Free learning for Rot Hackers open-source tools

Learn security by doing the work.

Learn WSHawk and Basilisk through complete, free courses built around real open-source tools, controlled labs, and evidence you can defend.

01 Free forever02 Open-source tools03 Downloadable labs
Live pathWSH / 4.0.4
Current programme

WSHawk
Practitioner

Progress42%
New labIdentity drift
65verified lab cases
WSHawkBasiliskAuthorizationGraphQLWebSocketsAI red teamingEvidence
01 / COURSES

Start with a question.
Finish with proof.

Free, focused programmes turn complex security work into a deliberate sequence of understanding, practice, evidence, and independent judgment.

01Flagship path

WSHawk Practitioner

Build a reliable WSHawk workflow from project setup and identity capture through HTTP, GraphQL, and WebSocket replay.

  • Capture & replay
  • Identity recording
  • Object discovery
5 guided lessons · 5 guided labsExplore course
02Core security

Authorization by Design

Use matrices, explicit policies, semantic comparison, bounded object mutation, and safe writes to prove authorization failures.

  • IDOR / BOLA
  • BFLA
  • Tenant isolation
5 guided lessons · 5 guided labsExplore course
03Realtime systems

WebSocket Fieldwork

Test connection identity, rooms, subscriptions, event replay, and race behavior in stateful realtime systems.

  • Handshake auth
  • Rooms
  • Subscriptions
4 guided lessons · 4 guided labsExplore course
04Professional practice

Evidence That Holds Up

Turn technical behavior into protected, reproducible findings with semantic analysis, lifecycle management, export, and retesting.

  • Semantic analysis
  • Findings
  • Redaction
5 guided lessons · 5 guided labsExplore course
05Scanner practice

Injection & Browser Testing

Exercise every WSHawk injection family against paired secure and vulnerable controls, verify browser execution, and tune scanner confidence.

  • SQLi and NoSQLi
  • XSS and Playwright
  • XXE and SSRF
7 guided lessons · 7 guided labsExplore course
06Web modules

Recon & Web Assessment

Use WSHawk's crawler, directory, HTTP, headers, TLS, CORS, CSRF, WAF, sensitive-data, and chaining modules as one scoped workflow.

  • Crawl and directory
  • Headers, CORS and TLS
  • CSRF and WAF
6 guided lessons · 6 guided labsExplore course
07Realtime depth

WebSocket Engineering

Go beyond room checks into connection controls, interception, scanners, binary protocols, session security, subscriptions, and recovery behavior.

  • Handshake controls
  • Interceptor and replay
  • Binary analysis
6 guided lessons · 6 guided labsExplore course
08Operations

Projects, Evidence & Integrations

Manage durable projects, browser identities, flows, findings, protected evidence, reports, integrity, external systems, and certificates.

  • Project storage
  • Browser evidence
  • Reports and SARIF
6 guided lessons · 6 guided labsExplore course
09Tooling breadth

Interfaces & Defensive Validation

Choose the right WSHawk interface and use the defensive validator for egress, automation, and cross-site WebSocket controls.

  • CLI and dashboard
  • Classic and Go desktop
  • Python API and Docker
5 guided lessons · 5 guided labsExplore course
10AI security

Basilisk AI Red Teaming

Learn Basilisk from a safe first preview through deterministic model-security testing, evidence review, evaluation, desktop operation, and CI automation.

  • AI red teaming
  • Prompt injection
  • Model posture
7 guided lessons · 7 guided labsExplore course
02 / THE METHOD

No passive watching.
Every lesson moves.

Learn the idea, operate the tool, work the controlled target, then explain what the evidence proves.

01

Understand the system

Short, precise lessons explain the protocol, trust boundary, and failure mode before a tool is opened.

02

Work the lab

Controlled targets let you capture traffic, form a hypothesis, and safely exercise the behavior yourself.

03

Build the proof

Save the requests, identities, responses, hashes, and reasoning needed to make a defensible finding.

04

Prove mastery

Scenario-based assessments check judgment and repeatability—not whether you memorized a button sequence.

03 / TWO CONTROLLED LABS
Controlled environment

Practice locally.
Know the answer.

Work WSHawk's secure-vulnerable web controls and Basilisk's deterministic AI-security ground truth. Both labs stay on loopback and make expected behavior explicit.

  • 01 WSHawk: 19 verified web and realtime controls
  • 02 Basilisk: 46 deterministic ground-truth scenarios
  • 03 Secure and vulnerable pairs for comparison
  • 04 Reproducible evidence, reports, and retesting
LAB / AUTHZ-07Resource access matrix
Running
GET/resource/tenant-b/document-204200
Identity
Status
Behavior
Signal
AAnonymousNo session
401
Authentication required
Expected
UUser AForeign tenant
200
Owner document returned
High drift
OUser BResource owner
200
Owner document returned
Expected
RAdministratorPrivileged
200
Owner document returned
Expected
!
Potential horizontal BOLAForeign identity received owner-equivalent data.
92% confidence
04 / LEARNING PATHS

Go from curious
to capable.

Choose a stage, follow the sequence, and move forward when you can reproduce the outcome—not merely describe it.

05 / OUTCOMES

Leave with a workflow,
not a playlist.

By the end of a path, you should be able to approach an unfamiliar target, choose the right test, control risk, and produce evidence another professional can repeat.

01Model identity, state, and trust boundaries
02Operate WSHawk across HTTP, GraphQL, and WebSocket flows
03Separate expected access differences from real authorization failures
04Run Basilisk model-security validations, posture comparisons, and evals safely
05Produce sanitized, reproducible, retestable findings
LEARN THE TOOL. UNDERSTAND THE SYSTEM.

Built around tools shipped by Rot Hackers.

THE WORK STARTS HERE

Learn every tool.
For free.

Rot Hackers Open Source Academy teaches what the system is doing, why the behavior matters, and how to prove it—without a paywall.

Explore free courses