Full feature map

180+ features across the complete manual testing workflow.

Use the search field to filter proxy, TLS, HTTP/2, h2c, HTTP/3, QPACK, MASQUE, WebTransport, Auto API Model, replay, active and passive scanning, OAST, reporting, project workflow, UI layout, themes, and low-level diagnostic capabilities.

Category 01

Proxy & Traffic Capture

11 features

Local HTTP/HTTPS proxy listener

Run a local proxy endpoint for browser, application, and tool traffic capture.

HTTP/1.1 keep-alive client connections

Handle persistent client-side HTTP sessions during capture.

Persistent upstream connections

Reuse upstream connections where possible for realistic proxy behavior.

HTTP CONNECT pass-through

Support CONNECT tunneling when TLS interception is not enabled.

Opt-in TLS MITM

Enable HTTPS inspection explicitly instead of silently intercepting encrypted traffic.

Per-host MITM scope and bypass rules

Choose which hosts should be intercepted and which should remain pass-through.

TLS version min/max controls

Constrain TLS behavior for testing compatibility and handshake policy.

Upstream TLS verification controls

Inspect or relax upstream certificate validation only when explicitly configured.

mTLS per-host client certificates

Attach client certificates to selected upstream hosts for mutual TLS environments.

Certificate pinning bypass switch

Expose an explicit Bypass SSL Pinning control beside TLS and proxy controls, with warning text and persisted audit intent for authorized lab work.

Pinning bypass diagnostics marker

Mark captures and diagnostics when SSL pinning bypass intent is enabled so reviewers can see the test boundary clearly.

Category 02

Low-Level Network Diagnostics

16 features

Connection Inspector

Review connection-level events for proxy troubleshooting and network analysis.

TCP accept timeline

Track when a client connection is accepted and how it progresses.

DNS resolution timings and errors

Record resolution attempts, durations, and failure details.

Upstream TCP connect timings

Measure upstream connection establishment for each target.

Upstream proxy chaining visibility

See whether traffic is routed directly or through a corporate proxy chain.

TLS handshake diagnostics

Surface SNI, ALPN, negotiated version, cipher, and handshake result details.

Byte counters and close reasons

Track bytes read and written with connection shutdown causes.

Packet Capture panel

Inspect low-level capture sessions from a dedicated network diagnostics workspace.

Proxy-mirror packet records

Synthesize packet records from proxy traffic when raw interface capture is unavailable or unnecessary.

Network interface selector

Select capture interfaces by system name, address, and loopback visibility.

Live PCAP capture

Record packet-level activity when libpcap support is available on the workstation.

PCAP evidence export

Write packet capture sessions for external analysis and evidence preservation.

PCAPNG and rotating capture files

Write packet evidence as PCAP or PCAPNG with configurable disk rotation.

ECH / Encrypted ClientHello diagnostics

Detect ECH in the outer ClientHello and record visibility limits without bypassing encryption.

HTTPS/SVCB and Alt-Svc h3 awareness

Record when a domain advertises HTTP/3 through DNS HTTPS records or Alt-Svc response headers.

RFC coverage reference

Open a dedicated protocol standards page from the app or website to review supported RFC areas.

Category 03

Intercept & Modification

7 features

Request intercept queue

Pause selected requests before they reach the target.

Response intercept queue

Inspect and modify selected responses before they return to the client.

Raw request editing

Edit headers and body bytes directly during intercept.

Raw response editing

Modify server responses for debugging and authorized test cases.

Forward, drop, and forward-all actions

Control each intercepted message or temporarily release the queue.

Match-and-replace rules

Apply configured request or response transformations during proxy flow.

Audit log for edits and transformations

Persist visible modification history for accountability and reporting.

Category 04

History, Storage & Search

10 features

SQLite project history

Store captured exchanges in a local project database.

Async write queue

Keep proxy capture responsive while persistence happens in the background.

Full-text search

Search requests, responses, metadata, and stored evidence quickly.

Large body spool

Store larger payloads outside the main database file when needed.

Raw and normalized body storage

Retain original bytes and decoded representations for analysis.

Truncation and observed-size metadata

Preserve payload size facts even when body storage is capped.

Configurable storage limits

Set body capture, database size, and retention limits per project.

Annotations, highlights, and issue markers

Attach investigator context directly to captured traffic.

Retention policies

Control how long project history and body data are kept.

Project import and export

Move sessions between machines or archive assessment work.

Category 05

Manual Testing Tools

16 features

Repeater tabs

Send captured or edited requests into organized manual replay tabs.

HTTP/2 Repeater over TLS and h2c

Replay edited HTTP/2 requests over HTTPS with ALPN h2 or cleartext h2c when the target supports it.

