands, expected outputs, pitfalls, and verification per phase.
Attack SAML SSO via XSW, signature strip, metadata extract.
Use when two or more verified findings may combine into a higher-impact authorized attack path.
Use when verified WordPress findings may combine into an authorized path to administrative or server control.
Escape Docker containers to host root via 5 techniques.
Use when classifying a verified web or WordPress behavior and selecting a related validation skill.
Compare recon waves to find NEW, REGRESSED, PERSISTENT findings.
Use when starting or restructuring an authorized external web and API assessment.