Web application and API testing
Authenticated and unauthenticated, following the OWASP Web Security Testing Guide as a floor rather than a ceiling. Business-logic flaws — the ones no scanner finds — are where most of the interesting results come from.
