Skip to content
CatSuite

Language

Choose whether the site follows your browser or always uses Brazilian Portuguese or English.

Get it free

Version 1.5.0 · Extensions

Intercept. Test. Extend.

CatSuite brings an interceptor, HTTPS proxy, Repeater, Intruder and Discoverer into one Android lab — and now runs your own JavaScript extensions in an isolated sandbox with explicit permissions.

  • 100% free
  • PT-BR + EN
  • Data stays on device
  • SDK 1.4.0

Open the extension IDE

Google PlayFree · No subscription · No paywall

New in version 1.5.0

From lab to platform.

CatSuite’s biggest update opens the lab to your own code: JavaScript extensions, visual analysis workflows, a connector for command-line tools and a biometric vault to protect it all.

.catplug

JavaScript extensions

.catplug packages run by QuickJS inside an isolated Android service. Every extension gets its own storage, permissions and limits.

  • Hooks in the proxy, Repeater, Intruder and Discoverer
  • Native tabs, menus and commands
  • Findings with evidence and fingerprints
.catflow

Visual workflows

Connect steps in a graph — capture, JWT, secrets, authorization and report — with conditions, joins, history and replay.

Optional

CatBridge

A connector paired by numeric code that brings httpx, Katana, Schemathesis, Nuclei and the ecosystem tools into your workflows, with pinned TLS and signed messages.

Protection

Biometric vault

Classify extensions and workflows as PUBLIC, PROTECTED or SECRET. Private content stays encrypted with an Android Keystore key.

.catdata

Findings and backups

Export findings with optional evidence and sensitive data redacted, or create portable password-protected backups.

Coming soon

Cat AI

The analysis assistant is being rebuilt to return safer, faster and with full control over context.

What’s coming

Lab modules

Everything you use, in one app.

The same modules from the app menu, wired together: whatever you capture in the Interceptor moves to Repeater, Intruder, an extension or a workflow with one tap.

01

Interceptor

Pause, edit, decide.

Review every request and response before it is forwarded and keep history organized by domain.

Features

  • Request and response interception
  • History with filters, domains and comparison
  • Site Map by host and endpoint
  • HAR, JSON, TXT and cURL export
02

Browser

DevTools in your pocket.

A technical browser with the inspection tools you would use on a computer.

Features

  • Network monitor, page source and inspect element
  • DOM modifier and JWT/Base64 detection in storage
  • User-Agent, desktop mode and IP spoofing headers
  • CatEyes: page technologies and CVE signals
03

Network Proxy

Full traffic capture.

Bring the device’s HTTP and HTTPS traffic into the lab with its own certificate.

Features

  • MITM proxy with exportable CA certificate
  • Full Capture for HTTP and HTTPS
  • Replacement rules for requests, responses, headers and cookies
  • Response pausing for editing
04

Repeater

Resend with precision.

Edit raw requests, resend as often as you need and compare responses side by side.

Features

  • HTTP editor with syntax highlighting
  • Header autocomplete
  • Response comparison mode
  • SSL/TLS control per send
05

Intruder

Payloads under control.

Mark positions, pick wordlists and run tests at your own pace, with pause and resume.

Features

  • $CAT$ markers in the request
  • Imported wordlists and payload generators
  • Session pause and resume
  • Result trimming and filtering
06

Discoverer

Map the surface.

Find paths, parameters and endpoints on authorized targets with fine-grained pacing.

Features

  • Built-in directory and parameter lists
  • GET, POST, PUT and DELETE methods
  • Requests per second, delay and automatic 429 backoff
  • Status and size filters
07

Decoder

Understand any format.

Transform and interpret the formats that show up in traffic, with automatic detection.

Features

  • Auto-detection for JWT, Base64, URL, Hex, HTML Entities and Binary
  • Base64URL and Unicode
  • Generate and identify MD5, SHA-1, SHA-256 and SHA-512
08

SSL/TLS

Check the connection.

