Offensive security
AR / SERVICE
API securityat the trust boundary.
Test REST and GraphQL interfaces for broken object-level authorisation, abuse, excessive data exposure, and weak operational controls.
Typical coverage
The scope follows the system.
These are common areas, not a pre-filled checklist. Final coverage is agreed around the environment, risks, access, and decisions the engagement needs to support.
01REST & GraphQL
02BOLA and BFLA
03Token handling
04Rate limits
05Schema exposure
06Abuse cases
What leaves the engagement
Output somebody can own.
01
Endpoint coverage map
02
Authorisation findings
03
Abuse-case evidence
04
Remediation priorities
Interactive lab
Explore the immersive model for this practice.
Start somewhere honest
Start with the system and the decision.
Tell us what is in scope, what is changing, and who needs to act on the output. We will shape the method around that context.
Start a conversation