HTTP/2 direct proxy coverage

Handle direct HTTP/2 proxy flows, interleaved request bodies, trailers, stream resets, GOAWAY, and safe frame serialization.

Non-http scheme replay handling

Reject or route unsupported replay schemes explicitly instead of silently treating them as ordinary HTTP traffic.

Extended CONNECT WebSocket editing

Edit HTTP/2 and HTTP/3 Extended CONNECT WebSocket handshakes with stricter scheme, path, and protocol validation.

Saved replay results

Persist response outcomes for later comparison and reporting.

Request diff timeline

Track request and response variants with status, size, duration, and findings.

Session macros for replay

Reuse configured session handling behavior while replaying requests.

Site auth token injection

Inject configured authentication headers during Repeater runs for selected targets.

Attacker

Exercise parameters and payload positions under explicit tester control.

Payload sets

Manage reusable inputs for manual and semi-automated tests.

Grep match and extract

Identify response markers and extract values during replay or fuzzing.

Decoder utilities

Decode, transform, and inspect common web payload encodings.

Comparer

Compare requests and responses to isolate behavioral differences.

GraphQL testing workspace

Send captured or replayed requests into a dedicated GraphQL analysis workspace.

WebSocket replay and intercept

Capture and inspect WebSocket frames alongside HTTP traffic.

Category 06

Scanning & Findings

18 features

Passive scanner

Generate findings from observed traffic without sending extra requests.

Header, cookie, CORS, cache, and TLS observations

Surface common configuration issues from captured responses.

JWT, secret, and sensitive keyword analysis

Flag tokens and exposed sensitive material in traffic.

Opt-in active scan engine

Scope-gated engine that generates probes from in-scope history and paces them through global and per-host rate and concurrency limits — only when you start it.

Injection detection suite

Observation checks for SQL (error, boolean, and time-based), OS command, SSTI, XXE, CRLF, LDAP, XPath, NoSQL, deserialization, expression-language/OGNL, and server-side includes.

Out-of-band (OAST) checks

Plant tokens for SSRF, blind SQLi, Log4Shell, and XXE and confirm them through a loopback HTTP collaborator and a DNS collaborator, correlated into findings.

Access-control differential checks

Compare against a baseline to flag JWT signature bypass, IDOR, mass assignment, and user enumeration.

Disclosure and misconfiguration checks

GraphQL introspection, secret exposure, sensitive path and directory-listing discovery, verbose-error disclosure, host-header injection, active CORS and over-permissive preflight, open redirect, HTTP TRACE/XST, risky HTTP methods, HTTP parameter pollution, prototype pollution, and web cache deception.

Gated intrusive/destructive checks

An explicit opt-in and warning unlock ReDoS, unauthenticated PUT writes, malformed-input fault injection, XML entity-expansion DoS, path-traversal secret-file reads, and XXE out-of-band file exfiltration.

Missing authorization checks

Compare paired requests to identify authorization gaps under tester-provided conditions.

Local OAST callback support

Run loopback-only HTTP and DNS callback collection for authorized blind testing workflows.

Scope-limited active checks

Apply active tooling only to allowed targets.

Rate and concurrency controls

Throttle active testing to match engagement constraints, globally and per host.

Findings lifecycle

Track status and review state for identified issues.

Authorization matrix

Organize access-control hypotheses and test results by role or account.

Category 07

Project Workflow & Reporting

11 features

Target scope rules

Define which hosts and URLs are in scope for active work.

Target sitemap

Build a navigable map of observed application paths.

Pinned workspace and testing checklist

Keep objectives, endpoints, notes, statuses, and related evidence together.

Evidence Board

Collect requests, findings, notes, and report references in one investigation board.

Report editor

Draft assessment output from findings and stored evidence.

Findings exports

Export issue data to JSON, Markdown, or HTML formats.

HAR export

Share selected traffic using the standard HTTP Archive format.

Raw request and response export

Save exact traffic artifacts for reproduction or evidence packages.

Session JSON export and import

Move structured project data between environments.

Project health dashboard

Monitor feature coverage, setup status, and workflow readiness.

API Surface evidence handoff

Add representative modeled endpoint evidence to reports, Repeater, Regression, or Auth Matrix without losing source exchange links.

Category 08

Auto API Model & API Surface

12 features

Normalized API route inference

Infer endpoint models from captured history, for example /api/users/123 becomes /api/users/{id}.

API Surface view

Browse modeled endpoints with host, route, methods, statuses, auth evidence, query parameters, JSON fields, source counts, and WebSocket hints.

Observed shape evidence

Surface request and response content types, path placeholders, query names, and JSON field names as captured evidence rather than authoritative schemas.

