Detect WebSocket endpoints, check encryption (WSS vs WS), origin validation, CSWSH vulnerabilities, and identify real-time libraries.