Built for practitioners, not spectators

Learn security by doing the work.

Practical education for modern web, GraphQL, and WebSocket security—built around real tools, controlled labs, and evidence you can defend.

01 Guided curriculum02 Hands-on labs03 Versioned lessons
Live pathWSH / 4.0.4
Current programme

WSHawk
Practitioner

Progress42%
New labIdentity drift
34scored scenarios
CaptureReplayAuthorizationGraphQLWebSocketsEvidence
01 / COURSES

Start with a question.
Finish with proof.

Focused programmes turn complex security work into a deliberate sequence of understanding, practice, evidence, and independent judgment.

01Flagship path

WSHawk Practitioner

Build a reliable WSHawk workflow from project setup and identity capture through HTTP, GraphQL, and WebSocket replay.

  • Capture & replay
  • Identity recording
  • Object discovery
5 guided lessons · 5 guided labsExplore course
02Core security

Authorization by Design

Use matrices, explicit policies, semantic comparison, bounded object mutation, and safe writes to prove authorization failures.

  • IDOR / BOLA
  • BFLA
  • Tenant isolation
5 guided lessons · 5 guided labsExplore course
03Realtime systems

WebSocket Fieldwork

Test connection identity, rooms, subscriptions, event replay, and race behavior in stateful realtime systems.

  • Handshake auth
  • Rooms
  • Subscriptions
4 guided lessons · 4 guided labsExplore course
04Professional practice

Evidence That Holds Up

Turn technical behavior into protected, reproducible findings with semantic analysis, lifecycle management, export, and retesting.

  • Semantic analysis
  • Findings
  • Redaction
5 guided lessons · 5 guided labsExplore course
05Scanner practice

Injection & Browser Testing

Exercise every WSHawk injection family against paired secure and vulnerable controls, verify browser execution, and tune scanner confidence.

  • SQLi and NoSQLi
  • XSS and Playwright
  • XXE and SSRF
7 guided lessons · 7 guided labsExplore course
06Web modules

Recon & Web Assessment

Use WSHawk's crawler, directory, HTTP, headers, TLS, CORS, CSRF, WAF, sensitive-data, and chaining modules as one scoped workflow.

  • Crawl and directory
  • Headers, CORS and TLS
  • CSRF and WAF
6 guided lessons · 6 guided labsExplore course
07Realtime depth

WebSocket Engineering

Go beyond room checks into connection controls, interception, scanners, binary protocols, session security, subscriptions, and recovery behavior.

  • Handshake controls
  • Interceptor and replay
  • Binary analysis
6 guided lessons · 6 guided labsExplore course
08Operations

Projects, Evidence & Integrations

Manage durable projects, browser identities, flows, findings, protected evidence, reports, integrity, external systems, and certificates.

  • Project storage
  • Browser evidence
  • Reports and SARIF
6 guided lessons · 6 guided labsExplore course
09Tooling breadth

Interfaces & Defensive Validation

Choose the right WSHawk interface and use the defensive validator for egress, automation, and cross-site WebSocket controls.

  • CLI and dashboard
  • Classic and Go desktop
  • Python API and Docker
5 guided lessons · 5 guided labsExplore course
02 / THE METHOD

No passive watching.
Every lesson moves.

Learn the idea, operate the tool, work the controlled target, then explain what the evidence proves.

01

Understand the system

Short, precise lessons explain the protocol, trust boundary, and failure mode before a tool is opened.

02

Work the lab

Controlled targets let you capture traffic, form a hypothesis, and safely exercise the behavior yourself.

03

Build the proof

Save the requests, identities, responses, hashes, and reasoning needed to make a defensible finding.

04

Prove mastery

Scenario-based assessments check judgment and repeatability—not whether you memorized a button sequence.

03 / LAB SPOTLIGHT
Controlled environment

Authorization is behavior.
Map all of it.

Compare anonymous, user, owner, and administrator behavior against the same object. Learn when a difference is expected—and when identical access proves a vulnerability.

  • 01 Record multiple authenticated identities
  • 02 Discover bounded object candidates
  • 03 Compare semantic response behavior
  • 04 Save reproducible evidence and retest
Practice this matrix
LAB / AUTHZ-07Resource access matrix
Running
GET/resource/tenant-b/document-204200
Identity
Status
Behavior
Signal
AAnonymousNo session
401
Authentication required
Expected
UUser AForeign tenant
200
Owner document returned
High drift
OUser BResource owner
200
Owner document returned
Expected
RAdministratorPrivileged
200
Owner document returned
Expected
!
Potential horizontal BOLAForeign identity received owner-equivalent data.
92% confidence
04 / LEARNING PATHS

Go from curious
to capable.

Choose a stage, follow the sequence, and move forward when you can reproduce the outcome—not merely describe it.

05 / OUTCOMES

Leave with a workflow,
not a playlist.

By the end of a path, you should be able to approach an unfamiliar target, choose the right test, control risk, and produce evidence another professional can repeat.

01Model identity, state, and trust boundaries
02Operate WSHawk across HTTP, GraphQL, and WebSocket flows
03Separate expected access differences from real authorization failures
04Produce sanitized, reproducible, retestable findings
LEARN THE TOOL. UNDERSTAND THE SYSTEM.

Built around tools shipped by Rot Hackers.

THE WORK STARTS HERE

Don't just learn
what to click.

Learn what the system is doing, why the behavior matters, and how to prove it.

Explore the academy