I'm interested less in the tools of the trade (there are many questions here already about that), and I am interested more in the process by which you would go about using those tools. So for instance, OWASP has the following testing guide:
https://www.owasp.org/index.php/OWASP_Testing_Guide_v3_Table_of_Contents
Do you have similar go-to guides, where you will move from A-Z though the list, testing for exploits, or do you consider a great deal of the process to be of a "non-disclosure" sort?