Dana Epp's Blog
Security (de)engineering for fun and profit
Learn how to improve your application security code reviews with the help of tools like graudit.
Learn how to write Burp Suite extensions using the new Montoya API with Kotlin and Visual Studio Code (VS Code)
Learn how to use artificial intelligence (AI) to discover sensitive data in the APIs you are hacking with the help of Microsoft Presidio.
Learn how to reverse engineer an Electron app to find artifacts like source code and API endpoints, and capture live traffic with Burp Suite.
Learn how to weaponize developer tools used for API linting to find attack vectors in the APIs you are hacking.
Learn everything you need to know about how to get started writing API security tests in Javascript using Postman.
Learn how to improve the performance of your port scans against API servers with the use of Project Discovery’s Naabu scanner.
Learn how to improve your recon process with the use of apkleaks to find hidden API servers, secrets, and endpoints embedded in mobile apps.
Let me show you how Nuclei can be used for more than vulnerability scanning. Learn how to leverage it as a tool for your API hacking.
Learn how to detect API endpoints and extract source code from web app frontends using JS Miner, a FREE Burp Suite Professional extension.