Practical notes from the field: recon workflows, bug bounty tooling, mobile testing setups, and the security experiments worth writing down.