The Browser is CatSuite's web exploration area: a technical browser that combines an address bar, search, controlled URL opening, a network monitor, page source, inspect element, a DOM modifier, JWT and Base64 detection in storage, User-Agent switching, desktop mode and IP spoofing headers. It puts the same inspection tools you would use on a computer in your pocket and automatically feeds the Interceptor and History. This page explains what each feature does, how to configure the module and how to use the Browser in real authorized testing flows.
What the Browser module is and what it is for #
The Browser opens pages in a WebView and, at the same time, exposes mobile DevTools over the loaded page. Beyond seeing the site, you follow every request, read the HTML and the JavaScript and CSS resources, select a visible element, edit the DOM tree, find tokens stored in the browser's storage and tune the headers of the next requests. It is the entry point to capture traffic without configuring the system proxy: everything you browse here already enters the intercepted flow.
When you confirm a request in the Interceptor, the app can open the Browser automatically to follow the result of the main navigation. The timeline of pages and requests is available when the History module is enabled in settings.
Core Browser concepts #
Before opening the screen, it helps to fix the terms that appear in the bar, the tools panel and the options menu.
Address bar and navigation #
The address bar accepts either a URL or search text. If what you typed is not a URL, the Browser sends the text to the chosen search engine (Google by default). The field shows a green padlock when the address starts with https:// and a search icon otherwise. Next to the field are the navigation controls — back, forward, reload and home — plus the CatEyes button and the three-dot menu.
Network monitor #
The Network monitor recaptures the page and lists requests in the order they were made, with status, method, domain, type, transferred size and timings. Each entry opens a detail with the request line, request and response headers, cookies sent and received, security flags (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) and a timeline with the start, middle and end of each resource. It is the equivalent of a desktop browser's Network tab.
Page source #
Page source shows the HTML of the open page and a resource bar with the JavaScript scripts and CSS stylesheets the site loaded. You switch between the HTML and each resource, search text inside the code, page through windows when the file is very large and download the current source. From here you can also open Inspect element.
Inspect element #
Inspect element turns on a selection mode on the page: you tap a visible element and CatSuite shows its attributes, generates a selector and lets you send the element to Page source or to the DOM modifier. It is the fast way to jump from what is on screen to the matching chunk in the code.
DOM modifier #
The DOM modifier checks the page and organizes the useful elements into a searchable, filterable list instead of showing an endless tree. It classifies items by category — field, textarea, select, form, button, link and external script — and marks which are hidden and which are editable. You edit the content and attributes of a field and apply the change straight onto the open page.
JWT and Base64 detection in storage #
When you open the storage explorer, CatSuite scans localStorage, sessionStorage and cookies for decodable values and highlights the ones that look like a JWT or Base64. A value marked as JWT opens the inspector with header, payload and signature; a Base64 value can be sent to the Decoder. This way you find tokens and secrets the page stored without decoding anything by hand.
JavaScript console and storage explorer #
The JavaScript console runs a snippet of code on the open page and shows the return value, the logs and the errors. The Storage explorer inspects and edits LocalStorage, SessionStorage, cookies (the ones that are not HttpOnly) and IndexedDB databases. Together they let you read and change the client state without leaving the app.
User-Agent and desktop mode #
The User-Agent is the identifier the browser sends in each request. CatSuite ships a catalog of ready-made profiles, organized into categories (Apple / iOS and macOS, Android by version and by usage type, Desktop, Consoles, Bots / Crawlers and others), plus the system default. Desktop mode goes beyond the User-Agent: it uses a wide layout and a desktop User-Agent to open the page as on a computer.
IP spoofing headers #
IP spoofing adds a source IP header to the next requests to simulate where the client appears to come from. You pick the header (X-Forwarded-For, X-Real-IP, CF-Connecting-IP, Client-IP or Forwarded) and a ready IP from the catalog (private and internal ranges, documentation and lab ranges, well-known public resolvers and IPv6 presets). Remember this is just a header: the server may or may not trust it.
CatEyes #
CatEyes identifies the page's technologies and cross-references versions with CVE signals from a local database, scoring confidence across layers of clues (headers, DOM, runtime and light probes). It has its own button in the bar, with color and pulse according to the severity found, and a dedicated page — see CatEyes.
| Term | What it is | Where it appears |
|---|---|---|
| Address bar | URL and search field with an HTTPS padlock | Top bar |
| Network monitor | Request list with status, timings and security | Tools |
| Page source | Page HTML and JS/CSS resources | Tools |
| Inspect element | Selection of a visible element on the page | Bar / Options |
| DOM modifier | Filterable list of editable elements | Tools |
| JWT / Base64 in storage | Token detection in storage and cookies | Storage explorer |
| User-Agent / desktop mode | Identity switch and desktop layout | Options → Headers / General |
| IP spoofing | Source IP header on the next requests | Options → Headers |
The Browser screen: bar, tabs and panels #
Top bar #
The top bar holds navigation. When the address field is collapsed, you see back, forward, reload and home on the left, the address bar in the center, the CatEyes button and the options menu on the right. When you tap the field, it expands for editing and shows the clear button, the send button and an arrow to collapse it.
