<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<oembed>
  <author_name>mti-techblog-writer</author_name>
  <author_url>https://blog.hatena.ne.jp/mti-techblog-writer/</author_url>
  <blog_title>エムティーアイ エンジニアリングブログ</blog_title>
  <blog_url>https://tech.mti.co.jp/</blog_url>
  <categories>
    <anon>セキュリティ</anon>
  </categories>
  <description>※この記事は「エムティーアイ Blog Summer 2026」の 6/26 の記事です。 こんにちは、テクノロジー本部 Red Teamの石廣です。 今回は、Red Teamの強みでもある手動診断について、自動スキャンとの違いを交えながらお話しします。 目次 はじめに 自動スキャンが得意なこと 自動・手動・コードレビューの役割分担 自動スキャンが見落とすもの 1. ビジネスロジックの脆弱性 2. 複雑な IDOR（水平権限昇格） 3. 競合状態 4. 多段階の攻撃チェーン 5. 認証フローのバイパス 6. SSRF の複雑なケース 手動診断のアプローチ 手動診断にも限界はある まとめ 参考資…</description>
  <height>190</height>
  <html>&lt;iframe src=&quot;https://hatenablog-parts.com/embed?url=https%3A%2F%2Ftech.mti.co.jp%2Fentry%2Fac2026summer%2F0626&quot; title=&quot;手動診断でしか見つからない脆弱性の話 - エムティーアイ エンジニアリングブログ&quot; class=&quot;embed-card embed-blogcard&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;display: block; width: 100%; height: 190px; max-width: 500px; margin: 10px 0px;&quot;&gt;&lt;/iframe&gt;</html>
  <image_url>https://cdn-ak.f.st-hatena.com/images/fotolife/m/mti-techblog-writer/20260623/20260623134148.png</image_url>
  <provider_name>Hatena Blog</provider_name>
  <provider_url>https://hatena.blog</provider_url>
  <published>2026-06-26 12:00:00</published>
  <title>手動診断でしか見つからない脆弱性の話</title>
  <type>rich</type>
  <url>https://tech.mti.co.jp/entry/ac2026summer/0626</url>
  <version>1.0</version>
  <width>100%</width>
</oembed>
