Skip to content
CatSuite

Language

Choose whether the site follows your browser or always uses Brazilian Portuguese or English.

Get it free

Modules

CatSuite modules

Explore the CatSuite modules: Interceptor, Network Proxy, Browser, Repeater, Intruder and Discoverer, with a glossary and how to use and configure each one.

16 min read

The CatSuite modules form a complete web security and API testing lab inside a single Android app. The Interceptor and the Network Proxy capture requests and responses, the Browser and CatEyes explore pages and identify technologies, the Repeater and the Intruder resend and automate variations, the Discoverer reveals paths and parameters, the Decoder translates tokens and hashes, SSL/TLS triages the secure connection, Wordlists and payloads feed the local attacks and History keeps the timeline and notes. This page introduces each module, explains the concepts they all share, shows how to use and configure the set as a whole and tells you which module to pick at each stage of the work.

The CatSuite modules and what they are for #

Every module runs in the same local lab: traffic is captured, analyzed and resent on the device itself, data stays on the device and you choose the authorized targets. The table summarizes each module, what it is for and where to open it in the app.

ModuleWhat it is forWhere to open it
InterceptorPause, review and edit every request and response, with history, Site Map, A/B comparison and exportBottom bar: INTERCEPTOR
Network ProxyBring HTTP and HTTPS traffic from other devices and apps into the lab, with its own CA and replacement rulesMENU
BrowserA technical browser with network monitor, page source, inspect element, DOM modifier and User-AgentBottom bar: BROWSER
CatEyesTechnology fingerprinting of the open page, with confidence levels and CVE signalsInside the Browser
RepeaterEdit the raw request, resend it as often as you like and compare responsesMENU
IntruderSend payloads at marked positions, with wordlists, a generator, processors and filtersMENU
DiscovererDiscover paths, parameters and endpoints with wordlists and controlled pacingMENU
DecoderConvert JWT, Base64, URL, Hex, HTML Entities and Binary and generate hashesMENU
SSL/TLSTriage of the handshake, certificate chain and fingerprintsMENU (SSL/TLS Analyzer)
Wordlists and payloadsManage default and imported wordlists and the payload generatorSettings > Wordlist
History and notesSession timeline and a notepad with exportMENU (History and Notepad)

Core concepts: the modules glossary #

The same terms show up on almost every CatSuite screen. The glossary below explains each one and points to the module where it matters most.

TermWhat it meansWhere to go deeper
RequestThe message the client sends to the server: request line (method, path and version), headers, a blank line and an optional body.Interceptor, Repeater
ResponseThe server's answer: status line, headers and body. The Interceptor can pause it for editing before it reaches the client.Interceptor
ProxyAn intermediary: the client sends its requests to CatSuite, which forwards them to the destination and returns the response.Network Proxy
MITMMan-in-the-middle: the proxy sits in the middle of the conversation and can read, record and change every authorized message.Network Proxy
CA certificateThe lab's own certificate authority. Once installed as trusted on the client, it lets you decrypt that device's HTTPS.Network Proxy
WordlistA text file with one entry per line. Each line becomes a candidate tested against the target.Wordlists and payloads
PayloadEach concrete value that comes out of a wordlist or a generator and goes into the request.Intruder, Wordlists and payloads
$CAT$ markerThe exact spot where each wordlist word goes. In the Discoverer it sits in the base URL; in the Intruder positions are marked with buttons and appear between §.Discoverer, Intruder
FingerprintIn CatEyes, identifying technologies from evidence; in the Network Proxy and SSL/TLS, the unique identifier of a certificate.CatEyes, SSL/TLS
CVEThe public identifier of a known vulnerability. CatEyes cross-checks versioned technologies against a local database and shows CVE signals for review.CatEyes
HARHTTP Archive: a JSON file compatible with HTTP traffic analysis tools and one of the history export formats.Interceptor
JWTJSON Web Token: a token made of three Base64URL segments (header, payload and signature), common in the Authorization header.Decoder, Browser
ScopeA list of hosts that limits where pausing and history recording apply, with suffix matching.Interceptor
ProbeThe request sent without markers at the start of an intrusion; its response becomes the comparison baseline.Intruder

How the modules connect #

The modules share the same history and pass requests to each other with a single tap:

  • The Network Proxy and the Browser feed the Interceptor and History with captured traffic.
  • From a history capture you can send the request to the Repeater (fine tuning), the Intruder (payload automation), the SSL/TLS Analyzer, the Decoder or the notepad.
  • The Discoverer and the Intruder read the lists from Wordlists and payloads and send findings back to the Repeater.
  • CatEyes analyzes the page open in the Browser, and the Decoder interprets tokens and values coming from any module.
  • Extensions and visual workflows observe and extend these modules, with source marking the origin (proxy, network_proxy, repetir, intruso, descobridor).

