Burp Suite
Deep legacy toolkit
Strong proxy, scanner, Attacker, Collaborator, extensions, and enterprise workflow coverage.
Competitive matrix
Interceptor is positioned as a complete desktop testing proxy: the core workflows security testers expect from Burp Suite and Caido, plus API surface modeling, protocol diagnostics, evidence workflow, ergonomic request/response review, local or self-hosted OAST options, packet capture, and privacy controls built in.
Burp Suite
Strong proxy, scanner, Attacker, Collaborator, extensions, and enterprise workflow coverage.
Interceptor
Combines capture, API modeling, replay, active/passive analysis, diagnostics, reports, evidence, packet capture, hardened HTTP/2 and HTTP/3 protocol handling, request/response review ergonomics, and strict local control.
Caido
Fast browser-oriented workflow with Intercept, Replay, Automate, HTTPQL, Workflows, Assistant, Plugins, and Sitemap.
Feature-by-feature
Legend: Native Partial / via extension Not positioned Interceptor exclusive
| Feature family | Burp Suite | Interceptor | Caido |
|---|---|---|---|
| Proxy, Capture & Interception | |||
| HTTP/HTTPS proxy capture | Native | Native | Native |
| HTTP history with advanced filtering | Native | Native + HTTPQL-style search | Native + HTTPQL |
| Request and response interception | Native | Native + auditable edits | Native |
| Raw message editing | Native | Native | Native |
| Match-and-replace rules | Native | Native + audit trail | Native |
| WebSocket interception and history | Native | Native | Partial / workflow dependent |
| TLS MITM controls | Native | Opt-in, scoped, auditable | Native |
| Customizable filter chips and advanced filters | Native filters | Themeable chips + full-width advanced filters | HTTPQL filters |
| Manual CA export / rotation / deletion | Native | Native, never auto-installed | Native |
| Per-host mTLS client certificates | Native | Native | Partial |
| Replay, Fuzzing & Automation | |||
| Request/response review search | Native search | Regex, case mode, match counts, auto-scroll | Native search |
| Syntax highlighting, line numbers, invisible chars | Editor-dependent | Native theme-aware review UI | Editor-dependent |
| Switchable request/response layout | Tool-specific panes | Top, side-by-side, or tabbed | Tool-specific panes |
| Manual replay workspace | Repeater | Repeater + saved attempts | Replay |
| Attack/fuzz runner | Attacker | Attacker + scope guard | Automate |
| Payload sets | Native | Native | Native |
| Grep match and extraction | Native | Native | Native |
| Session macros / auth replay support | Native | Native + site auth rules | Workflows |
| Visual workflow automation | Extensions / BApps | Scriptable rules | Workflows |
| Decoder utilities | Decoder | Decoder | Convert |
| Comparer / diff tooling | Comparer | Comparer + diff timeline | Manual comparison |
| GraphQL-focused workspace | Extensions / scanner checks | Native | Replay workflows |
| Scanning, Findings & OAST | |||
| Passive scanner | Native | Native | Findings |
| Active scanner | Native | 45+ opt-in checks, scope-aware, gated intrusive mode | Automate / workflows |
| Issue lifecycle and review state | Native | Native | Native |
| OAST / blind callback testing | Collaborator | Local HTTP + DNS collaborator, self-hosted option | Plugin / external workflow |
| Custom passive rules | BChecks / extensions | Scriptable rules | Plugins / workflows |
| Authorization matrix | Extension ecosystem | Native | Manual workflow |
| Storage, Search & Project Workflow | |||
| Project sitemap | Target / sitemap | Native | Sitemap |
| Full-text local history search | Native | SQLite FTS + filters | HTTPQL |
| Body spool / large payload handling | Native | Native local body spool | Native storage |
| Project import/export | Native | Native project/session export | Native |
| Inferred API surface model | Extensions / Enterprise APIs | Normalized routes + evidence counts | Sitemap / workflows |
| Endpoint checklist generation | Manual / extensions | Authz, input, cache, replay, negative cases | Manual workflow |
| API model session diff | Project comparison workflows | Endpoint, status, auth, field changes | Manual workflow |
| Evidence board | Reporting workflow | Native evidence board | Manual notes / plugins |
| Project health dashboard | Dashboard / enterprise views | Native | Workspace metadata |
| Privacy redaction before storage/display | Settings / extensions | Native redaction rules | Project controls |
| Reporting, Export & Collaboration | |||
| Built-in report editor | Reporting | Native report editor | Export-centric |
| Findings export: JSON / Markdown / HTML | Native formats | Native | Native / API |
| Send To without focus theft | Workflow-dependent | Green updated-tab badges | Workflow-dependent |
| HAR and raw request/response exports | Native | Native | Native |
| Multi-user collaboration | Enterprise | Local project handoff | Cloud / team workspace |
| AI assistant | Integrations vary | Roadmap / local-first stance | Assistant |
| Extensibility, Protocols & Diagnostics | |||
| Extension/plugin ecosystem | BApp Store / API | Plugins + scriptable rules | Plugins SDK |
| Command palette / fast navigation | Keyboard shortcuts | Tools menu command palette | Modern command UX |
| Configurable workspace tab navigation | Fixed tool layout | Left, top, right, or compact switcher | Fixed sidebar workflow |
| Network connection inspector | Event/log views | Native TCP/DNS/TLS timeline | Request-level views |
| Packet capture / PCAP evidence | External tools | Native PCAP/PCAPNG workflow | Not positioned |
| HTTP/2, h2c, HTTP/3, QPACK, MASQUE, WebTransport handling | Protocol support varies | Native codecs, replay paths, validation, and RFC map | HTTP testing focus |
| ECH / HTTPS-SVCB / Alt-Svc diagnostics | TLS details | Native diagnostics | Not positioned |
| Strict authorized-testing boundaries | Policy / tooling controls | Opt-in MITM, local OAST, scope gates | Scope controls |
Interceptor-only angle
These are not just checkbox equivalents. They are product boundaries and workflow choices designed for controlled, authorized testing environments.
Callback handling is loopback-scoped and opt-in, so blind testing stays under explicit operator control.
DNS timing, TCP connects, upstream proxy chaining, TLS handshake metadata, byte counters, and close reasons sit next to HTTP evidence.
Proxy-mirror records, optional native PCAP capture, PCAPNG output, and rotating disk capture support network-level investigation.
Evidence board, report editor, findings lifecycle, raw exports, and project health views keep assessment output connected to captured traffic.
HTTP/2 direct proxy, h2c replay, HTTP/3, QPACK, MASQUE, WebTransport, ECH, HTTPS/SVCB, Alt-Svc, and RFC coverage are surfaced as first-class diagnostic context.
Search bars, syntax highlighting, invisible-character display, line numbers, safe HTML rendering, History placement, persisted splitters, layout switching, and Send To badges reduce context loss.
TLS MITM is opt-in, CA trust is never installed automatically, active tooling is scope-aware, and proxy-side edits are auditable.
Methodology
This matrix is a marketing comparison of feature families, not a legal certification of parity. Burp and Caido capabilities are summarized from publicly documented product pages and docs; Interceptor capabilities are taken from the local feature map and product scope.
Burp Suite Pro · Burp tools docs · Caido docs · Caido product site
Interceptor is built for testers who want full capture, replay, scanning, evidence, diagnostics, and reporting in one local-first desktop workspace.
Download