Recon & Web Assessment
Use WSHawk's crawler, directory, HTTP, headers, TLS, CORS, CSRF, WAF, sensitive-data, and chaining modules as one scoped workflow.
Do the work in order.
- 0160 min↗
Crawl, discover directories, and detect soft 404s
Combine links, scripts, robots, sitemaps, OpenAPI, and bounded path discovery into an endpoint map.
- 0260 min↗
Analyze headers, technology, WAF, and sensitive data
Interpret missing controls and exposed signatures without turning every informational signal into a vulnerability.
- 0355 min↗
Use DNS, WHOIS, subdomain, and port discovery responsibly
Understand the public recon modules, their scope requirements, and why a localhost lab cannot fabricate passive internet truth.
- 0460 min↗
Inspect TLS, CORS, and origin policy
Combine certificate inspection with browser-origin policy and secure WebSocket origin validation.
- 0560 min↗
Forge and verify CSRF requests
Build an authenticated cross-site request, compare token enforcement, and restore state.
- 0665 min↗
Forge, replay, and chain HTTP attacks
Use every HTTP method, templates, regex extraction, variable substitution, and bounded request flows.
