- Before contest, go through docs
- Find similar protocols, similar audits and their reports
- Make a list of specifications, maybe go through the interfaces, if available. Properties for public and external functions would normally be there in the docs
- Pen and paper, write down a list of specs/invariants, draw a couple of flowcharts, completely understand what you need to look for
- Certora
- Manual Review
- Slither, Aderyn (Static Analysis)
- Check coverage and fuzz, if needed