Competitive matrix

Burp depth. Caido speed. Interceptor local-first control.

Interceptor is positioned as a complete desktop testing proxy: the core workflows security testers expect from Burp Suite and Caido, plus API surface modeling, protocol diagnostics, evidence workflow, ergonomic request/response review, local or self-hosted OAST options, packet capture, and privacy controls built in.

Burp Suite

Deep legacy toolkit

Strong proxy, scanner, Attacker, Collaborator, extensions, and enterprise workflow coverage.

Caido

Modern collaboration UX

Fast browser-oriented workflow with Intercept, Replay, Automate, HTTPQL, Workflows, Assistant, Plugins, and Sitemap.

Feature-by-feature

One table. Three columns. Clear coverage.

Legend: Native Partial / via extension Not positioned Interceptor exclusive

Feature family Burp Suite Interceptor Caido
Proxy, Capture & Interception
HTTP/HTTPS proxy captureNativeNativeNative
HTTP history with advanced filteringNativeNative + HTTPQL-style searchNative + HTTPQL
Request and response interceptionNativeNative + auditable editsNative
Raw message editingNativeNativeNative
Match-and-replace rulesNativeNative + audit trailNative
WebSocket interception and historyNativeNativePartial / workflow dependent
TLS MITM controlsNativeOpt-in, scoped, auditableNative
Customizable filter chips and advanced filtersNative filtersThemeable chips + full-width advanced filtersHTTPQL filters
Manual CA export / rotation / deletionNativeNative, never auto-installedNative
Per-host mTLS client certificatesNativeNativePartial
Replay, Fuzzing & Automation
Request/response review searchNative searchRegex, case mode, match counts, auto-scrollNative search
Syntax highlighting, line numbers, invisible charsEditor-dependentNative theme-aware review UIEditor-dependent
Switchable request/response layoutTool-specific panesTop, side-by-side, or tabbedTool-specific panes
Manual replay workspaceRepeaterRepeater + saved attemptsReplay
Attack/fuzz runnerAttackerAttacker + scope guardAutomate
Payload setsNativeNativeNative
Grep match and extractionNativeNativeNative
Session macros / auth replay supportNativeNative + site auth rulesWorkflows
Visual workflow automationExtensions / BAppsScriptable rulesWorkflows
Decoder utilitiesDecoderDecoderConvert
Comparer / diff toolingComparerComparer + diff timelineManual comparison
GraphQL-focused workspaceExtensions / scanner checksNativeReplay workflows
Scanning, Findings & OAST
Passive scannerNativeNativeFindings
Active scannerNative45+ opt-in checks, scope-aware, gated intrusive modeAutomate / workflows
Issue lifecycle and review stateNativeNativeNative
OAST / blind callback testingCollaboratorLocal HTTP + DNS collaborator, self-hosted optionPlugin / external workflow
Custom passive rulesBChecks / extensionsScriptable rulesPlugins / workflows
Authorization matrixExtension ecosystemNativeManual workflow
Storage, Search & Project Workflow
Project sitemapTarget / sitemapNativeSitemap
Full-text local history searchNativeSQLite FTS + filtersHTTPQL
Body spool / large payload handlingNativeNative local body spoolNative storage
Project import/exportNativeNative project/session exportNative
Inferred API surface modelExtensions / Enterprise APIsNormalized routes + evidence countsSitemap / workflows
Endpoint checklist generationManual / extensionsAuthz, input, cache, replay, negative casesManual workflow
API model session diffProject comparison workflowsEndpoint, status, auth, field changesManual workflow
Evidence boardReporting workflowNative evidence boardManual notes / plugins
Project health dashboardDashboard / enterprise viewsNativeWorkspace metadata
Privacy redaction before storage/displaySettings / extensionsNative redaction rulesProject controls
Reporting, Export & Collaboration
Built-in report editorReportingNative report editorExport-centric
Findings export: JSON / Markdown / HTMLNative formatsNativeNative / API
Send To without focus theftWorkflow-dependentGreen updated-tab badgesWorkflow-dependent
HAR and raw request/response exportsNativeNativeNative
Multi-user collaborationEnterpriseLocal project handoffCloud / team workspace
AI assistantIntegrations varyRoadmap / local-first stanceAssistant
Extensibility, Protocols & Diagnostics
Extension/plugin ecosystemBApp Store / APIPlugins + scriptable rulesPlugins SDK
Command palette / fast navigationKeyboard shortcutsTools menu command paletteModern command UX
Configurable workspace tab navigationFixed tool layoutLeft, top, right, or compact switcherFixed sidebar workflow
Network connection inspectorEvent/log viewsNative TCP/DNS/TLS timelineRequest-level views
Packet capture / PCAP evidenceExternal toolsNative PCAP/PCAPNG workflowNot positioned
HTTP/2, h2c, HTTP/3, QPACK, MASQUE, WebTransport handlingProtocol support variesNative codecs, replay paths, validation, and RFC mapHTTP testing focus
ECH / HTTPS-SVCB / Alt-Svc diagnosticsTLS detailsNative diagnosticsNot positioned
Strict authorized-testing boundariesPolicy / tooling controlsOpt-in MITM, local OAST, scope gatesScope controls

Interceptor-only angle

What Interceptor adds beyond a merged Burp + Caido workflow.

These are not just checkbox equivalents. They are product boundaries and workflow choices designed for controlled, authorized testing environments.

01

Local-only OAST

Callback handling is loopback-scoped and opt-in, so blind testing stays under explicit operator control.

02

Network diagnostics

DNS timing, TCP connects, upstream proxy chaining, TLS handshake metadata, byte counters, and close reasons sit next to HTTP evidence.

03

Packet capture evidence

Proxy-mirror records, optional native PCAP capture, PCAPNG output, and rotating disk capture support network-level investigation.

04

Evidence-first workflow

Evidence board, report editor, findings lifecycle, raw exports, and project health views keep assessment output connected to captured traffic.

05

Modern protocol awareness

HTTP/2 direct proxy, h2c replay, HTTP/3, QPACK, MASQUE, WebTransport, ECH, HTTPS/SVCB, Alt-Svc, and RFC coverage are surfaced as first-class diagnostic context.

06

Review ergonomics

Search bars, syntax highlighting, invisible-character display, line numbers, safe HTML rendering, History placement, persisted splitters, layout switching, and Send To badges reduce context loss.

07

Safety defaults

TLS MITM is opt-in, CA trust is never installed automatically, active tooling is scope-aware, and proxy-side edits are auditable.

Methodology

Based on public product documentation.

This matrix is a marketing comparison of feature families, not a legal certification of parity. Burp and Caido capabilities are summarized from publicly documented product pages and docs; Interceptor capabilities are taken from the local feature map and product scope.

Want Burp + Caido coverage without losing local control?

Interceptor is built for testers who want full capture, replay, scanning, evidence, diagnostics, and reporting in one local-first desktop workspace.

Download