Understand the system
Short, precise lessons explain the protocol, trust boundary, and failure mode before a tool is opened.
↗
ROT HACKERSACADEMYStart learning Practical education for modern web, GraphQL, and WebSocket security—built around real tools, controlled labs, and evidence you can defend.
Focused programmes turn complex security work into a deliberate sequence of understanding, practice, evidence, and independent judgment.
Build a reliable WSHawk workflow from project setup and identity capture through HTTP, GraphQL, and WebSocket replay.
Use matrices, explicit policies, semantic comparison, bounded object mutation, and safe writes to prove authorization failures.
Test connection identity, rooms, subscriptions, event replay, and race behavior in stateful realtime systems.
Turn technical behavior into protected, reproducible findings with semantic analysis, lifecycle management, export, and retesting.
Exercise every WSHawk injection family against paired secure and vulnerable controls, verify browser execution, and tune scanner confidence.
Use WSHawk's crawler, directory, HTTP, headers, TLS, CORS, CSRF, WAF, sensitive-data, and chaining modules as one scoped workflow.
Go beyond room checks into connection controls, interception, scanners, binary protocols, session security, subscriptions, and recovery behavior.
Manage durable projects, browser identities, flows, findings, protected evidence, reports, integrity, external systems, and certificates.
Choose the right WSHawk interface and use the defensive validator for egress, automation, and cross-site WebSocket controls.
Learn the idea, operate the tool, work the controlled target, then explain what the evidence proves.
Short, precise lessons explain the protocol, trust boundary, and failure mode before a tool is opened.
↗Controlled targets let you capture traffic, form a hypothesis, and safely exercise the behavior yourself.
↗Save the requests, identities, responses, hashes, and reasoning needed to make a defensible finding.
↗Scenario-based assessments check judgment and repeatability—not whether you memorized a button sequence.
↗Compare anonymous, user, owner, and administrator behavior against the same object. Learn when a difference is expected—and when identical access proves a vulnerability.
Choose a stage, follow the sequence, and move forward when you can reproduce the outcome—not merely describe it.
Protocols, scope, traffic capture, request anatomy, state, identity, and ethical testing practice.
Authorization testing, object discovery, safe mutation, browser evidence, races, and reproducible reporting.
Binary protocols, multi-tenant systems, automation, attack chains, false-positive control, and tool internals.
By the end of a path, you should be able to approach an unfamiliar target, choose the right test, control risk, and produce evidence another professional can repeat.
Learn what the system is doing, why the behavior matters, and how to prove it.
Explore the academy ↗