The screen: main navigation, MENU and module panels #

On the home screen, tap START. On first access, the app shows the terms of use and the module selection: History, Notepad, Discoverer, SSL/TLS Analyzer and Network Proxy can be enabled right then or later in Settings.

Bottom bar #

EntryWhat it opens
INTERCEPTORIntercept, History, Site Map and module options
BROWSERThe lab's technical browser, with CatEyes
MENURepeater, Intruder, Discoverer, History, Notepad, Decoder, SSL/TLS Analyzer, Network Proxy, Settings and Extensions

Panels and tabs of each module #

Each module has its own layout. Use the table as a quick map before opening the detailed page.

ModuleScreen layout
InterceptorINTERCEPT, HISTORY and OPTIONS tabs; editor with Raw, Headers, Body and Search
Network ProxyOperational dashboard (operation, statistics, diagnostics) and a hub with SERVICE, LOCAL NETWORK, HTTPS AND CERTIFICATES, TRUSTED CLIENTS and HISTORY AND PRIVACY
BrowserAddress bar, BROWSER TOOLS panel and BROWSER OPTIONS menu
CatEyesSummary card with chips, eye badge on the Browser bar and analysis sections
RepeaterMANUAL EXECUTION card, REQUEST panel, A/B COMPARISON panel and RESPONSE panel
IntruderPreparation page (TARGET, REQUEST and PAYLOADS tabs) and a flow page with the results
DiscovererRun, Settings and Headers screens; processed, results and failures counters
DecoderHome page with FORMATS, JWT INSPECTOR, JWT AND SIGNATURES, JWE INSPECTOR, HASHES AND CRYPTO and SMART DECODE
Wordlists and payloadsDEFAULT WORDLISTS and USER WORDLISTS sections

Options and how to configure the modules #

Each module has its own settings page, covered in detail in its documentation. The table gathers the options that most influence the lab as a whole, with the app's real values and defaults.

OptionValuesDefaultWhat it does
Module selection (Settings)History, Notepad, Discoverer, SSL/TLS Analyzer, Network ProxyChosen at first launchEnables or disables the optional MENU modules
Interception (Interceptor)On, OffOffTurns the queue on; each new message is held for review
Intercept response (Interceptor)On, OffOffAlso pauses the response after the request goes through
Pause only in scope (Interceptor)On, OffOffPauses only the scope hosts; with no hosts, the pause is global
History limit (Interceptor)100, 300, 500, 1000, 2000, 5000300Keeps up to N requests and discards the oldest
Full Capture (Interceptor)On, OffOffRecords all local proxy traffic in history, when the device supports it
Proxy port (Network Proxy)1024 to 655358080Local port where the listener accepts connections
Intercept HTTPS traffic (Network Proxy)On, OffOnDecrypts HTTPS with the CA; off keeps the destination in a tunnel
Mask sensitive data (Network Proxy)On, OffOnHides known credentials in the view and common exports
History retention (Network Proxy)Current session, 1 day, 7 days, 30 days, Manual7 daysHow long the captures stay saved
Enable SSL/TLS (Repeater)On, OffOnWhen off, forces HTTP even if the original target is on HTTPS
Ignore certificate errors (Repeater and Intruder)On, OffOffAccepts invalid or self-signed certificates in the lab
Requests per second (Intruder)0, 1, 2, 3, 5, 10, 200 (free)Rate cap for the intrusion; 0 honors only the delay
Requests per second (Discoverer)1 to 62Base pace of the scan
Extra delay (Discoverer)0, 100, 250, 500, 750, 1000 ms250 msA fixed extra pause between attempts

To prepare the lab, open Settings and enable the optional modules you plan to use. History comes first, because without it there is no timeline to review later. Enable the Network Proxy only when you need to capture traffic from another device or app.

