Skip to content
CatSuite

Language

Choose whether the site follows your browser or always uses Brazilian Portuguese or English.

Get it free

Modules

Browser

Guide to the CatSuite Browser module: network monitor, page source, inspect element, DOM modifier, JWT/Base64, User-Agent, desktop mode and IP spoofing.

14 min read

The Browser is CatSuite's web exploration area: a technical browser that combines an address bar, search, controlled URL opening, a network monitor, page source, inspect element, a DOM modifier, JWT and Base64 detection in storage, User-Agent switching, desktop mode and IP spoofing headers. It puts the same inspection tools you would use on a computer in your pocket and automatically feeds the Interceptor and History. This page explains what each feature does, how to configure the module and how to use the Browser in real authorized testing flows.

What the Browser module is and what it is for #

The Browser opens pages in a WebView and, at the same time, exposes mobile DevTools over the loaded page. Beyond seeing the site, you follow every request, read the HTML and the JavaScript and CSS resources, select a visible element, edit the DOM tree, find tokens stored in the browser's storage and tune the headers of the next requests. It is the entry point to capture traffic without configuring the system proxy: everything you browse here already enters the intercepted flow.

When you confirm a request in the Interceptor, the app can open the Browser automatically to follow the result of the main navigation. The timeline of pages and requests is available when the History module is enabled in settings.

Core Browser concepts #

Before opening the screen, it helps to fix the terms that appear in the bar, the tools panel and the options menu.

Address bar and navigation #

The address bar accepts either a URL or search text. If what you typed is not a URL, the Browser sends the text to the chosen search engine (Google by default). The field shows a green padlock when the address starts with https:// and a search icon otherwise. Next to the field are the navigation controls — back, forward, reload and home — plus the CatEyes button and the three-dot menu.

Network monitor #

The Network monitor recaptures the page and lists requests in the order they were made, with status, method, domain, type, transferred size and timings. Each entry opens a detail with the request line, request and response headers, cookies sent and received, security flags (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) and a timeline with the start, middle and end of each resource. It is the equivalent of a desktop browser's Network tab.

Page source #

Page source shows the HTML of the open page and a resource bar with the JavaScript scripts and CSS stylesheets the site loaded. You switch between the HTML and each resource, search text inside the code, page through windows when the file is very large and download the current source. From here you can also open Inspect element.

Inspect element #

Inspect element turns on a selection mode on the page: you tap a visible element and CatSuite shows its attributes, generates a selector and lets you send the element to Page source or to the DOM modifier. It is the fast way to jump from what is on screen to the matching chunk in the code.

DOM modifier #

The DOM modifier checks the page and organizes the useful elements into a searchable, filterable list instead of showing an endless tree. It classifies items by category — field, textarea, select, form, button, link and external script — and marks which are hidden and which are editable. You edit the content and attributes of a field and apply the change straight onto the open page.

JWT and Base64 detection in storage #

When you open the storage explorer, CatSuite scans localStorage, sessionStorage and cookies for decodable values and highlights the ones that look like a JWT or Base64. A value marked as JWT opens the inspector with header, payload and signature; a Base64 value can be sent to the Decoder. This way you find tokens and secrets the page stored without decoding anything by hand.

JavaScript console and storage explorer #

The JavaScript console runs a snippet of code on the open page and shows the return value, the logs and the errors. The Storage explorer inspects and edits LocalStorage, SessionStorage, cookies (the ones that are not HttpOnly) and IndexedDB databases. Together they let you read and change the client state without leaving the app.

User-Agent and desktop mode #

The User-Agent is the identifier the browser sends in each request. CatSuite ships a catalog of ready-made profiles, organized into categories (Apple / iOS and macOS, Android by version and by usage type, Desktop, Consoles, Bots / Crawlers and others), plus the system default. Desktop mode goes beyond the User-Agent: it uses a wide layout and a desktop User-Agent to open the page as on a computer.

IP spoofing headers #

IP spoofing adds a source IP header to the next requests to simulate where the client appears to come from. You pick the header (X-Forwarded-For, X-Real-IP, CF-Connecting-IP, Client-IP or Forwarded) and a ready IP from the catalog (private and internal ranges, documentation and lab ranges, well-known public resolvers and IPv6 presets). Remember this is just a header: the server may or may not trust it.

CatEyes #

CatEyes identifies the page's technologies and cross-references versions with CVE signals from a local database, scoring confidence across layers of clues (headers, DOM, runtime and light probes). It has its own button in the bar, with color and pulse according to the severity found, and a dedicated page — see CatEyes.

