2025-08

Mobile API OSINT

iOS Application Security Testing Fundamentals

A practical primer on assessing iOS apps: IPA extraction, keychain, plist analysis, and dynamic instrumentation with Frida and objection.
Mobile API OSINT

Bypassing SSL Pinning to Intercept Mobile App APIs

A practical guide to intercepting mobile API traffic by defeating certificate pinning with Frida, objection, and Burp Suite.
Web Exploitation

REST API Penetration Testing Methodology: From Recon to BOLA

A practical, repeatable methodology for testing REST APIs: BOLA, mass assignment, broken rate limiting, and blue-team defenses.
Web Exploitation

GraphQL API Security Testing: Advanced Offensive and Defensive Techniques

Advanced GraphQL pentesting: introspection, batching abuse, depth-limit bypass, IDOR, and blue-team defenses.
Security

Breaking OAuth 2.0 and OpenID Connect: Redirect, State, and Token Attacks

A practical guide to OAuth 2.0 and OIDC attacks - redirect_uri abuse, state/CSRF, PKCE, and token leakage - with blue-team defenses.
Mobile API OSINT

OSINT for Red Teamers: Mapping People and Infrastructure

A practical red-team OSINT workflow for enumerating people and infrastructure with theHarvester, Shodan, breach data, and DNS recon.
Mobile API OSINT

Subdomain Enumeration and Attack Surface Mapping with Amass, Subfinder, and httpx

A practical recon workflow chaining amass, subfinder, httpx, and ffuf to map an organization's external attack surface.
Mobile API OSINT

Phishing and Initial Access Tradecraft for Authorized Red Teams

A practical look at pretexting, Gophish campaigns, Evilginx MFA phishing, and the blue-team controls that stop them.