API SecurityAdvanced Level65 Hours Live

API Security & Microservices Exploitation

BOLA/BFLA authorization flaws, GraphQL query depth attacks, mass assignment, and OAuth 2.0 / JWT vulnerabilities.

Broken Object Level Auth (BOLA)
GraphQL Introspection & Batching
OAuth 2.0 Redirect URI Hijacking
65 Hours Practical Workload
1 Core Modules
1 Sandboxed Labs
Cryptographic TS-ID Verifiable

Course Overview & Objectives

Modern architectures rely on REST and GraphQL APIs. Master the OWASP API Security Top 10, discovering Broken Object Level Authorization (BOLA), mass assignment, JWT signature stripping, and GraphQL denial-of-service vulnerabilities.

What You Will Master

  • Perform systematic audits against the OWASP API Security Top 10
  • Exploit BOLA/IDOR flaws to access restricted multi-tenant business data
  • Crack weak JWT HMAC secrets and manipulate claims for privilege escalation
  • Abuse GraphQL batch queries, deep recursion, and schema introspection flaws

Prerequisites

  • REST API basics
  • Familiarity with JSON and HTTP authentication

Platforms & Tools Covered

PostmanKiterunnerjwt_toolInQL GraphQL ScannerBurp Suite

Detailed Curriculum Modules

1 modules structured from foundational theory through complex adversarial execution.

65 Total Workload Hours
MODULE 01

REST API Authentication & JWT Deep Dive

1 Lessons

Token forgery, algorithm confusion attacks (RS256 to HS256), and jku/kid header injections.

Exploiting JWT None Algorithm & Header Injections
50m

Hands-on Virtual Sandbox Labs

Zero local hardware dependencies. Provisioned in cloud containers via browser terminal.

LAB 01~50 mins

GraphQL Batching & Nested Recursion DoS

Trigger compute starvation on a vulnerable GraphQL endpoint via circular queries.

Skills Tested:GraphQL, DoS Defense

Faculty & Lead Instructor

Direct weekly instruction, live office hours, and code-review feedback.

KS

Kunal Singh

Thread Security Education

Lead Security Architect

Advising engineering teams on resilient microservice architectures and zero-trust API gateways.

Frequently Asked Questions

Everything you need to know about scheduling, cohort admissions, and lab access.

Are practical API targets provided?

Yes! You test against custom banking and healthcare API testbeds simulated in cloud sandboxes.

Ready to Master API Security & Microservices Exploitation?

Join the upcoming cohort. Seats are limited to maintain a high faculty-to-student ratio and rigorous sandbox feedback.

API Security & Microservices Exploitation | TSE Masterclass | Thread Security Education (TSE)