Mayhem Blog

Why Vulnerability Scanning Alone Isn’t Enough for API Security

Why Vulnerability Scanning Alone Isn’t Enough for API Security

If you’re only looking for API compliance—a check box answer to “Is my API secure?”—then vulnerability scanning can provide that. It doesn’t, however, mean that your API is truly secure.
Which Type of API is Best: Key Features of REST, gRPC, and GraphQL APIs

Which Type of API is Best: Key Features of REST, gRPC, and GraphQL APIs

In this post, we’ll discuss the key features of REST, gRPC, and GraphQL APIs and which projects each API type is best for.
Automated API Testing Vs Manual Testing

Automated API Testing Vs Manual Testing

API testing can be manual or automated. Learn when to use automated vs. manual API testing and what to look for in an API testing tool.
Why API Security Is Everywhere (Except Where You Need It)

Why API Security Is Everywhere (Except Where You Need It)

Unfortunately, many devs and ops engineers don't view API security as a priority - and that's a mistake. In this blog post, we'll explore why API security is so important, and how you can make sure you're doing it right.
When API Testing Is Required and Industry-Specific API Standards

When API Testing Is Required and Industry-Specific API Standards

In this week’s post, we’ll talk about when API testing is required and industry-specific API testing standards.
What Is API Testing and Why Is It Important?

What Is API Testing and Why Is It Important?

APIs share data and enable communication between everything connected to the internet. API testing ensures that these connections are secure and work as intended.
If You’re Only Doing WAF, You’re Doing API Security Wrong

If You’re Only Doing WAF, You’re Doing API Security Wrong

Some organizations have begun using Web Application Firewalls (WAFs) to protect their APIs, but this isn’t a true solution to API security.
How to Use an HTTP Archive (HAR) With Mayhem

How to Use an HTTP Archive (HAR) With Mayhem

Learn how to fuzz an API without a specification by recording transactions with the API as an HTTP Archive (.har file).
How to Write Your Own Mayhem for API Plugin

How to Write Your Own Mayhem for API Plugin

Mayhem for API supports the writing of your own plugins to guide Mayhem for API into making legitimate requests to your API.

Fancy some inbox Mayhem?

Subscribe to our monthly newsletter for expert insights and news on DevSecOps topics, plus Mayhem tips and tutorials.

By subscribing, you're agreeing to our website terms and privacy policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.