map → identify a trust assumption → test it → confirm impact → document. Repeat per feature. Depth over speed.
Lab 1 — Map an isolated target: enumerate its endpoints, inputs and auth boundaries; produce an attack-surface note. Quiz — Which parts of a request does the client control? What is a "trust boundary"?