Home panel and open page #
With no site loaded, the Browser shows the home panel with the illustration, the "Search the network or type a URL" field and the SEARCH button. When a page is open, it fills the WebView with a progress bar at the top while loading; if the address fails, the PAGE UNAVAILABLE screen appears with the error details and the HOME and RELOAD buttons.
BROWSER TOOLS panel #
The BROWSER TOOLS panel ("Tools active on the browser's current page.") gathers the analysis shortcuts as cards: CAT EYES (layered analysis), CONSOLE JS (scripts, return and logs), STORAGE (local, cookies and IndexedDB), NETWORK MONITOR (requests, resources and order) and DOM MODIFIER (search, filters and editing). With no site loaded, it shows the "SITE NOT LOADED YET" notice.
BROWSER OPTIONS menu #
The three-dot menu opens the BROWSER OPTIONS sheet, organized into blocks: general items (hide logo, desktop mode, clear cache and cookies), NAVIGATION, TOOLS, REQUESTS and, inside it, the HEADERS tab with the GENERAL, CUSTOMIZATION and CACHE AND NETWORK CONTROL groups.
Browser options and how to configure them #
Open the three-dot menu to adjust the internal browser's behavior. The choices are persistent: CatSuite keeps your preference across sessions.
| Option | Values | Default | What it does |
|---|---|---|---|
| Hide logo | On / Off | Off | Removes the illustrated header to keep the browser cleaner. |
| Desktop mode | On / Off | Off | Uses a wide layout and a desktop User-Agent to open pages as on a computer; requires a real site loaded. |
| Clear cache | Action | — | Removes cache, storage and local databases of the current page. |
| Clear cookies | Action | — | Deletes the cookies of the browser's current session. |
| Allow HTTP + HTTPS | On / Off | On | When off, it uses HTTPS only: HTTP addresses try to migrate to HTTPS and Android blocks mixed content. |
| Search engine | Google / DuckDuckGo / Bing / Brave Search / Ecosia | Sets the provider used when the typed text is not a URL. | |
| User-Agent | Profile catalog | System default | Switches the identifier sent on navigations, fetch and compatible XHR. |
| Accept-Language | Presets / original | Browser default | Sets the preferred language sent on the next requests. |
| Accept | Presets / original | Browser default | Controls the content types the browser starts to prefer. |
| Content-Type | Presets / original | Original | Overrides the content type sent. |
| Referer | Contextual presets / original | Original | Sets the referrer of the next navigations; presets use the current tab or the destination origin. |
| Origin | Presets / original | Original | Sets the origin sent on main navigations and compatible requests. |
| Sec-Fetch-Site | same-origin / same-site / cross-site / original | Original | Adjusts the site context declared on the main navigation. |
| IP spoofing | Header + IP from catalog | Off | Adds a source IP header to all new requests. |
| Extra headers | Name/value pairs | Empty | Adds or edits arbitrary headers (for example X-Api-Key). |
| No-Cache | On / Off | Off | Injects Cache-Control: no-cache and Pragma: no-cache. |
| Bypass ETag | On / Off | Off | Removes If-None-Match and If-Modified-Since to force 200 responses. |
| Identity Encoding | On / Off | Off | Uses Accept-Encoding: identity for uncompressed responses. |
| Block trackers | On / Off | Off | Blocks the marked analytics hosts without turning off Full Capture. |
To adjust each one: leave Hide logo to your visual taste. Turn on Desktop mode when the target serves a different mobile version and you want to see the desktop site — open the site first, because the option is only available with a page loaded. Use Clear cache and Clear cookies to repeat a login flow from scratch. Keep Allow HTTP + HTTPS on to open mixed targets in the lab; turn it off to force HTTPS only. Pick the Search engine you prefer in the bar. In the Headers block, switch the User-Agent to a catalog profile, adjust Accept-Language, Accept, Content-Type, Referer, Origin and Sec-Fetch-Site when you need to mimic a specific context, and use Extra headers for API keys and your own headers. Turn on No-Cache, Bypass ETag and Identity Encoding to avoid cache and compression and see the raw response.
