Summary
- Input validation and protocol manipulation assessment for injection, parser differential testing, request smuggling, method tampering, header confusion, serialization abuse, and payload mutation.
- Hands off to authz, business-logic, exploit, or reporting workflows when those become the owner phase.