Classic Desktop v4 Guide
The established Electron + Python desktop for projects, replay, AuthZ diffing, race testing, browser pairing, and web pentest work.
Classic Desktop v4 Guide
Classic WSHawk Desktop wraps the local Python project services in an Electron shell and keeps traffic, identities, notes, findings, and exports inside one project-backed workflow.
Download it from the WSHawk v4.0.4 release.
For the bridge-free private Go worker, authorization matrices, protected evidence, findings, and retesting, read the Electron + Go Desktop guide.
Main Areas
- overview and scanner views
- advanced tools for replay, interceptor, payload work, and evidence
- web pentest workspace for HTTP discovery and attack tooling
Typical Workflow
- create a project
- connect or import target context
- pair the browser companion if needed
- capture traffic
- replay or compare actions
- run race tests where state changes matter
- review findings and notes in the same project
- export an evidence bundle
What the Desktop Is Best At
- stateful WebSocket operations
- mixed HTTP plus WebSocket targets
- cross-identity comparison
- browser-authenticated workflows
- evidence review before handoff
Browser Companion
The browser companion is for scoped handshake capture and browser-authenticated flows. In the current release it uses pairing and scoped capture rather than a long-lived extension bridge token.
Smoke Check
cd desktop
npm run smoke