
Are you interested in learning how to test different types of APIs for quality and security? Do you want to dive into the essential skills and techniques for testing GraphQL, SOAP, and REST APIs? If so, this course is for you!
Course Length: 4 Hours
Includes a Certificate of Completion
Next scheduled date:
Description
Are you interested in learning how to test different types of APIs for quality and security? Do you want to dive into the essential skills and techniques for testing GraphQL, SOAP, and REST APIs? If so, this course is for you!
In this course, you will learn the fundamentals of API testing, including what APIs are, how they work, and why they are important. You will also learn the differences between GraphQL, SOAP, and REST APIs, and how they affect the way you test them for flaws and vulnerabilities. You will gain hands-on experience with various tools and frameworks for API testing, such as Postman, SoapUI, and GraphQL Playground. By the end of this course, you will be equipped to:
- Perform endpoint analysis to understand the API’s structure and functionality
- Conduct scans on APIs to identify security misconfigurations and excessive data exposure, ensuring robust security measures
- Understanding the unique issues affected GraphQL, REST, and SOAP API’s
- Thoroughly assess APIs for rate limiting mechanisms and business logic flaws that may lead to unauthorized access or abuse
System Requirements
-
Student Requirements
- Students will need a computer capable of running the local SamuraiWTF VM lab environment.
FAQ
• How to attack REST APIs
• How to prevent API security flaws
• Explore and attack OAuth and JWTs
• Understand that strong data validation is key to API security
This course is suitable for individuals seeking to learn how to hack web APIs or enhance their API security skills. Whether you are a penetration tester, security analyst, developer, or an individual interested in understanding API security, this course will provide you with the necessary knowledge and hands-on experience. Prior foundational knowledge in web application security, HTTP requests, and familiarity with common web application testing tools, such as Burp Suite or OWASP ZAP, is recommended to make the most of this course.
About the Instructor

Jennifer Shannon
"Known Bad Actor"Bio
Jennifer is a Senior Security Consultant with Secure Ideas with a background in malware analysis, penetration testing, and teaching. She graduated with honors from Florida State College at Jacksonville’s networking program. An avid computer geek for most of her life, she began her journey in cybersecurity as a SOC Analyst where she showed an aptitude for both penetration testing and malware analysis. She was quickly promoted into a role that capitalized on her abilities.
Related products
-
Multiple InstructorsLive
Workshop: Foundations of Network Forensics and Analysis with Troy Wojewoda
View Course This product has multiple variants. The options may be chosen on the product page -
Multiple InstructorsLive
Workshop: The Hitchhiker’s Guide To Social Engineering with Cameron Cartier
View Course This product has multiple variants. The options may be chosen on the product page -
Multiple InstructorsLive
Assumed Compromise: A Methodology with Detections and Microsoft Sentinel
View Course -
Multiple InstructorsLive
Workshop: Offensive Tooling Foundations with Chris Traynor
View Course