Skip to content
CatSuite

Language

Choose whether the site follows your browser or always uses Brazilian Portuguese or English.

Get it free

Modules

Interceptor

CatSuite Interceptor: how to use and configure the queue, edit requests and responses, Site Map, history with filters and HAR, JSON, TXT and cURL export.

16 min read

The Interceptor is CatSuite's live traffic control module: it pauses every request and every response in a queue, lets you review and edit method, URL, headers, cookies and body before forwarding, and keeps all history organized by domain, with a Site Map by host and endpoint, side-by-side comparison and HAR, JSON, TXT and cURL export. This page explains each concept, each option and how to use and configure the Interceptor step by step, always against an authorized target.

What the Interceptor is and what it is for #

The Interceptor solves a core problem of web analysis: looking at and changing traffic as it happens. Instead of reading a log after the fact, you hold the message in transit, inspect the content and decide what goes through — forward as is, edit and forward, or drop.

When interception is on, each message from the Network Proxy or the Browser stops in a queue. When it is off, traffic passes straight through and is only recorded in history, if history is enabled.

Typical use cases:

  • Stop a login or an API call to see exactly which headers and cookies the client sends.
  • Swap a body parameter or a URL before the request reaches the server.
  • Change the status, headers or body of a response to test how the client app reacts.
  • Build the map of a target's hosts and endpoints as you browse.
  • Compare two captures side by side and export the evidence in HAR, JSON, TXT or cURL.

The Interceptor is a local inspection point: it operates on the device's own proxy, with no intermediate servers. Captures and preferences stay in the app's private storage.

Essential Interceptor concepts #

Before touching the options, it helps to understand the terms on screen. Each concept below maps directly to a panel or button in the module.

Request and response interception #

Intercepting means holding the message before it moves on. By default, the Interceptor pauses requests (what the client sends). With the Intercept response option on, it also pauses the response (what the server returns) after the request is forwarded, opening a second editing moment. That way you control both directions of the HTTP exchange.

Interception queue #

The interception queue is the list of paused messages waiting for your decision. Each item shows method, host and path. While the queue exists, traffic is truly stopped — nothing moves on without your action. The queue header shows the state (interception on or off) and, during a send, displays FINISHING SEND. The queue layout toggles between CARDS (more detail) and COMPACT (more items on screen).

Host scope and selective pausing #

The scope is a list of hosts that defines where the pause applies. With Pause only in scope on and hosts set in Scope management, the queue holds only those hosts' traffic and lets the rest through. The match is by suffix: example.com covers api.example.com and other subdomains, and the field accepts the *.host form. With no hosts in scope, the pause stays global so no traffic escapes.

History, limit and Full Capture #

The history keeps the messages that passed through the Interceptor and the proxy, by domain, for later review. The history limit keeps up to a maximum number of visible requests and automatically discards the oldest. Full Capture, when the device supports it, records all proxy traffic in history — not only what you intercepted by hand. It depends on device support and may not be available on every device.

Site Map (site tree) by host and endpoint #

The Site Map rearranges history as a tree: each host becomes a node that expands into the observed paths (endpoints). Each endpoint shows the methods and statuses seen plus a request counter. It is the quick way to understand the target surface. Tapping a host's filter icon applies the host (or host plus path) to the history filter.

A/B request comparison #

Comparison opens two captures side by side — A and B — in a full screen. You switch between REQUEST and RESPONSE, and the different lines between the two sides are highlighted, which makes it easy to see what changed from one capture to another.

HAR, JSON, TXT and cURL export #

Export takes the filtered history out of the app. There are four formats: TXT (organized text), cURL .txt (a file of full cURL commands, with -X, -H and -d), JSON (structured data for analysis and automation) and .HAR (a file compatible with HTTP traffic analysis tools). The same screen is used to download or share.

Automatic rules and extensions #

When extensions process the proxy, the applicable replacement rules run before the handlers and before the message reaches the queue. A request changed by an automatic rule gets an AUTOMATIC RULE mark in the queue. Manual editing in the Interceptor prevails over what was already applied.