Authentication and role hints

Highlight Authorization, Cookie, API key, Set-Cookie, WWW-Authenticate, role, profile, permission, scope, claim, and group evidence observed in traffic.

Linked source exchanges

Keep every inferred endpoint connected to the captured exchanges that produced it, with one-click evidence opening.

Per-endpoint checklist generation

Create Workspace items for authz comparison, input validation, cache behavior, sensitive data exposure, replay coverage, and negative cases.

Safe endpoint workflow actions

Send representative endpoint requests to Repeater, Regression, Auth Matrix, Report, or linked evidence from the modeled endpoint view.

API model diff baselines

Capture a baseline and compare the current model for new endpoints, removed endpoints, changed statuses, new fields, auth evidence changes, and sensitive-looking fields.

Model confidence and evidence counts

Show low/medium/high confidence and evidence counts so inferred shapes are treated as traffic-backed hints.

WebSocket route evidence

Carry WebSocket upgrade observations into the API model so HTTP and WebSocket entry points can be reviewed together.

Imported spec requests as drafts

Keep imported OpenAPI and Postman requests in history so captured and imported API work can share workflow tooling.

Scope-aware modeled workflow

Use the same central Send To tooling and scope-aware active boundaries when moving from model evidence to testing actions.

Category 09

Platform, Safety & Extensibility

13 features

Local-first storage

Keep captured data and project artifacts on the tester machine.

Manual CA export, rotation, and deletion

Control certificate authority material without automatic trust installation.

Upstream proxy authentication support

Work in corporate network environments that require proxy credentials.

Client certificate rules

Attach certificates to selected hosts for mTLS testing.

Redaction rules

Reduce sensitive data exposure in persisted artifacts and UI views.

Custom privacy redaction

Redact cookies, authorization headers, API keys, tokens, and project-specific regex matches.

Plugin manifest loading

Register extension metadata and capabilities explicitly.

Plugin sandbox policy

Keep extension behavior constrained and inspectable.

Scriptable passive rules and transformations

Extend analysis and request handling for project-specific workflows.

Command palette in Tools menu

Access frequent actions quickly from the Tools menu without crowding the main interface.

Window state restoration

Restore the main window position and state when the desktop app starts.

Always-on-top window mode

Keep Interceptor visible above other tools during focused testing sessions.

Linux AppImage packaging

Distribute Linux builds as AppImage artifacts with checksum support.

Category 10

Modern Protocols & RFC Coverage

22 features

HTTP/2 advanced codec coverage

Parse frames, streams, SETTINGS, flow-control signals, priorities, and HTTP/2 client-side MITM traffic.

HPACK for HTTP/2

Handle HTTP/2 header compression and decompression for captured and bridged traffic.

Modern HTTP priorities

Recognize RFC 9218 Priority headers and HTTP/2 reprioritization signals.

WebSocket over HTTP/2

Support Extended CONNECT WebSocket bootstrapping over HTTP/2.

HTTP/3 protocol primitives

Parse and safely serialize HTTP/3 frames and SETTINGS with QUIC varint bounds, reserved identifier checks, and strict boolean setting validation.

Hardened QPACK codec

Represent HTTP/3 fields with QPACK, including Huffman string literals, dynamic table references, dynamic indexed field lines, literal name references, and strict pseudo-header validation.

Safe QPACK header serialization

Reject invalid field names, unknown pseudo-headers, duplicate pseudo-headers, bad ordering, oversized integers, and truncated string literals before emitting or accepting field sections.

Safe HTTP/2 frame serialization

Serialize GOAWAY, RST_STREAM, DATA, HEADERS, WINDOW_UPDATE, and error frames with stream-state and size checks before bytes are forwarded.

HTTP/2 request trailer forwarding

Preserve intercepted request trailers and forward them upstream when HTTP/2 direct proxy traffic is bridged to upstream services.

Strict HTTP/3 SETTINGS validation

Reject reserved identifiers, duplicate settings, invalid boolean values, truncated values, and malformed varints before a connection is trusted.

QPACK dynamic reference validation

Validate dynamic indexed field lines and dynamic literal name references against encoder stream state before decoding or replaying header blocks.

WebSocket over HTTP/3

Recognize HTTP/3 Extended CONNECT WebSocket semantics and require CONNECT, :protocol websocket, :scheme https, absolute :path, and :authority.

HTTP Datagrams and Capsule Protocol

Parse and safely serialize HTTP datagram capsules with QUIC varint validation, payload bounds checks, and truncated capsule rejection.