To avoid freezing the whole device, keep interception off while you are only observing, and turn on Pause only in scope with the target hosts listed under Scope management. That way the queue holds only the traffic you care about.

To control the pace of the active modules, start with the Discoverer's safe defaults (2 requests per second and a 250 ms delay) and, in the Intruder, set a requests-per-second cap or a delay before running large lists. The Discoverer's automatic 429 backoff eases the load when the target asks for a pause.

To protect your evidence, keep Mask sensitive data on in the Network Proxy and match retention to the size of the job. Ignoring certificate errors is a lab exception: leave it off on public targets.

The actions below are the lab's "plumbing": they move a request from one module to another and take the evidence out of the app.

Button / ActionWhereWhat it does
STARTHome screenEnters the app; on first access, opens the terms and the module selection
INTERCEPTOR / BROWSER / MENUBottom barSwitches between capture, browsing and the other modules
Send to the Repeater / IntruderLong press on a history captureOpens the request in the target module for replay or automation
Send to the SSL/TLS Analyzer, Decoder or notepadLong press on a history captureTakes the capture to TLS triage, decoding or note taking
Compare with anotherLong press on a history captureOpens two captures side by side, with differing lines highlighted
A → REPEATER / B → REPEATERInterceptor A/B comparisonSends one of the compared captures to the Repeater
DOWNLOAD AND SHAREInterceptor OPTIONS tabExports the filtered history as TXT, cURL .txt, JSON or .HAR
START NETWORK PROXYNetwork Proxy dashboardBrings up the listener and shows the proxy address
EXPORT CAHTTPS AND CERTIFICATESShares the .crt certificate to install on the client
VERIFICAR / BAIXAR TXTCatEyesVerifies the open page and downloads the text report
DECODE / NOTESRepeater editor context menuSends the selection to the Decoder or the Notepad
Send to the RepeaterDiscoverer result or long press on an Intruder resultTakes the finding to manual tuning
START INTRUSION / PAUSE / RESUMEIntruderSends the probe, fires the attack and controls the run
ADD WORDLISTSettings > WordlistImports a .txt list and starts validation

End-to-end lab workflow #

A typical test moves through several modules, from the first traffic to the report. The table shows the phases and what each one delivers.

PhaseModulesOutcome
1. PrepareSettings, SecurityModules enabled, authorized target defined and scope configured
2. CaptureBrowser, Network ProxyFirst requests and responses in history
3. MapInterceptor, CatEyes, SSL/TLSSite Map by host, technologies identified and secure connection checked
4. UnderstandDecoderTokens, cookies and parameters translated into readable text
5. ManipulateRepeaterThe effect of each change measured through compared responses
6. AutomateIntruder, Discoverer, Wordlists and payloadsBulk variations filtered and hidden paths revealed
7. RecordHistory and notesTimeline reviewed and observations written down
8. ReportInterceptor, CatEyesHAR, JSON, TXT and cURL exports, the CatEyes TXT report and exported notes

Which module to use when #

You want to...Use
See a page's traffic without setting anything upBrowser
Capture traffic from another device or a native appNetwork Proxy
Hold a request or response and edit it before it moves onInterceptor
Rewrite a header or cookie automatically across all trafficNetwork Proxy replacement rules
Find out which frameworks, servers and versions a page usesCatEyes
Change one field at a time and resend until you understand the effectRepeater
Test hundreds of values at the same position in a requestIntruder
Find unpublished directories, endpoints and parametersDiscoverer
Read a JWT or a Base64 value, or generate a hashDecoder
Check the handshake, chain and certificate fingerprintsSSL/TLS
Import your own word listWordlists and payloads
Review the session and write down evidenceHistory and notes

Step by step: your first full cycle in CatSuite #

  1. On the home screen, tap START, accept the terms of use and enable at least History and Notepad in the module selection.
  2. On the bottom bar, tap BROWSER and open an authorized target. The traffic it generates already enters the intercepted flow.
  3. In the Browser, open CatEyes from the eye badge and tap VERIFICAR (verify) to identify the page's technologies.
  4. Tap INTERCEPTOR, open the HISTORY tab and use the site tree to see the hosts and endpoints you visited.
  5. Tap a capture to read headers, body and response. If there is a token, long-press and send the value to the Decoder.
  6. Long-press again and choose Send to the Repeater. Change one field, tap SEND and compare the responses.
  7. When you need to test many values, send the same capture to the Intruder, tap AUTO-DETECT, pick a wordlist on the PAYLOADS tab and tap START INTRUSION.
  8. To look for hidden paths, open the Discoverer from the MENU, choose the wordlist under CONFIGURAÇÕES (settings) and tap SALVAR (save); then enter the URL with $CAT$ and tap INICIAR (start).
  9. Write your observations in the Notepad and review the timeline in History.
  10. On the Interceptor's OPTIONS tab, open DOWNLOAD AND SHARE, choose the format and tap download to keep the evidence.

