API Penetration Testing
REST, GraphQL, and everything in between: a deep, dedicated track aligned to the OWASP API Security Top 10.
Course overview
A dedicated, deep-dive API security testing track: not a module bolted onto a web course, but a full track structured around the OWASP API Security Top 10. Covers API discovery and reconnaissance (including shadow APIs), authentication and authorization attacks (BOLA, BFLA), injection and input validation, rate limiting and mass assignment, GraphQL-specific attacks, and the modern tooling working API testers use daily.
What you'll learn
- Discover an application's full API surface, including undocumented and shadow APIs
- Exploit Broken Object Level Authorization (BOLA) and Broken Function Level Authorization (BFLA)
- Find and exploit injection and input validation flaws specific to API endpoints
- Exploit mass assignment vulnerabilities and abuse missing rate limiting for resource exhaustion
- Test GraphQL APIs for introspection abuse, excessive data exposure, and batching attacks
- Use modern API testing tooling (Postman, Burp Suite API testing, Kiterunner) in a real workflow
- Map findings to the OWASP API Security Top 10 and write a report an API team can act on
Who this course is for
Pentesters who want to go deep on API security specifically. APIs are now the primary attack surface for most modern applications, and this track goes far beyond a single module in a general web course. Basic HTTP/REST familiarity assumed.
Curriculum
Module 1: API Security Fundamentals
- Welcome: Why APIs Are the Real Attack Surface Now
- REST, GraphQL, and SOAP, What Actually Differs for a Tester
- The OWASP API Security Top 10
- Module 1 Knowledge Check
Module 2: API Discovery and Reconnaissance
- Finding Documented APIs: Swagger, OpenAPI, and Postman Collections
- Finding Shadow and Undocumented APIs
- API Versioning and Its Security Implications
- Lab: Full API Discovery Sweep of a Test Application
Module 3: Authentication and Authorization Attacks
On completion of every module, enrolled students receive a verifiable certificate of completion. Full curriculum, hands-on labs, and instructor support are available at pentestnotes.tech/courses/api-penetration-testing.