К содержимому
learnspaceYOUR NEXT CHAPTER
ПРОСТРАНСТВО ОБУЧЕНИЯ
ГлавнаяКаталог курсовМоё обучениеCoursera

Знания без границ

Учитесь у лучших университетов и компаний мира.

Открыть Coursera
Интеграция
Пространство университета
Моё пространствоСтраница курса
↵
ЯЛичный кабинетСтудент
© 2026 LearnSpaceКаждый день — возможность узнать больше.Помощь
API Security Testing for Pentesters & Bug Hunters (2026) · LearnSpace
Назад в каталог
courseraПрограммирование

API Security Testing for Pentesters & Bug Hunters (2026)

Курс от Packt
Средний≈ 6.1 чАнглийский
О курсеНавыкиПрограммаПреподаватели

О курсе

This course features Coursera Coach! A smarter way to learn with interactive, real-time conversations that help you test your knowledge, challenge assumptions, and deepen your understanding as you progress through the course. Dive into the world of API security testing with this comprehensive course designed for both aspiring bug hunters and penetration testers. You’ll gain hands-on experience with key API vulnerabilities, understand attack surfaces, and learn methods to detect and exploit weaknesses while strengthening your security mindset. This course equips you with actionable skills that are highly relevant in today’s cybersecurity landscape. Starting with a solid foundation, the course introduces API concepts, explains their importance in modern applications, and walks you through the different API types including REST, SOAP, and GraphQL. You’ll explore lab setups using vAPI and Docker, learn to work with Swagger UI and OpenAPI specifications, and practice configuring secure API requests for testing purposes. The course then moves into advanced, practical exercises with the OWASP Top 10 API vulnerabilities. Through interactive labs using Postman, you’ll learn to identify and exploit broken object-level authorization, excessive data exposure, mass assignment, security misconfigurations, and more. You’ll also gain insight into using fuzzers, parsing JSON outputs, and applying AI techniques in API pentesting. This course is ideal for ethical hackers, penetration testers, bug bounty hunters, and security enthusiasts who want to strengthen their API testing skills. No prior advanced experience is required, though a basic understanding of web technologies is helpful. Difficulty level is intermediate, suitable for learners looking to bridge theory and hands-on security practice. By the end of the course, you will be able to confidently identify API vulnerabilities, set up secure lab environments, leverage tools like Postman and Swagger UI for testing, and apply advanced techniques including fuzzing and AI-assisted pentesting to real-world API security challenges.

Навыки, которые вы освоите

API TestingSecurity TestingPostman API PlatformVulnerability AssessmentsOpen Web Application Security Project (OWASP)Application Programming Interface (API)Application SecurityDocker (Software)Penetration TestingAuthenticationsExploit developmentAI IntegrationsExploitation techniquesJSONContinuous MonitoringVulnerability ScanningSoftware DocumentationTest ToolsSecurity ManagementRestful API

Программа курса

6 модулей · 40 учебных материалов

01Introduction1 материалов

Introduction

IntroductionВидео
02Introduction to API Security4 материалов

Introduction to API Security

Introduction to API SecurityВидеоWhy APIs are important - API Attack SurfaceВидео

Учитесь у экспертов

Packt - Course Instructors

Преподаватель курса

API Security Testing for Pentesters & Bug Hunters (2026)
В каталоге вашей программы

Инвестируйте в себя

Новые знания — в удобное для вас время.

Начать на Coursera

Обучение откроется на Coursera
в новой вкладке

Обучение на Coursera

≈ 6.1 ч

6 модулей

Язык: Английский

Часть программы вашего университета
Identifying API Endpoints for Security TestingDIALOGUE
Introduction to API Security - AssessmentЗадание
03Understanding APIs for Bug Bounties4 материалов

Understanding APIs for Bug Bounties

Bug Bounty Targets for APIВидеоHow to Find HackerOne API Reports & Purpose of APIsВидеоExploring Common API Vulnerabilities and Real-World Bug ReportsDIALOGUEUnderstanding APIs for Bug Bounties - AssessmentЗадание
04Deep Dive into APIs7 материалов

Deep Dive into APIs

What are the Types of API?ВидеоUnderstanding REST APIsВидеоUnderstanding SOAP APIsВидеоUnderstanding GraphQL APIsВидеоUse Cases of APIsВидеоComparing REST, SOAP, and GraphQL APIsDIALOGUEDeep Dive into APIs - AssessmentЗадание
05Lab Setup using vAPI7 материалов

Lab Setup using vAPI

Lab Setup in DockerВидеоUnderstanding OpenAPI SpecificationsВидеоIntroduction to Swagger UIВидеоBreakdown of Swagger UI ComponentsВидеоConfiguring Swagger UI to Send RequestsВидеоSetting Up and Testing API Security LabsDIALOGUELab Setup using vAPI - AssessmentЗадание
06OWASP Top 10 Practical Test Cases17 материалов

OWASP Top 10 Practical Test Cases

Broken Object Level Authorization - Part 1ВидеоBroken Object Level Authorization - Part 2ВидеоPostman FundamentalsВидеоPostman Lab & Workspace SetupВидеоUnderstanding Collections in PostmanВидеоUnderstanding Environments in PostmanВидеоExcessive Data ExposureВидеоMass Assignment VulnerabilityВидеоSecurity MisconfigurationВидеоUnderstanding FuzzerВидеоImproper Assets ManagementВидеоNo Logging & MonitoringВидеоParsing API JSON Output to Grep InfoВидеоUsing AI for API PentestingВидеоOWASP Top 10 Practical Test Cases - AssessmentЗаданиеFull Course Practice AssessmentЗаданиеFull Course AssessmentЗадание