Authorized web security testing
Interceptor
Interceptor is a desktop HTTP/HTTPS proxy for security testers, developers, and auditors who need controlled traffic capture, opt-in TLS interception, API surface modeling, HTTP/2 and HTTP/3 replay, hardened QPACK/MASQUE/WebTransport handling, ergonomic review tools, and evidence-ready reporting without sending project data to a cloud service.
Interceptor desktop workspace
A local-first HTTP and HTTPS testing proxy for capture, replay, diagnostics, findings, and reporting.
Major categories
A complete manual testing loop.
Interceptor combines capture, low-level diagnostics, inferred API modeling, replay, scanning, project organization, and reporting so a test can move from first request to final evidence without losing context.
Proxy & Capture
Capture HTTP and HTTPS traffic, handle CONNECT, keep upstream behavior visible, and control TLS interception explicitly.
Intercept & Edit
Pause requests or responses, edit raw messages, forward or drop, and keep user-visible modifications auditable.
Replay & Fuzz
Replay HTTP/1.1, HTTPS, HTTP/2, and h2c traffic, compare variants, track outcomes, and keep active work inside defined scope.
Storage & Search
Persist exchanges locally, search full text, spool large bodies, annotate traffic, and preserve project sessions.
Scanning & Findings
Generate passive findings and run a scope-gated active scanner with dozens of opt-in checks, OAST correlation, a gated intrusive mode, lifecycle state, and issues linked to evidence.
Project Workflow
Use project health, target scope, checklists, evidence boards, and reports to keep engagements organized.
Network Diagnostics
Inspect DNS, TCP, upstream proxy, TLS handshake, byte counters, close reasons, and chaining behavior.
Safety & Extensibility
Keep TLS MITM opt-in, CA handling manual, active tooling scope-aware, and extensions explicit.
Modern Protocols
Validate HTTP/3 frames, QPACK fields, MASQUE CONNECT-UDP, WebTransport, ECH, HTTPS/SVCB, Alt-Svc, and RFC coverage from one reference page.
Auto API Model
Infer normalized API routes from history, review request/response shape evidence, generate endpoint test checklists, diff model baselines, and launch safe workflows from modeled endpoints.
Review UI
Search, render, highlight, and line-number content in unified themed lists with zebra striping and scroll-stable live updates, rearrange request/response and History panels, switch themes, and persist project layouts.
Product boundary
Built for authorized environments.
TLS interception is opt-in. CA trust is never installed automatically. Active tooling is scope-aware. The product is intended for authorized security testing, application debugging, and internal traffic analysis.
View the full feature listStart with traffic. Finish with evidence.
Use Interceptor to understand behavior, test hypotheses, compare variants, and produce a clean record of what was observed.
See pricing