Reference library
API penetration testing guides
Four sourced, vendor-neutral guides for the people who scope, buy and read API penetration tests.
- OWASP API Security Top 10 (2023) The ten categories in the official words, what each one looks like in a REST or GraphQL API, the probe that finds it, and a public incident for every category that has one. Read
- API penetration testing cost Published European day rates and effort bands, the seven drivers that decide how many days you buy, two worked scopes, and the questions that make three quotations comparable. Read
- The API pentest report Four readers, seven sections and one worked finding. How to tell a report that will get fixed from a scanner dump with a cover page, before you commission either. Read
- DORA, NIS2 and PCI DSS None of the three names APIs. All three reach them. The clauses, the cadence each sets, the evidence each auditor accepts, and how to write the obligation into your own policy. Read