SAST detection methodology for weak / misused cryptography (CWE-327, CWE-328, CWE-326, CWE-780), including ECB mode, static/reused IV or nonce, MD5/SHA1 and fast unsalted hashing for passwords, low KDF iterations, hardcoded keys, CBC-without-MAC padding oracles, textbook RSA, disabled TLS verification, and timing-unsafe comparison.