TermWhat it isWhere it appears
Address barURL and search field with an HTTPS padlockTop bar
Network monitorRequest list with status, timings and securityTools
Page sourcePage HTML and JS/CSS resourcesTools
Inspect elementSelection of a visible element on the pageBar / Options
DOM modifierFilterable list of editable elementsTools
JWT / Base64 in storageToken detection in storage and cookiesStorage explorer
User-Agent / desktop modeIdentity switch and desktop layoutOptions → Headers / General
IP spoofingSource IP header on the next requestsOptions → Headers

The Browser screen: bar, tabs and panels #

Top bar #

The top bar holds navigation. When the address field is collapsed, you see back, forward, reload and home on the left, the address bar in the center, the CatEyes button and the options menu on the right. When you tap the field, it expands for editing and shows the clear button, the send button and an arrow to collapse it.

Home panel and open page #

With no site loaded, the Browser shows the home panel with the illustration, the "Search the network or type a URL" field and the SEARCH button. When a page is open, it fills the WebView with a progress bar at the top while loading; if the address fails, the PAGE UNAVAILABLE screen appears with the error details and the HOME and RELOAD buttons.

BROWSER TOOLS panel #

The BROWSER TOOLS panel ("Tools active on the browser's current page.") gathers the analysis shortcuts as cards: CAT EYES (layered analysis), CONSOLE JS (scripts, return and logs), STORAGE (local, cookies and IndexedDB), NETWORK MONITOR (requests, resources and order) and DOM MODIFIER (search, filters and editing). With no site loaded, it shows the "SITE NOT LOADED YET" notice.

BROWSER OPTIONS menu #

The three-dot menu opens the BROWSER OPTIONS sheet, organized into blocks: general items (hide logo, desktop mode, clear cache and cookies), NAVIGATION, TOOLS, REQUESTS and, inside it, the HEADERS tab with the GENERAL, CUSTOMIZATION and CACHE AND NETWORK CONTROL groups.

Browser options and how to configure them #

Open the three-dot menu to adjust the internal browser's behavior. The choices are persistent: CatSuite keeps your preference across sessions.

OptionValuesDefaultWhat it does
Hide logoOn / OffOffRemoves the illustrated header to keep the browser cleaner.
Desktop modeOn / OffOffUses a wide layout and a desktop User-Agent to open pages as on a computer; requires a real site loaded.
Clear cacheAction—Removes cache, storage and local databases of the current page.
Clear cookiesAction—Deletes the cookies of the browser's current session.
Allow HTTP + HTTPSOn / OffOnWhen off, it uses HTTPS only: HTTP addresses try to migrate to HTTPS and Android blocks mixed content.
Search engineGoogle / DuckDuckGo / Bing / Brave Search / EcosiaGoogleSets the provider used when the typed text is not a URL.
User-AgentProfile catalogSystem defaultSwitches the identifier sent on navigations, fetch and compatible XHR.
Accept-LanguagePresets / originalBrowser defaultSets the preferred language sent on the next requests.
AcceptPresets / originalBrowser defaultControls the content types the browser starts to prefer.
Content-TypePresets / originalOriginalOverrides the content type sent.
RefererContextual presets / originalOriginalSets the referrer of the next navigations; presets use the current tab or the destination origin.
OriginPresets / originalOriginalSets the origin sent on main navigations and compatible requests.
Sec-Fetch-Sitesame-origin / same-site / cross-site / originalOriginalAdjusts the site context declared on the main navigation.
IP spoofingHeader + IP from catalogOffAdds a source IP header to all new requests.
Extra headersName/value pairsEmptyAdds or edits arbitrary headers (for example X-Api-Key).
No-CacheOn / OffOffInjects Cache-Control: no-cache and Pragma: no-cache.
Bypass ETagOn / OffOffRemoves If-None-Match and If-Modified-Since to force 200 responses.
Identity EncodingOn / OffOffUses Accept-Encoding: identity for uncompressed responses.
Block trackersOn / OffOffBlocks the marked analytics hosts without turning off Full Capture.

To adjust each one: leave Hide logo to your visual taste. Turn on Desktop mode when the target serves a different mobile version and you want to see the desktop site — open the site first, because the option is only available with a page loaded. Use Clear cache and Clear cookies to repeat a login flow from scratch. Keep Allow HTTP + HTTPS on to open mixed targets in the lab; turn it off to force HTTPS only. Pick the Search engine you prefer in the bar. In the Headers block, switch the User-Agent to a catalog profile, adjust Accept-Language, Accept, Content-Type, Referer, Origin and Sec-Fetch-Site when you need to mimic a specific context, and use Extra headers for API keys and your own headers. Turn on No-Cache, Bypass ETag and Identity Encoding to avoid cache and compression and see the raw response.

Browser buttons and actions #

Top bar #

ButtonWhat it does
BackGoes back one page in the WebView history.
ForwardGoes forward one page in the WebView history.
ReloadReloads the current address.
HomeReturns to the home search panel.
Clear (in the field)Empties the address field and keeps the keyboard open.
Send (in the field)Opens the typed URL or searches the text.
CatEyesOpens the technology and CVE analysis; the color indicates the severity.
Menu (three dots)Opens the BROWSER OPTIONS sheet.

