Two books, both still on the shelf: Black Hat GraphQL and Black Hat Bash.
Our founder co-wrote both for No Starch Press. They exist because the material did not, and clients kept asking where to send their engineers.
Nick Aleks co-authored Black Hat GraphQL (No Starch Press, 2023) and Black Hat Bash (No Starch Press, 2024). Neither started as a book. Both started as the same problem: a thing we do constantly on engagements, with no decent written reference to point clients at afterwards.
Black Hat GraphQL
GraphQL moved into production faster than the security tooling around it did. A single endpoint, a type system that will happily describe itself to an attacker, and authorisation logic scattered across resolvers — we kept finding the same failures and kept having to explain them from scratch. The book is that explanation, written once.
Black Hat Bash
The other one is less glamorous and gets used more. Offensive work is held together by shell — the loop you write at 2am to pull one field out of four hundred responses. Most people learn it badly, by copying. The book teaches it deliberately.
Why it matters here
Publishing is a forcing function. You cannot hand-wave a technique in print the way you can in a report nobody outside the client will read. Writing both books made our methodology better, which is most of the reason we did it.
ASEC