The talk will be focused on pentesting techniques for applications using GraphQL. As applications become data intensive, GraphQL will be the frontrunner when it comes to web and mobile applications and is getting rapidly adopted for new and existing API infrastructure. GraphQL guidelines can be implemented in a variety of ways and hence vulnerabilities are configuration specific and custom to the implementation at hand. The talk will discuss both traditional web application and non-traditional core GQL specific vulnerabilities and demonstrate the same for pentesting such implementations in a holistic manner.