The Interceptor screen: tabs and panels #

The Interceptor has three tabs at the top: INTERCEPT, HISTORY and OPTIONS. The default accent color is yellow (purple in the Virtual App).

Intercept tab #

This is where you work the live queue. At the top is the interception switch (on/off) and the CARDS/COMPACT layout toggle. Below, the INTERCEPTION QUEUE lists the paused messages with METHOD, HOST and PATH. With nothing in the queue, the area shows WAITING FOR NEW REQUESTS. Each item leads to the REQUEST EDITOR and, when applicable, to the paused response section.

History tab #

Shows the INTERCEPTOR HISTORY. At the top there is the search field (Search by site, domain, method, URL or status...) and the buttons for site tree (Site Map), interesting only, Network Proxy (when applicable) and the filters menu. The list brings each capture; selecting one, the detail panel shows the REQUEST and RESPONSE tabs and the GENERAL INFORMATION. Touch and hold a capture to open the copy, share and send menu.

Options tab #

Gathers two configuration blocks: INTERCEPT SETTINGS (queue behavior, scope, Full Capture and HTTP colors) and HISTORY SETTINGS (limit, capture conditions, response contents, history scope and the DOWNLOAD AND SHARE shortcut).

When you open a request in the queue, the REQUEST EDITOR presents four sub-tabs:

  • Raw — the whole request as text (initial line with method and URL/path, headers and body). Editing here syncs with the structured tabs.
  • Headers — the list of EDITABLE HEADERS as key/value pairs. This is where you edit cookies, through the Cookie header, along with Authorization, User-Agent and others.
  • Body — the body editor, which adapts to the format: BODY // FORM URLENCODED, BODY // FORMATTED JSON or BODY // TEXT.
  • Search — finds a span inside the request itself.

When done, use APPLY AND SEND to forward with the edits. If the raw text becomes invalid, the editor warns you (Fix the raw request to edit the headers.) and locks the structured tabs until you fix it.

Interceptor options and how to configure them #

Intercept options #

The table gathers the INTERCEPT SETTINGS block of the Options tab.

OptionValuesDefaultWhat it does
InterceptionOn, OffOffTurns the queue on; each new message stops for review before moving on
Intercept responseOn, OffOffAlso pauses the response after the request is forwarded
Redirect to the BrowserOn, OffOnOpens the Browser when you send the request from the Interceptor
Pause only in scopeOn, OffOffPauses only the scope hosts; with no hosts, the pause is global
Scope managementhost listemptySets the covered hosts (suffix match, accepts *.host)
Full CaptureOn, OffOffRecords all local proxy traffic in history (depends on the device)
HTTP colorsOn, OffOnHighlights method, initial line, headers and values in the request and response areas
Interceptor historyOn, OffOnTurns history recording of captures on or off

To turn interception on, you can use the Intercept tab switch or this options block. With it on, intercept only when you really mean to hold traffic — the queue blocks everything that comes in until you act item by item.

To limit the pause to a target, turn on Pause only in scope and open Scope management to add the hosts. Remember the suffix match: shop.example covers www.shop.example and api.shop.example. With no hosts, even with the option on the pause stays global on purpose, so nothing escapes.

To follow the result, keep Redirect to the Browser on: when you send the request, the app opens the Browser so you can see the main navigation. Turn it off if you prefer to stay in the Interceptor after confirming the request.

History options #

The table gathers the HISTORY SETTINGS block.

OptionValuesDefaultWhat it does
History limit100, 300, 500, 1000, 2000, 5000300Keeps up to N requests before discarding the oldest
Capture only in conditionsAll, Wi-Fi, Data, ChargingAllRestricts capture by network type or battery state
View response contentsOn, OffOffShows the full body of images, scripts and CSS (uses more memory)
Record history only in scopeOn, OffOffRecords only requests to scope hosts
Download and share——Opens the export screen with filters by method, status, domain, type, day and time

To save memory on modest devices, choose the 100 limit (the lightest option, focused on the newest requests). The 300 default balances performance and retention; 1000 to 5000 keep long sessions at the cost of more memory.