Browser buttons and actions #
Top bar #
| Button | What it does |
|---|---|
| Back | Goes back one page in the WebView history. |
| Forward | Goes forward one page in the WebView history. |
| Reload | Reloads the current address. |
| Home | Returns to the home search panel. |
| Clear (in the field) | Empties the address field and keeps the keyboard open. |
| Send (in the field) | Opens the typed URL or searches the text. |
| CatEyes | Opens the technology and CVE analysis; the color indicates the severity. |
| Menu (three dots) | Opens the BROWSER OPTIONS sheet. |
Tools panel #
| Button | What it does |
|---|---|
| CAT EYES | Opens CatEyes to score the page's technologies and signatures. |
| CONSOLE JS | Opens the console to run JavaScript and read outputs and logs. |
| STORAGE | Opens the explorer for LocalStorage, SessionStorage, cookies and IndexedDB. |
| NETWORK MONITOR | Opens the monitor and recaptures the page. |
| DOM MODIFIER | Opens the filterable list of elements for editing. |
Network monitor #
| Button | What it does |
|---|---|
| START MONITOR AND RELOAD | Arms the monitor and reloads the page to capture from the start. |
| List entry | Opens the REQUEST DETAIL with headers, cookies, security and timings. |
| Detail tabs | Switch between Request, Response, Headers, Cookies, Security and Timings. |
DOM modifier #
| Button | What it does |
|---|---|
| CHECK / REFRESH CAPTURE | Reads the current DOM and builds the element list. |
| Search | Filters by input, form, script, href, name and other terms. |
| More filters | Opens the filters by DOM category. |
| EDIT | Opens the element editor to change content and attributes. |
| COPY DATA / COPY SELECTOR | Copies the element value or the generated selector. |
Page source #
| Button | What it does |
|---|---|
| Resource bar | Switches between the page HTML and each JS script or CSS stylesheet. |
| SEARCH | Searches text in the code, with previous and next result. |
| Download current source | Downloads the open HTML or resource. |
| Inspect element | Turns on element selection on the page. |
Step by step: how to use the Browser #
Open a target and capture traffic #
- On the home panel, type the authorized target URL or some search text and tap SEARCH.
- Wait for the page to load in the WebView.
- Open the Interceptor or History to see the requests the Browser generated.
- Send what matters to the Repeater or the Intruder.
Monitor the network of a page #
- With a site loaded, open the NETWORK MONITOR from the tools panel or the menu.
- Tap START MONITOR AND RELOAD to capture from the beginning of the load.
- Read the STATUS, ITEMS, FAILURES and TOTAL counters and walk through the load SEQUENCE.
- Tap an entry to open the REQUEST DETAIL and check headers, cookies, security flags and timings.
Read and download the page source #
- Open Page source from the options menu.
- Use the resource bar to switch between the HTML and the loaded JS scripts or CSS stylesheets.
- Tap SEARCH and look for a term; use the arrows to move to the previous or next result.
- Tap Download current source to save the open file.
Inspect an element and edit the DOM #
- Turn on Inspect element from the bar or the menu and tap a visible element on the page.
- Check the attributes and the generated selector and send the element to the DOM modifier.
- In the DOM modifier, tap CHECK if the list is empty and filter by the element's category.
- Tap EDIT, change the content or the attributes and confirm to apply the change on the page.
Detect JWT and Base64 in storage #
- Open STORAGE (Storage explorer) from the tools panel.
- Pick the area: LocalStorage, SessionStorage, Cookies or IndexedDB.
- Look for the values highlighted as JWT or Base64.
- Open a JWT to see header, payload and signature, or send a Base64 value to the Decoder.
Switch the User-Agent and turn on desktop mode #
- Open Options → Headers and tap User-Agent.
- Choose a category and a ready profile (or the system default) and go back.
- To see the site as on a computer, return to the main options screen and turn on Desktop mode.
- Reload the page to apply the new identity.
Apply IP spoofing by headers #
- Open Options → Headers and tap IP spoofing.
- Choose the source header (for example X-Forwarded-For) and an IP from the catalog.
- Tap APPLY IP SPOOFING.
- Reload the page; to remove it, open again and tap DISABLE IP SPOOFING.
Examples #
Source IP header added to the Browser's next requests.
GET / HTTP/1.1
Host: exemplo.com
User-Agent: Cat Suite
X-Forwarded-For: 203.0.113.10JWT value found in the page's localStorage.
{
"key": "token",
"value": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjMifQ.c2lnbmF0dXJl"
}Snippet run in the JavaScript console to read the page storage.
return JSON.stringify(localStorage);Common problems and frequently asked questions (FAQ) #
The tool cards appear disabled. No site has been loaded yet. Search the network or type a URL to open a real page before using the tools.
Desktop mode will not turn on. It is only available with a site loaded. Open a real target and try again.
The Network monitor lists nothing. Tap START MONITOR AND RELOAD: the monitor needs to reload the page to capture requests from the start.
A cookie does not show in the explorer. HttpOnly cookies are not exposed here; the others can be inspected and edited.
The HTTP page will not open. With HTTPS-only mode active, the browser tries to migrate to HTTPS and Android blocks mixed content. In an authorized lab, turn on Allow HTTP + HTTPS.
I changed the Referer/Origin and the site broke. Some targets validate these headers. Go back to the original value in the Headers block or use Restore Default.
IP spoofing changed nothing. The source IP is just a header; the server may ignore it. Confirm the header was applied and that the target trusts that header.