Certificate and secure connection triage without leaving the lab.

Features

  • Handshake and chain validation
  • Certificate fingerprints
  • TLS failure diagnostics
09

History

Context that sticks.

A session timeline and local notes so no evidence gets lost.

Features

  • Browser and request timeline
  • Notepad with export
  • Everything stored on the device
10

Extensions

Your code, inside the lab.

Extend the modules with JavaScript and turn routines into reproducible workflows.

Features

  • Hooks in the proxy and testing modules
  • Tabs, menus, commands and findings
  • Visual workflows and CatBridge

SDK 1.4.0 · API v1

Write extensions. In JavaScript.

A .catplug package bundles the manifest, code and resources with SHA-256 hashes. CatSuite validates everything before installing, starts the extension disabled and only unlocks the capabilities you approve.

  1. 01
    Create or import

    From the app, the web IDE or a template.

  2. 02
    Review permissions

    Destinations and capabilities are shown before enabling.

  3. 03
    Enable and run

    Hooks, commands and tabs come alive instantly.

  4. 04
    Record findings

    Evidence, severity and confidence in one place.

cat.proxy.onRequest(message => {
  if (cat.http.parseUrl(message.url).hostname !== 'api.aurora.test') return;
  message.headers.push({name: 'X-Cat-Lab', value: 'auditor'});
  return message;
});

cat.events.on('http.response', async message => {
  const cache = message.headers.find(h => h.name.toLowerCase() === 'cache-control');
  if (!cache || !cache.value.includes('public')) return;
  await cat.findings.add({
    fingerprint: 'cache-publico:' + cat.http.parseUrl(message.url).pathname,
    title: {'pt-BR': 'Resposta com cache público', en: 'Response with public cache'},
    description: {'pt-BR': 'Revise o Cache-Control desta resposta.', en: 'Review the Cache-Control of this response.'},
    severity: 'low',
    confidence: 'observed',
    url: message.url
  });
});
Tags laboratory requests and records a finding when a response allows public caching.

Capabilities declared in the manifest

  • traffic.readObserve traffic
  • traffic.modifyModify traffic
  • http.sendSend requests
  • external.callCall external APIs
  • ui.menuAdd menus
  • ui.tabCreate tabs
  • storageStore data
  • findingsRecord findings
  • repeaterOpen in Repeater
  • commandsRegister commands
  • pipeline.stepWorkflow steps
  • parsersContent parsers
  • connector.runRun connectors

API v1 limits

4
active extensions
32 MiB
per environment
100 ms
per mutation handler
2
concurrent HTTP calls
120 s
total HTTP timeout
32 KiB
editable preview

Visual workflows + CatBridge

Routines become workflows.

Drag blocks, connect outputs to compatible inputs and approve the workflow. Every run keeps duration, inputs, outputs, hashes and versions — and can be compared or replayed without new sends.

Drag the blocks. Tap Arrange to realign the workflow.

  1. httpCapture
  2. whenCondition
  3. true · jwtJWT
    false · secretSecrets
  4. joinJoin
  5. reportReport

Stable artifact types

  • http
  • endpoint
  • jwt
  • secret
  • analysis
  • finding
  • record
  • javascript
  • openapi

Included templates

  • Identity auditCapture → JWT → Secrets → Authorization → Report
  • API mapCrawler → JavaScript → Endpoints → OpenAPI → Report
  • BranchesCondition on Authorization, parallel branches and a join
  • API audithttpx → Katana → join → OpenAPI → Schemathesis

Optional connector

Command-line tools, on a leash.

CatBridge runs on your computer or server, pairs with a 24-digit code valid for two minutes and talks to the app over TLS with a pinned certificate and signed messages. An extension never chooses binaries, arguments or paths.

