# Introduction to CatSuite

> What CatSuite is, how the lab modules connect and what changed in version 1.5.0 with extensions, visual workflows and CatBridge.

- Language: en
- Canonical URL: https://netcattest.com/catsuite/en/docs/introduction
- Section: Get started
- Updated: 2026-10-05
- Other language (pt-BR): https://netcattest.com/catsuite/docs/introducao

**CatSuite** is a free Android lab for web security, API testing and QA. It brings the tools that are usually scattered between computer and phone into a single workflow: traffic capture, request editing and resending, wordlist testing, path discovery, decoding and TLS analysis.

> [!IMPORTANT]
> Only use CatSuite on your own environments, for learning, CTFs and explicitly authorized testing.

## How the lab is organized

| Module | What it is for |
|---|---|
| Interceptor | Pause, review and decide on requests and responses, with history, Site Map and export. |
| Browser | Technical browser with network monitor, page source, inspection, DOM modifier and CatEyes. |
| Network Proxy | HTTP and HTTPS traffic capture with its own CA certificate and replacement rules. |
| Repeater | Raw request editing and resending, with response comparison. |
| Intruder | Testing with `$CAT$` markers, wordlists, pause and resume. |
| Discoverer | Path, parameter and endpoint discovery on authorized targets. |
| Decoder | JWT, Base64, URL, Hex, HTML Entities, Binary and hashes. |
| SSL/TLS Analyzer | Handshake, certificate chain and fingerprints. |
| History and Notepad | Session timeline and local notes. |

Whatever you capture in one module can move to another with a single tap: a request from History opens in Repeater, becomes the base for Intruder or goes into an extension.

## What is new in version 1.5.0

- **Extensions** — JavaScript `.catplug` packages run by QuickJS inside an isolated Android service. See [CatSuite extensions](https://netcattest.com/catsuite/en/docs/extensions).
- **Visual workflows** — `.catflow` graphs with steps, conditions, joins and reproducible runs. See [Visual workflows](https://netcattest.com/catsuite/en/docs/workflows).
- **CatBridge** — an optional connector that brings httpx, Katana, Schemathesis and Nuclei into workflows. See [CatBridge](https://netcattest.com/catsuite/en/docs/catbridge).
- **Vault and protection** — PUBLIC, PROTECTED and SECRET levels with strong biometrics. See [Security](https://netcattest.com/catsuite/en/docs/security).

> [!NOTE] Cat AI coming soon
> Cat AI is out of this version while it is being rebuilt and will return in a future update. Every other module and the extensions work as usual.

## Lab principles

1. **Explicit action** — the app never generates traffic on its own; captures, sends and analyses depend on you.
2. **Data on the device** — history, notes, sessions and extension data stay on the phone.
3. **Least privilege** — extensions start disabled and only receive approved capabilities.
4. **Bilingual** — interface, extensions and this documentation in Portuguese and English.

## Next steps

- [Getting started with CatSuite](https://netcattest.com/catsuite/en/docs/getting-started)
- [Build your first extension](https://netcattest.com/catsuite/en/docs/extensions)
- [Open the extension IDE in the browser](https://netcattest.com/catsuite/en/ide)