Tools panel #

ButtonWhat it does
CAT EYESOpens CatEyes to score the page's technologies and signatures.
CONSOLE JSOpens the console to run JavaScript and read outputs and logs.
STORAGEOpens the explorer for LocalStorage, SessionStorage, cookies and IndexedDB.
NETWORK MONITOROpens the monitor and recaptures the page.
DOM MODIFIEROpens the filterable list of elements for editing.

Network monitor #

ButtonWhat it does
START MONITOR AND RELOADArms the monitor and reloads the page to capture from the start.
List entryOpens the REQUEST DETAIL with headers, cookies, security and timings.
Detail tabsSwitch between Request, Response, Headers, Cookies, Security and Timings.

DOM modifier #

ButtonWhat it does
CHECK / REFRESH CAPTUREReads the current DOM and builds the element list.
SearchFilters by input, form, script, href, name and other terms.
More filtersOpens the filters by DOM category.
EDITOpens the element editor to change content and attributes.
COPY DATA / COPY SELECTORCopies the element value or the generated selector.

Page source #

ButtonWhat it does
Resource barSwitches between the page HTML and each JS script or CSS stylesheet.
SEARCHSearches text in the code, with previous and next result.
Download current sourceDownloads the open HTML or resource.
Inspect elementTurns on element selection on the page.

Step by step: how to use the Browser #

Open a target and capture traffic #

  1. On the home panel, type the authorized target URL or some search text and tap SEARCH.
  2. Wait for the page to load in the WebView.
  3. Open the Interceptor or History to see the requests the Browser generated.
  4. Send what matters to the Repeater or the Intruder.

Monitor the network of a page #

  1. With a site loaded, open the NETWORK MONITOR from the tools panel or the menu.
  2. Tap START MONITOR AND RELOAD to capture from the beginning of the load.
  3. Read the STATUS, ITEMS, FAILURES and TOTAL counters and walk through the load SEQUENCE.
  4. Tap an entry to open the REQUEST DETAIL and check headers, cookies, security flags and timings.

Read and download the page source #

  1. Open Page source from the options menu.
  2. Use the resource bar to switch between the HTML and the loaded JS scripts or CSS stylesheets.
  3. Tap SEARCH and look for a term; use the arrows to move to the previous or next result.
  4. Tap Download current source to save the open file.

Inspect an element and edit the DOM #

  1. Turn on Inspect element from the bar or the menu and tap a visible element on the page.
  2. Check the attributes and the generated selector and send the element to the DOM modifier.
  3. In the DOM modifier, tap CHECK if the list is empty and filter by the element's category.
  4. Tap EDIT, change the content or the attributes and confirm to apply the change on the page.

Detect JWT and Base64 in storage #

  1. Open STORAGE (Storage explorer) from the tools panel.
  2. Pick the area: LocalStorage, SessionStorage, Cookies or IndexedDB.
  3. Look for the values highlighted as JWT or Base64.
  4. Open a JWT to see header, payload and signature, or send a Base64 value to the Decoder.

Switch the User-Agent and turn on desktop mode #

  1. Open Options → Headers and tap User-Agent.
  2. Choose a category and a ready profile (or the system default) and go back.
  3. To see the site as on a computer, return to the main options screen and turn on Desktop mode.
  4. Reload the page to apply the new identity.

Apply IP spoofing by headers #

  1. Open Options → Headers and tap IP spoofing.
  2. Choose the source header (for example X-Forwarded-For) and an IP from the catalog.
  3. Tap APPLY IP SPOOFING.
  4. Reload the page; to remove it, open again and tap DISABLE IP SPOOFING.

Examples #

Source IP header added to the Browser's next requests.

IP spoofing headerHTTP
GET / HTTP/1.1
Host: exemplo.com
User-Agent: Cat Suite
X-Forwarded-For: 203.0.113.10

JWT value found in the page's localStorage.

JWT in storageJSON
{
  "key": "token",
  "value": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjMifQ.c2lnbmF0dXJl"
}

Snippet run in the JavaScript console to read the page storage.

Reading storage in the consoleJavaScript
return JSON.stringify(localStorage);

Common problems and frequently asked questions (FAQ) #

The tool cards appear disabled. No site has been loaded yet. Search the network or type a URL to open a real page before using the tools.

Desktop mode will not turn on. It is only available with a site loaded. Open a real target and try again.

The Network monitor lists nothing. Tap START MONITOR AND RELOAD: the monitor needs to reload the page to capture requests from the start.

A cookie does not show in the explorer. HttpOnly cookies are not exposed here; the others can be inspected and edited.

The HTTP page will not open. With HTTPS-only mode active, the browser tries to migrate to HTTPS and Android blocks mixed content. In an authorized lab, turn on Allow HTTP + HTTPS.

I changed the Referer/Origin and the site broke. Some targets validate these headers. Go back to the original value in the Headers block or use Restore Default.

IP spoofing changed nothing. The source IP is just a header; the server may ignore it. Confirm the header was applied and that the target trusts that header.

Next step #