Web applications
Authentication and session handling, access control between accounts and between roles, injection into whatever the application talks to, and the business logic that only makes sense once you understand what the application is for. The last category is the one scanners never find.