The capture conditions save data and battery: Wi-Fi captures only on wireless, Data only on mobile data and Charging only with the device charging and battery above 50%. All imposes no restriction.

Buttons and actions #

In the Intercept tab and the editor #

Button / ActionWhereWhat it does
Interception switchTop of the tabTurns the queue on or off
CARDS / COMPACTTop of the queueToggles the queue layout
EDITQueue itemOpens the request editor
SENDQueue / editorForwards the message unchanged
DROPQueue / editorBlocks and discards the message
APPLY AND SENDEditorApplies the edits and forwards
Raw / Headers / Body / SearchRequest editorToggles the editor sub-tabs

In the paused response #

Button / ActionWhat it does
EDIT AND SENDOpens the response editor
STATUS / HEADERS / BODYResponse editor sub-tabs
QUICK ACTIONS → INJECT JSOpens the field to inject JavaScript into the response
QUICK ACTIONS → SWAP JSON/BODYReplaces the response body/JSON
INJECT AND SENDApplies the JS injection and forwards
FORMAT JSONReformats the JSON body for reading
SEND / DROPForwards or discards the response

In the History tab #

Button / ActionWhat it does
Search fieldFilters by site, domain, method, URL or status
Site treeOpens or closes the Site Map
Interesting onlyShows only captures marked as interesting
Network ProxyShows only Network Proxy traffic
Filters menuOpens HISTORY OPTIONS
Long press on a captureOpens the copy, share and send menu

The HISTORY OPTIONS menu brings ADVANCED SEARCH (Search by regex, Match case, Search in body, Clear filters, Clear history) and the filters METHOD (GET, POST, PUT, DELETE), STATUS, DOMAIN (Select Domains) and TYPE (HTML, JSON, Image, JS, CSS).

The long-press menu on a capture offers: Copy (URL, Request headers, Request body, Full request, Response headers, Response body, Full response, Request and response, cURL, fetch (JavaScript), Python requests, HTTPie); Share; Compare with another; Mark as interesting; Explain here (AI explanation); and sending to Repeater, Intruder, SSL/TLS Analyzer, Decoder and the notepad.

In export (Download and share) #

Button / ActionWhat it does
EXPORT FORMATChooses TXT, cURL .txt, JSON or .HAR
DOWNLOADSaves the file with the current filters
SHARESends the file through the system share sheet
CLEAR FILTERSRemoves the selected method, status, domain, type, day and time

In the A/B comparison #

Button / ActionWhat it does
REQUEST / RESPONSEChooses which part to compare between A and B
A → REPEATER / B → REPEATERSends capture A or B to the Repeater
A → INTERCEPT / B → INTERCEPTLoads capture A or B into the queue for editing

Step by step #

1. Turn interception on and hold the first request #

  1. Capture traffic with the Network Proxy or browse with the Browser.
  2. On the INTERCEPT tab, flip the interception switch.
  3. Trigger an action on the target (a click, a form submit). The message appears in the INTERCEPTION QUEUE.
  4. Tap the item to open the REQUEST EDITOR or decide right away: SEND or DROP.

2. Edit method, URL, headers, cookies and body #

  1. With the request open in the editor, go to the Raw tab to adjust the initial line (method and path) or paste a full request.
  2. Go to Headers to change key/value pairs. Edit the Cookie header to swap cookies and Authorization for the token.
  3. Go to Body to edit the body in the detected format (form urlencoded, JSON or text).
  4. Check everything and tap APPLY AND SEND.

3. Intercept and edit the response #

  1. On the OPTIONS tab, turn on Intercept response.
  2. Forward a request normally. When the reply arrives, the PAUSED RESPONSE section opens.
  3. Adjust STATUS, HEADERS or BODY; use FORMAT JSON to read better; if needed, INJECT JS from QUICK ACTIONS.
  4. Tap EDIT AND SEND (or INJECT AND SEND) to return the response to the client.

