# Interceptor

> CatSuite Interceptor: how to use and configure the queue, edit requests and responses, Site Map, history with filters and HAR, JSON, TXT and cURL export.

- Language: en
- Canonical URL: https://netcattest.com/catsuite/en/docs/modules/interceptor
- Section: Modules
- Updated: 2026-10-06
- Other language (pt-BR): https://netcattest.com/catsuite/docs/modulos/interceptador

The **Interceptor** is CatSuite's live traffic control module: it pauses every **request** and every **response** in a queue, lets you review and edit **method, URL, headers, cookies and body** before forwarding, and keeps all **history** organized by domain, with a **Site Map** by host and endpoint, side-by-side **comparison** and **HAR, JSON, TXT and cURL export**. This page explains each concept, each option and how to use and configure the Interceptor step by step, always against an authorized target.

> [!WARNING]
> Intercepting, editing and resending traffic can affect apps, sessions and services on the device. Use the Interceptor only within a flow you started yourself and against systems you have written authorization to test. See [Security and responsible use](https://netcattest.com/catsuite/en/docs/security).

## What the Interceptor is and what it is for

The Interceptor solves a core problem of web analysis: looking at and changing traffic **as it happens**. Instead of reading a log after the fact, you hold the message in transit, inspect the content and **decide what goes through** — forward as is, edit and forward, or drop.

When interception is **on**, each message from the [Network Proxy](https://netcattest.com/catsuite/en/docs/modules/proxy) or the [Browser](https://netcattest.com/catsuite/en/docs/modules/browser) stops in a **queue**. When it is **off**, traffic passes straight through and is only recorded in **history**, if history is enabled.

Typical use cases:

- Stop a login or an API call to see exactly which headers and cookies the client sends.
- Swap a body parameter or a URL before the request reaches the server.
- Change the status, headers or body of a **response** to test how the client app reacts.
- Build the map of a target's hosts and endpoints as you browse.
- Compare two captures side by side and export the evidence in HAR, JSON, TXT or cURL.

The Interceptor is a **local inspection point**: it operates on the device's own proxy, with no intermediate servers. Captures and preferences stay in the app's private storage.

## Essential Interceptor concepts

Before touching the options, it helps to understand the terms on screen. Each concept below maps directly to a panel or button in the module.

### Request and response interception

**Intercepting** means holding the message before it moves on. By default, the Interceptor pauses **requests** (what the client sends). With the **Intercept response** option on, it also pauses the **response** (what the server returns) after the request is forwarded, opening a second editing moment. That way you control both directions of the HTTP exchange.

### Interception queue

The **interception queue** is the list of paused messages waiting for your decision. Each item shows **method, host and path**. While the queue exists, traffic is truly stopped — nothing moves on without your action. The queue header shows the state (**interception on or off**) and, during a send, displays **FINISHING SEND**. The queue layout toggles between **CARDS** (more detail) and **COMPACT** (more items on screen).

### Host scope and selective pausing

The **scope** is a list of hosts that defines where the pause applies. With **Pause only in scope** on and hosts set in **Scope management**, the queue holds only those hosts' traffic and lets the rest through. The match is **by suffix**: `example.com` covers `api.example.com` and other subdomains, and the field accepts the `*.host` form. With no hosts in scope, the pause stays **global** so no traffic escapes.

### History, limit and Full Capture

The **history** keeps the messages that passed through the Interceptor and the proxy, by domain, for later review. The **history limit** keeps up to a maximum number of visible requests and automatically discards the oldest. **Full Capture**, when the device supports it, records **all** proxy traffic in history — not only what you intercepted by hand. It depends on device support and may not be available on every device.

### Site Map (site tree) by host and endpoint

The **Site Map** rearranges history as a **tree**: each **host** becomes a node that expands into the observed **paths** (endpoints). Each endpoint shows the **methods** and **statuses** seen plus a request counter. It is the quick way to understand the target surface. Tapping a host's filter icon applies the host (or host plus path) to the history filter.

### A/B request comparison

**Comparison** opens two captures side by side — **A** and **B** — in a full screen. You switch between **REQUEST** and **RESPONSE**, and the **different lines** between the two sides are highlighted, which makes it easy to see what changed from one capture to another.

### HAR, JSON, TXT and cURL export

**Export** takes the filtered history out of the app. There are four formats: **TXT** (organized text), **cURL .txt** (a file of full `cURL` commands, with `-X`, `-H` and `-d`), **JSON** (structured data for analysis and automation) and **.HAR** (a file compatible with HTTP traffic analysis tools). The same screen is used to **download** or **share**.

### Automatic rules and extensions

When [extensions](https://netcattest.com/catsuite/en/docs/extensions) process the proxy, the applicable **replacement rules** run **before** the handlers and before the message reaches the queue. A request changed by an automatic rule gets an **AUTOMATIC RULE** mark in the queue. Manual editing in the Interceptor prevails over what was already applied.

## The Interceptor screen: tabs and panels

The Interceptor has three tabs at the top: **INTERCEPT**, **HISTORY** and **OPTIONS**. The default accent color is yellow (purple in the Virtual App).

### Intercept tab

This is where you work the live queue. At the top is the **interception switch** (on/off) and the **CARDS/COMPACT** layout toggle. Below, the **INTERCEPTION QUEUE** lists the paused messages with **METHOD**, **HOST** and **PATH**. With nothing in the queue, the area shows **WAITING FOR NEW REQUESTS**. Each item leads to the **REQUEST EDITOR** and, when applicable, to the **paused response** section.