  • One-time numeric code pairing
  • Pinned TLS with a per-device certificate
  • Signed messages (RFC 9421)
  • Read-only containers with no network
  • Request budget per task
Capability Executor Result
http.probehttpx 1.12.0HTTP services, status, titles and technologies
web.crawlKatana 1.7.0Pages, forms, parameters and static JavaScript
api.schema.testSchemathesis 4.29.1Coverage, checks and reduced cases from OpenAPI
nuclei.scanNucleiReviewed and approved HTTP GET/HEAD templates

SDK 1.4 ecosystem: asset discovery, DNS, ports, typed fuzzing, TLS, JWT and code analysis, depending on the installed executors.

Control comes first

Your lab. Your rules.

CatSuite is designed for authorized use and keeps you in charge: nothing leaves the device without your action and every new capability goes through your approval.

Data on the device

History, notes, sessions and extension data stay on your phone.

Isolated execution

Extensions run on QuickJS in a separate Android service with limited memory and time.

Explicit permissions

Installs start disabled. Broader destinations and capabilities require new approval.

Verifiable integrity

SHA-256 for every package file and an Ed25519 signature over canonical JSON.

Biometric vault

Strong biometrics, Android Keystore and CryptoObject protect PROTECTED and SECRET content.

Protected files

CATSEAL2 envelope with Argon2id and AES-256-GCM for password-protected packages, workflows and backups.

Protection levels

  1. PUBLIC

    Runs while the app is open; pauses when you leave.

  2. PROTECTED

    Pauses when you leave the app and saves encrypted progress.

  3. SECRET

    Also wipes controlled keys and buffers when locking.

Only use CatSuite on your own environments, for learning, CTFs and explicitly authorized testing.

Animated neural core of Cat AI

Cat AI

CAT AI COMING SOON

Cat AI is out of this version while it is being rebuilt. When it returns, it will understand only the context you allow — nothing more.

On Cat AI’s radar

  • PlanningComing soon
  • Multi-agentsComing soon
  • Send imageComing soon
  • NotesComing soon
  • Interesting requestsComing soon
  • Network ProxyComing soon
  • InterceptComing soon
  • DiscovererComing soon
  • IntruderComing soon
  • PermissionsComing soon
  • Text fileComing soon

Frequently asked questions

Straight to the point.

What is CatSuite?

A free Android lab for web security, API testing and QA. It brings an interceptor, network proxy, technical browser, Repeater, Intruder, Discoverer, decoder and SSL/TLS analyzer into one workflow.

Is Cat AI available?

Not yet. Cat AI is being rebuilt and will return in a future version. Meanwhile, every other module and the extensions work as usual.

What are extensions?

.catplug packages with JavaScript code run by QuickJS inside an isolated Android service. They can observe and change traffic, create tabs and commands, store data and record findings — only with the permissions you approve.

Can an extension access my files or run programs?

No. The SDK offers no general file access, process execution, DOM or fetch. Network sends only reach declared and approved destinations, with TLS validated by Android.

Do I need CatBridge?

No. CatBridge is optional and brings tools such as httpx, Katana, Schemathesis and Nuclei into visual workflows. Everything else works with the app alone.

Does CatSuite send my data to third parties?

Not automatically. History, notes, sessions and extension data stay on your phone. Exporting, sharing or sending anything always depends on your action.

Where can I get it?

The app is on Google Play, for free, with no subscription and no paywall. CatBridge (Windows and Linux) and the 1.4.0 extension SDK are in the official repository github.com/netcattest/catsuite, and the CatSuite Studio extension is on the Visual Studio Code Marketplace.

Can I build extensions in VS Code?

Yes. Install the CatSuite Studio extension from the Visual Studio Code Marketplace: it brings SDK suggestions, project validation, a local preview with fixtures and signed .catplug package builds. If you prefer not to install anything, use the web IDE.

Black tech cat, the CatSuite mascot
The guardian of the mobile lab.

Google Play · Android · 2026

Your lab starts now.

Free. No subscription. No paywall.