Catalog
api-securityintermediate
API Penetration Testing
REST, GraphQL, and everything in between: a deep, dedicated track aligned to the OWASP API Security Top 10.
8 modules31 lessons13h
#api-security#rest#graphql#owasp-api-top-10#bola#authorization
What you'll learn
- Discover an application's full API surface, including undocumented and shadow APIs
- Exploit Broken Object Level Authorization (BOLA) and Broken Function Level Authorization (BFLA)
- Find and exploit injection and input validation flaws specific to API endpoints
- Exploit mass assignment vulnerabilities and abuse missing rate limiting for resource exhaustion
- Test GraphQL APIs for introspection abuse, excessive data exposure, and batching attacks
- Use modern API testing tooling (Postman, Burp Suite API testing, Kiterunner) in a real workflow
- Map findings to the OWASP API Security Top 10 and write a report an API team can act on
Who this course is for
Pentesters who want to go deep on API security specifically. APIs are now the primary attack surface for most modern applications, and this track goes far beyond a single module in a general web course. Basic HTTP/REST familiarity assumed.
A dedicated, deep-dive API security testing track: not a module bolted onto a web course, but a full track structured around the OWASP API Security Top 10. Covers API discovery and reconnaissance (including shadow APIs), authentication and authorization attacks (BOLA, BFLA), injection and input validation, rate limiting and mass assignment, GraphQL-specific attacks, and the modern tooling working API testers use daily.
Curriculum
Course content
01API Security Fundamentals
4 lessons- Welcome: Why APIs Are the Real Attack Surface NowEnroll to view
- REST, GraphQL, and SOAP, What Actually Differs for a TesterEnroll to view
- The OWASP API Security Top 10Enroll to view
Reviews
No reviews yet.