### History tab

Shows the **INTERCEPTOR HISTORY**. At the top there is the search field (**Search by site, domain, method, URL or status...**) and the buttons for **site tree** (Site Map), **interesting only**, **Network Proxy** (when applicable) and the **filters menu**. The list brings each capture; selecting one, the detail panel shows the **REQUEST** and **RESPONSE** tabs and the **GENERAL INFORMATION**. Touch and hold a capture to open the copy, share and send menu.

### Options tab

Gathers two configuration blocks: **INTERCEPT SETTINGS** (queue behavior, scope, Full Capture and HTTP colors) and **HISTORY SETTINGS** (limit, capture conditions, response contents, history scope and the **DOWNLOAD AND SHARE** shortcut).

## The request editor: Raw, Headers, Body and Search

When you open a request in the queue, the **REQUEST EDITOR** presents four sub-tabs:

- **Raw** — the whole request as text (initial line with **method** and **URL/path**, **headers** and **body**). Editing here syncs with the structured tabs.
- **Headers** — the list of **EDITABLE HEADERS** as key/value pairs. This is where you edit **cookies**, through the `Cookie` header, along with `Authorization`, `User-Agent` and others.
- **Body** — the body editor, which adapts to the format: **BODY // FORM URLENCODED**, **BODY // FORMATTED JSON** or **BODY // TEXT**.
- **Search** — finds a span inside the request itself.

When done, use **APPLY AND SEND** to forward with the edits. If the raw text becomes invalid, the editor warns you (**Fix the raw request to edit the headers.**) and locks the structured tabs until you fix it.

> [!TIP]
> To change a single value, the **Headers** or **Body** tab is safer than **Raw**, because it keeps the structure. Use **Raw** when you need to rewrite the initial line (method and path) or paste a whole request.

## Interceptor options and how to configure them

### Intercept options

The table gathers the **INTERCEPT SETTINGS** block of the Options tab.

| Option | Values | Default | What it does |
| --- | --- | --- | --- |
| Interception | On, Off | Off | Turns the queue on; each new message stops for review before moving on |
| Intercept response | On, Off | Off | Also pauses the response after the request is forwarded |
| Redirect to the Browser | On, Off | On | Opens the Browser when you send the request from the Interceptor |
| Pause only in scope | On, Off | Off | Pauses only the scope hosts; with no hosts, the pause is global |
| Scope management | host list | empty | Sets the covered hosts (suffix match, accepts `*.host`) |
| Full Capture | On, Off | Off | Records all local proxy traffic in history (depends on the device) |
| HTTP colors | On, Off | On | Highlights method, initial line, headers and values in the request and response areas |
| Interceptor history | On, Off | On | Turns history recording of captures on or off |

To **turn interception on**, you can use the Intercept tab switch or this options block. With it on, intercept only when you really mean to hold traffic — the queue blocks everything that comes in until you act item by item.

To **limit the pause to a target**, turn on **Pause only in scope** and open **Scope management** to add the hosts. Remember the suffix match: `shop.example` covers `www.shop.example` and `api.shop.example`. With no hosts, even with the option on the pause stays global on purpose, so nothing escapes.

To **follow the result**, keep **Redirect to the Browser** on: when you send the request, the app opens the [Browser](https://netcattest.com/catsuite/en/docs/modules/browser) so you can see the main navigation. Turn it off if you prefer to stay in the Interceptor after confirming the request.

> [!NOTE]
> **Full Capture** uses the local proxy to record all traffic in history. It depends on device support; when it is not available, the app warns that full interception could not be enabled on this device and interception keeps working normally, only without the broad capture.

### History options

The table gathers the **HISTORY SETTINGS** block.

| Option | Values | Default | What it does |
| --- | --- | --- | --- |
| History limit | 100, 300, 500, 1000, 2000, 5000 | 300 | Keeps up to N requests before discarding the oldest |
| Capture only in conditions | All, Wi-Fi, Data, Charging | All | Restricts capture by network type or battery state |
| View response contents | On, Off | Off | Shows the full body of images, scripts and CSS (uses more memory) |
| Record history only in scope | On, Off | Off | Records only requests to scope hosts |
| Download and share | — | — | Opens the export screen with filters by method, status, domain, type, day and time |

To **save memory** on modest devices, choose the **100** limit (the lightest option, focused on the newest requests). The **300** default balances performance and retention; **1000** to **5000** keep long sessions at the cost of more memory.

The **capture conditions** save data and battery: **Wi-Fi** captures only on wireless, **Data** only on mobile data and **Charging** only with the device charging and battery above 50%. **All** imposes no restriction.

> [!IMPORTANT]
> To unlock the timeline of sites, requests and what passed through the interceptor, the [History and notes](https://netcattest.com/catsuite/en/docs/modules/history) module must be active in Settings. Without it, history recording is unavailable.

## Buttons and actions

### In the Intercept tab and the editor

| Button / Action | Where | What it does |
| --- | --- | --- |
| Interception switch | Top of the tab | Turns the queue on or off |
| CARDS / COMPACT | Top of the queue | Toggles the queue layout |
| EDIT | Queue item | Opens the request editor |
| SEND | Queue / editor | Forwards the message unchanged |
| DROP | Queue / editor | Blocks and discards the message |
| APPLY AND SEND | Editor | Applies the edits and forwards |
| Raw / Headers / Body / Search | Request editor | Toggles the editor sub-tabs |

### In the paused response

| Button / Action | What it does |
| --- | --- |
| EDIT AND SEND | Opens the response editor |
| STATUS / HEADERS / BODY | Response editor sub-tabs |
| QUICK ACTIONS → INJECT JS | Opens the field to inject JavaScript into the response |
| QUICK ACTIONS → SWAP JSON/BODY | Replaces the response body/JSON |
| INJECT AND SEND | Applies the JS injection and forwards |
| FORMAT JSON | Reformats the JSON body for reading |
| SEND / DROP | