Security Logging & Monitoring Failures
Hard to test from outside, but note where actions appear untracked or where log injection is possible.
OWASP rank: 9
Practical checks
- Check whether security events seem logged/alerted
- Test for log injection via user input
- Note absence of lockout/alerting on abuse