Build the mental model
Scope, traffic, requests, state, identity, capture, replay, and controlled object discovery.
ROT HACKERSACADEMYStart learning 9 practical programmes, 49 guided lessons, and one controlled lab. Start with setup or jump directly to the workflow you need.
Build a reliable WSHawk workflow from project setup and identity capture through HTTP, GraphQL, and WebSocket replay.
Use matrices, explicit policies, semantic comparison, bounded object mutation, and safe writes to prove authorization failures.
Test connection identity, rooms, subscriptions, event replay, and race behavior in stateful realtime systems.
Turn technical behavior into protected, reproducible findings with semantic analysis, lifecycle management, export, and retesting.
Exercise every WSHawk injection family against paired secure and vulnerable controls, verify browser execution, and tune scanner confidence.
Use WSHawk's crawler, directory, HTTP, headers, TLS, CORS, CSRF, WAF, sensitive-data, and chaining modules as one scoped workflow.
Go beyond room checks into connection controls, interception, scanners, binary protocols, session security, subscriptions, and recovery behavior.
Manage durable projects, browser identities, flows, findings, protected evidence, reports, integrity, external systems, and certificates.
Choose the right WSHawk interface and use the defensive validator for egress, automation, and cross-site WebSocket controls.
Scope, traffic, requests, state, identity, capture, replay, and controlled object discovery.
Authorization matrices, GraphQL, realtime systems, safe mutation, races, and false-positive control.
Protected evidence, lifecycle management, reproducible reporting, and automated retesting.
Injection families, browser verification, crawling, discovery, TLS, CORS, CSRF, and controlled attack chains.
Handshake controls, interception, payload evolution, binary protocols, subscriptions, sessions, and recovery.
Project durability, browser evidence, protected storage, reporting, integrations, interfaces, and defensive validation.
The downloadable lab pairs secure controls with intentional web, GraphQL, WebSocket, authorization, browser, OAST, and race behaviors. Public DNS, WHOIS, subdomain, port, and TLS lessons explain their separate authorized-target requirements instead of fabricating internet results.