Explore Academic Resources

Runtime protection for APIs

What Is API Runtime Protection?

TL;DR API runtime protection 101 API runtime protection is a security layer that monitors API traffic

API Red-Teaming: The Complete Guide to Finding and Exploiting API Vulnerabilities

TLDR What Is API Red-Teaming? API red-teaming is an offensive security exercise where testers act as

API Discovery

All You Need to Know About API Discovery

TL;DR What is API Discovery? API discovery identifies every API that an organization runs, whether a

Featured Posts

Filter by Tags

Zero-day Attack

A Zero-day Attack is a cyberattack that exploits a previously unknown vulnerability – a “zero-day vulnerability”

WebSockets

WebSockets is a communication protocol that provides full-duplex, persistent, two-way communication channels between a client (such

Web Scraping

Web Scraping is the automated extraction of data from websites and web applications, typically using bots

Web Application Security

Web Application Security is the practice and discipline of protecting web applications from security threats, vulnerabilities,

WAF / Web Application Firewall

A WAF, or Web Application Firewall, is a security solution that monitors, filters, and blocks malicious

WAAP / Web Application and API Protection

WAAP, which stands for Web Application and API Protection, is a category of security solution that

Vulnerability Scan

A Vulnerability Scan is an automated process that examines systems, networks, applications, or APIs to identify

Threat Modeling

Threat Modeling is a structured, proactive process for identifying, analyzing, and addressing potential security threats to

Threat Landscape

The Threat Landscape refers to the overall, ever-evolving picture of the cyber threats facing an organization,

Threat Actor

A Threat Actor is any individual, group, or entity that carries out, or has the intent

Taint Analysis

Taint Analysis is a technique used in security testing and program analysis to track how untrusted

Swagger

Swagger is a widely used set of tools and specifications for designing, building, documenting, and consuming

Software Composition Analysis (SCA)

Software Composition Analysis (SCA) is a security practice and category of tooling focused on identifying and

Social Engineering Attack

A Social Engineering Attack is a form of attack that manipulates people into divulging confidential information,

Shadow APIs

Shadow APIs are APIs that exist and are actively used within an organization but operate outside

Sensitive Data Exposure

Sensitive Data Exposure is a security risk in which confidential or sensitive information is not adequately

Security Misconfiguration

Security Misconfiguration is a category of vulnerability that arises when systems, applications, servers, frameworks, cloud services,

Secure SDLC

A Secure SDLC (Secure Software Development Life Cycle) is an approach to software development that integrates

SAST

SAST, or Static Application Security Testing, is a method of analyzing an application’s source code, bytecode,

Remote Code Execution (RCE)

Remote Code Execution (RCE) is one of the most severe categories of security vulnerability, in which

Red Team

A Red Team is a group of security professionals who simulate real-world adversaries – thinking and