In this demonstration, we use Postman to launch a combination of traditional application attacks (e.g., SQLi, XSS) and more sophisticated API attacks. The video shows the difference between what a WAF can identify and block vs. the attacks the Salt platform is able to prevent.
Additional resources

API Security Best Practices Guide

Solution Brief: Web Application Firewalls and API Security
Download Solution Brief: Web Application Firewalls and API Security Now

Securing APIs: The New Application Attack Surface
Download Securing APIs: The New Application Attack Surface Now