Finding vulnerabilities like XSS, SQLi, IDOR, SSRF, and CSRF through manual and automated testing across web applications.
Testing REST and GraphQL APIs for broken auth, excessive data exposure, rate-limiting issues, and BOLA/BFLA vulnerabilities.
Analyzing APKs for insecure storage, exposed components, improper authentication, and runtime vulnerabilities via static and dynamic analysis.