API Security & Microservices Exploitation
BOLA/BFLA authorization flaws, GraphQL query depth attacks, mass assignment, and OAuth 2.0 / JWT vulnerabilities.
Course Overview & Objectives
Modern architectures rely on REST and GraphQL APIs. Master the OWASP API Security Top 10, discovering Broken Object Level Authorization (BOLA), mass assignment, JWT signature stripping, and GraphQL denial-of-service vulnerabilities.
What You Will Master
- Perform systematic audits against the OWASP API Security Top 10
- Exploit BOLA/IDOR flaws to access restricted multi-tenant business data
- Crack weak JWT HMAC secrets and manipulate claims for privilege escalation
- Abuse GraphQL batch queries, deep recursion, and schema introspection flaws
Prerequisites
- REST API basics
- Familiarity with JSON and HTTP authentication
Platforms & Tools Covered
Detailed Curriculum Modules
1 modules structured from foundational theory through complex adversarial execution.
REST API Authentication & JWT Deep Dive
Token forgery, algorithm confusion attacks (RS256 to HS256), and jku/kid header injections.
Hands-on Virtual Sandbox Labs
Zero local hardware dependencies. Provisioned in cloud containers via browser terminal.
GraphQL Batching & Nested Recursion DoS
Trigger compute starvation on a vulnerable GraphQL endpoint via circular queries.
Faculty & Lead Instructor
Direct weekly instruction, live office hours, and code-review feedback.
Kunal Singh
Thread Security EducationLead Security Architect
Advising engineering teams on resilient microservice architectures and zero-trust API gateways.
Frequently Asked Questions
Everything you need to know about scheduling, cohort admissions, and lab access.
Are practical API targets provided?
Yes! You test against custom banking and healthcare API testbeds simulated in cloud sandboxes.
Ready to Master API Security & Microservices Exploitation?
Join the upcoming cohort. Seats are limited to maintain a high faculty-to-student ratio and rigorous sandbox feedback.