- INFO
- WSTG-INFO Information Gathering: Information exposure and application mapping.
- CONF
- WSTG-CONF Configuration and Deployment Management Testing: Configuration and deployment management.
- IDNT
- WSTG-IDNT Identity Management Testing: Identity management: roles, registration and provisioning.
- ATHN
- WSTG-ATHN Authentication Testing: Authentication: credentials, recovery and lockout.
- SESS
- WSTG-SESS Session Management Testing: Session management: tokens, cookies, logout and timeout.
- INPV
- WSTG-INPV Input Validation Testing: Input validation and injection handling.
- ERRH
- WSTG-ERRH Testing for Error Handling: Error handling without information leakage.
- CRYP
- WSTG-CRYP Testing for Weak Cryptography: Transport security and cryptographic choices.
- BUSL
- WSTG-BUSL Business Logic Testing: Business logic and multi-step workflow integrity.
- CLNT
- WSTG-CLNT Client-side Testing: Client-side security: DOM, cross-origin policy and framing.
- APIT
- WSTG-APIT API Testing: GraphQL and API surface review.
- API2
- API2:2023 Broken Authentication: API authentication and token handling.
- API3
- API3:2023 Broken Object Property Level Authorization: Property level authorization on reads and writes.
- API4
- API4:2023 Unrestricted Resource Consumption: Rate limits and resource consumption controls.
- API6
- API6:2023 Unrestricted Access to Sensitive Business Flows: Protection of sensitive business flows.
- API7
- API7:2023 Server Side Request Forgery: Server side request forgery defenses.
- API8
- API8:2023 Security Misconfiguration: API security configuration and hardening.
- API9
- API9:2023 Improper Inventory Management: API inventory, versions and undocumented endpoints.
- API10
- API10:2023 Unsafe Consumption of APIs: Safe consumption of third-party APIs.
- IAM
- Least privilege for users, roles and service accounts.
- TRUST
- Privilege escalation paths and cross-account trust.
- SIGN-IN
- Sign-in hardening: federation, MFA and conditional access.
- STORAGE
- Object storage exposure and access policies.
- SECRETS
- Secrets in code, images and secret stores.
- CI/CD
- CI/CD pipeline integrity and build permissions.
- METADATA
- Instance metadata and workload identity protection.
- CONTAINERS
- Container and Kubernetes configuration.
- SERVERLESS
- Serverless functions and event triggers.
- AI SERVICES
- Hosted AI services: model endpoints, keys and quotas.
- LOGGING
- Logging and audit trail coverage.
- EXTERNAL
- External infrastructure: exposed hosts, services and remote access.