LEARNING PATH: Advanced Application Security

API Security: Attack and Defense

“Distributed” is the name of the game today, and web applications are no different. They’re often divided up into smaller ‘microservices’ and work with multiple clients, from browsers and mobile applications to other services. 

This has resulted in many older websites becoming APIs, or Application Programming Interfaces. Today, APIs are ubiquitous and companies are adopting, developing, and harnessing their potential at massive scale. 

In this API Security course, we take a deep-dive into both offensive and defensive techniques. We explore vulnerabilities that are specific to Web APIs, specifically REST APIs, and look at how these vulnerabilities can be exploited by malicious actors. 

Subsequently, we look at defense, where we explore deep-rooted strategies in addressing these vulnerabilities comprehensively. All of these lessons will be taught with the aid of our world-renowned hands-on labs that show you not only what you should do, but how you should do it.

We’ll explore this class through the lens of the now-famous OWASP API Security Top 10 Document that defines the Top 10 API Vulnerabilities that currently affect Web APIs.

API security course from AppSecEngineer
Proficiency Intermediate
Audience Developers
Course Duration​ 7
Lessons​ 20
Cloud Labs​ 8



Cloud Security Expert

Course duration




Cloud Labs


  • BOLA - Insecure Direct Object Reference
  • BFLA - Verb Tampering
  • Mass Assignment
  • Excessive Data Exposure
  • ReDOS Resource Exhaustion attacks
  • Rate Limiting and other Controls for Resource Management
  • Request Filter Input Validation
  • JSON Schema Input Validation
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking "Accept" you consent to the use of All the cookies