Cross-module usage examples #

A request captured in the Interceptor history and sent to the Repeater:

Request in the RepeaterHTTP
GET /api/profile?id=42 HTTP/1.1
Host: target.example
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJhbmEiLCJyb2xlIjoidXNlciIsImV4cCI6MTc5OTk5OTk5OX0.c2lnbmF0dXJl
Accept: application/json

The payload of the token above, after pasting it into the Decoder's JWT inspector:

Decoded JWT payloadJSON
{
  "sub": "ana",
  "role": "user",
  "exp": 1799999999
}

The same request in the Intruder, with the position marked by AUTO-DETECT:

Marked position in the IntruderHTTP
GET /api/profile?id=§42§ HTTP/1.1
Host: target.example
Accept: application/json

Discoverer URLs with the $CAT$ marker, for paths and for parameters:

Discoverer base URLText
https://target.example/$CAT$
https://target.example/search?$CAT$=cat-suite

A simple wordlist ready to import under Settings > Wordlist:

my-list.txtText
admin
api/v1
backup
config
uploads

Manual proxy settings on a second test device:

Proxy on the client deviceText
Server: 192.168.0.42
Port: 8080

A command generated by the cURL export, ready to reproduce outside the app:

Exported cURLShell
curl -i -X GET "https://target.example/api/profile?id=42" \
  -H "Accept: application/json"

Where to download CatBridge and the extensions SDK #

The CatSuite app is free and ships with every module on this page; you install it from Google Play. The developer tools live at official addresses:

ToolWhere
CatBridge, the optional connector that runs on your computercatbridge folder on GitHub
CatSuite Studio, the VS Code extension with the SDK and the catsuite.d.ts typesVisual Studio Marketplace
CatSuite Studio source codecatsuite-vscode folder on GitHub
Full official repositorygithub.com/netcattest/catsuite

The step-by-step guides are in Downloads and SDK, Install and pair CatBridge and CatSuite Studio for VS Code.

Common problems and FAQ #

A module does not show up in the MENU. History, Notepad, Discoverer, SSL/TLS Analyzer and Network Proxy are optional modules. Enable them in Settings.

History is empty. Make sure History is enabled in Settings, that Interceptor history is on and that the capture conditions (Wi-Fi, Data, Charging) are not restricting recording.

I turned interception on and all traffic stopped. That is the expected behavior: the queue holds everything until you act. Use SEND or DROP on each item, or turn on Pause only in scope.

Traffic from other apps does not appear. The Browser captures only the traffic it generates itself. For other apps and devices, use the Network Proxy with the CA installed on the client.

HTTPS does not validate in the Network Proxy. The CA was not installed as trusted on the client, or the host is on the Bypassed hosts list. Check the fingerprint with COPY FINGERPRINT.

What is the difference between the Repeater and the Intruder? The Repeater does precise, manual replay of one request at a time; the Intruder automates many variations from marked positions and a wordlist or generator.

Where does the $CAT$ marker go in the Intruder? In the Intruder you do not type the marker: the AUTO-DETECT and MARK SELECTION buttons wrap the chosen span and the position shows up as P1, P2 and so on. In the Discoverer, $CAT$ goes literally into the base URL.

CatEyes says to open a site first. It analyzes the page open in the Browser. Load an authorized target before tapping VERIFICAR.

Do CVE signals confirm a vulnerability? No. They are leads from the local database for manual review; the detected version may be incomplete or already patched by the vendor.

My wordlist was not accepted. The file must be a .txt with one entry per line and at least one useful line. See Wordlists and payloads.

The Network Proxy stopped on its own. The listener works only while CatSuite is in the foreground and resumes automatically when you return to the app.

Next step #