Java code auditing TL;DR: Servlets, filters, deserialisation, expression injection, JDBC. Decompile JARs with CFR / Procyon / jadx. Stub — to be filled in. What it is TODO Preconditions / where it applies TODO Technique TODO Detection and defence TODO References TODO