CONNECT-UDP / MASQUE primitives

Recognize CONNECT-UDP requests, validate HTTPS schemes and MASQUE well-known targets, parse IPv6 zone identifiers, and harden datagram context IDs.

MASQUE target validation

Validate URI-template targets, IPv6 scoped literals, host and port authority forms, and datagram context IDs before CONNECT-UDP state is accepted.

WebTransport over HTTP/3 primitives

Handle session request fields, streams, datagrams, close/drain capsules, SETTINGS dependencies, initial limits, absolute paths, and truncated stream varints.

WebTransport bounds validation

Check stream identifiers, capsule payloads, close codes, drain signals, and session limits before WebTransport traffic reaches replay or inspection views.

ECH / Encrypted ClientHello awareness

Detect ECH and clearly report that inner ClientHello decryption requires the service key.

DNS HTTPS/SVCB awareness

Inspect HTTPS resource records for ALPN, ECH, target, and HTTP/3 advertisements when resolver support exists.

Alt-Svc HTTP/3 diagnostics

Flag response headers advertising h3 or h3-* alternatives.

In-app RFC reference page

Access the standards coverage page from Help > RFC.

Website RFC reference

Review the same standards map publicly from the site navigation.

Category 11

Review UI & Navigation

28 features

Request/response search bars

Search inside request and response viewers with case-sensitive mode, regex mode, previous/next navigation, and match counts.

Auto-scroll to search matches

Jump directly to matching content when search text or search options change.

HTTP syntax highlighting

Separate fields, values, punctuation, nested key/value pairs, cookies, and structured values with theme-aware colors.

Line-number gutters

Show compact line numbers beside request and response content with dynamic width, kept precisely aligned with the text's line positions all the way to the bottom.

Invisible-character display

Reveal newlines, tabs, spaces, carriage returns, and control bytes as fixed-width visible tokens.

HTML response Render tab

Render captured HTML responses in a dedicated safe viewer tab for faster visual inspection.

Switchable request/response layouts

Choose stacked, side-by-side, or tabbed request/response views, persist the choice in the project, and restore splitter positions.

Movable History panel

Place History on the left, right, or top of the request/response workspace, with Selected request details moving beside it when the top layout is active.

History query numbering

Show captured query numbers as the first History column and size timestamp and method columns so their full values remain visible.

Project-persisted workspace layout

Save request/response arrangement, History placement, and splitter positions in the project so reopened ITP sessions restore the same workspace.

Compact History typography

Use a smaller History list font so dense captures remain readable without forcing constant horizontal or vertical scrolling.

Configurable main tab bar position

Move the main workspace tab bar to the left, top, or right from the View menu to fit wide monitors, vertical layouts, or personal workflow preferences.

Current-tab switcher dropdown

Display the active workspace name and open a compact dropdown of the other visible tabs for quick switching without scanning the full tab strip.

Compact tab switcher mode

Hide the full tab bar and keep only the current-tab switcher in the top toolbar before the proxy controls when screen space matters.

Send To without focus theft

Send content to tools while staying in the current workspace; updated destination tabs get a visible notification badge.

Themeable History filter chips

Customize History filter colors through themes and refresh them immediately when the theme changes.

Wide Advanced Filter panel

Use a full-width advanced filter panel that keeps controls readable with at most two settings per row.

Editor cut/copy/paste menus

Use standard cut, copy, and paste actions from request and response context menus.

Theme-defined editor colors

Control syntax highlighting, filter state colors, high-contrast palettes, and colorblind-friendly theme choices across all bundled themes.

Ubuntu high-contrast theme pack

Switch between three Ubuntu-inspired high-contrast themes designed for stronger foreground, border, and state separation.

Colorblind-friendly theme

Use an accessible palette that avoids relying on red/green contrast alone for status, warnings, filters, and syntax accents.

Top layout detail positioning

When History is placed above the workspace, keep Selected request details on the right so request and response panels retain practical width.

Stable Repeater controls

Keep Send, Cancel, layout controls, replay options, HTTP/2 mode, and response panels stable without unwanted resizing.

Self-hosted OAST server option

Run a separate Python OAST server for controlled lab or remote callback infrastructure while keeping app integration explicit.

Unified themed list views

Every list — History, Connections, Packet Capture, queues, results, and more — shares one themed control with theme-derived zebra striping and centred column headers.

Scroll-stable live lists

Lists keep your scroll position while they rebuild, so incoming traffic no longer yanks the focused row back to the top of History or other live views.

Decoded Raw message view

The Raw request/response view strips chunked Transfer-Encoding framing so bodies read cleanly, while the Hex view still shows the exact on-the-wire bytes.

HTTPQL search Clear button

Clear the History query filter in one click with a button beside the HTTPQL search field.