📄️ Security Testing Quick Reference
Copy-paste reference for authorised security testing — OWASP Top 10 checks, test payloads for practice targets, security headers, cookie flags, curl recipes, scanner commands (ZAP, Semgrep, Trivy, Gitleaks), JWT decoding, CVSS bands, finding template and practice targets.
📄️ Security Testing Best Practices
Habits that make security testing safe, legal and useful — permission and scope, non-destructive proofs, shift-left, combine scanners with manual testing, triage findings, test access control hardest, protect data, report responsibly, and a pre-engagement and pre-report checklist.