Skip to content

Details

## Mini API Security Hands-On Workshop by Practical DevSecOps!

The mini 90-minute API Security hands-on workshop provides practical experience in API security through live demonstrations and guided exercises. Participants will learn to identify, exploit, and defend against common API vulnerabilities using industry-standard tools. The workshop covers authentication mechanisms, common attack techniques, and defensive scanning. No slides, but whiteboard notes, and only real-world demonstrations in a controlled lab environment that you can practice.

In this workshop:

  1. You will directly work with APIs to understand security from both offensive and defensive perspectives.
  2. You will learn API authentication with HTTP Basic, API Keys, OAuth, JWT.
  3. You will learn enumeration and exploitation techniques using tools like FFUF.
  4. You will learn to exploitcritical vulnerabilities including insecure deserialization and path traversal attacks

The workshop concludes with defensive techniques using automated scanning tools and implementing security controls like rate limiting.

All exercises are conducted in a dedicated lab environment, emphasizing learning by doing—each concept is immediately reinforced through hands-on practice.

The Practical DevSecOps's lab environment is available through a browser, and known to work well even on notebooks, and ipads without any third party additional software.

Participants leave with practical skills to immediately secure APIs in their own environments.

Related topics

Application Security
OWASP
Software Security
Education
API

Sponsors

Security Compass

Security Compass

Global Contributing Corporate Member & Local Event Supporter

BDO Canada

BDO Canada

Global Contributing Corporate Member & Local Event Sponsor

Corellium

Corellium

Local Event Sponsor

Cycode

Cycode

Local Event Sponsor

You may also like