4. Explore the Site Map by host and endpoint #

  1. On the HISTORY tab, tap the site tree icon.
  2. Expand a host to see its paths, with methods, statuses and counts.
  3. Tap a host's filter icon (or a path) to apply that slice to history and close the Site Map.

5. Filter history and compare two captures #

  1. On the HISTORY tab, use the search field or open the filters menu and choose method, status, domain and type.
  2. For precise text, turn on Search by regex and, if you want, Search in body.
  3. On a capture, long press and choose Compare with another; then tap another capture.
  4. On the comparison screen, switch REQUEST/RESPONSE and watch the different lines highlighted.

6. Export in HAR, JSON, TXT or cURL #

  1. On the OPTIONS tab, open DOWNLOAD AND SHARE.
  2. Adjust the filters (method, status, domain, type, day and time) and watch the TOTAL, SELECTED and FILTERS counters.
  3. Tap EXPORT FORMAT and choose .HAR, JSON, TXT or cURL .txt.
  4. Tap DOWNLOAD or SHARE.

7. Send to the Repeater and the Intruder #

  1. In history (or in the editor), long press a capture.
  2. Choose Send to the Repeater for manual, precise replay, or Send to the Intruder for automation with wordlists.
  3. Dig deeper in the destination module.

Examples #

Original request paused in the queue, before any edit:

Intercepted requestHTTP
POST /api/login HTTP/1.1
Host: target.example
Content-Type: application/json
Cookie: session=abc123

{"user":"ann","password":"123456"}

The same request after editing the cookie and body in the Headers/Body tabs:

Edited requestHTTP
POST /api/login HTTP/1.1
Host: target.example
Content-Type: application/json
Cookie: session=new_value

{"user":"ann","password":"another-password"}

Command produced by Copy cURL from a history capture:

Equivalent cURLShell
curl -i -X POST "https://target.example/api/login" \
  -H "Content-Type: application/json" \
  -H "Cookie: session=abc123" \
  -d '{"user":"ann","password":"123456"}'

Snippet of an exported .HAR file, in the format HTTP analysis tools accept:

HAR export (snippet)JSON
{
  "log": {
    "version": "1.2",
    "creator": { "name": "CatSuite", "version": "1.3" },
    "entries": [
      {
        "request": {
          "method": "POST",
          "url": "https://target.example/api/login"
        },
        "response": {
          "status": 200
        }
      }
    ]
  }
}

Common problems and FAQ #

I turned interception on and the app froze all traffic. That is the expected behavior: the queue holds everything until you act. Resolve the queue items with SEND or DROP, or turn interception off.

The queue does not hold only the target I want. Turn on Pause only in scope and add the hosts in Scope management. With no hosts, the pause is global on purpose.

I turned on Intercept response and nothing shows up. The response only pauses after the matching request is forwarded. Forward the request and wait for the reply.

History records nothing. Check that Interceptor history is on and that the History and notes module is active in settings. Also check the capture conditions (Wi-Fi, Data, Charging).

History search does not find what I expect. If Search by regex is on and the expression is invalid, the panel warns you. Fix the regex or turn off regex mode. Turn on Search in body to look inside the contents.

The export came out empty. Some filter is too strict. Tap CLEAR FILTERS and check the TOTAL and SELECTED counters before downloading.

Full Capture will not turn on. It depends on device support. When unavailable, the app warns you and interception keeps working normally, only without the broad capture.

Best practices and security #

  • Keep interception off when you only want to observe; turn it on only to hold traffic on purpose.
  • Use the scope so you do not stop traffic from other apps and services on the device.
  • Prefer editing in Headers and Body over rewriting the whole Raw request, so you do not break the structure.
  • Compare two captures before concluding that an edit had an effect.
  • Export in .HAR or JSON to keep evidence; use cURL to reproduce the request outside the app.

Next step #