Build the mental model
Scope, traffic, requests, state, identity, capture, replay, and controlled object discovery.
ROT HACKERSACADEMY10 practical programmes, 56 guided lessons, and two controlled labs. Everything is free—start with setup or jump directly to the workflow you need.
Build a reliable WSHawk workflow from project setup and identity capture through HTTP, GraphQL, and WebSocket replay.
Use matrices, explicit policies, semantic comparison, bounded object mutation, and safe writes to prove authorization failures.
Test connection identity, rooms, subscriptions, event replay, and race behavior in stateful realtime systems.
Turn technical behavior into protected, reproducible findings with semantic analysis, lifecycle management, export, and retesting.
Exercise every WSHawk injection family against paired secure and vulnerable controls, verify browser execution, and tune scanner confidence.
Use WSHawk's crawler, directory, HTTP, headers, TLS, CORS, CSRF, WAF, sensitive-data, and chaining modules as one scoped workflow.
Go beyond room checks into connection controls, interception, scanners, binary protocols, session security, subscriptions, and recovery behavior.
Manage durable projects, browser identities, flows, findings, protected evidence, reports, integrity, external systems, and certificates.
Choose the right WSHawk interface and use the defensive validator for egress, automation, and cross-site WebSocket controls.
Learn Basilisk from a safe first preview through deterministic model-security testing, evidence review, evaluation, desktop operation, and CI automation.
Scope, traffic, requests, state, identity, capture, replay, and controlled object discovery.
Authorization matrices, GraphQL, realtime systems, safe mutation, races, and false-positive control.
Protected evidence, lifecycle management, reproducible reporting, and automated retesting.
Safe validation, prompt-injection probes, posture comparison, evaluation, sessions, reports, desktop workflows, and CI.
Injection families, browser verification, crawling, discovery, TLS, CORS, CSRF, and controlled attack chains.
Handshake controls, interception, payload evolution, binary protocols, subscriptions, sessions, and recovery.
Project durability, browser evidence, protected storage, reporting, integrations, interfaces, and defensive validation.
The WSHawk lab covers web, GraphQL, browser, WebSocket, authorization, injection, OAST, chaining, and race behavior. The Basilisk lab adds 46 deterministic AI-security ground-truth scenarios.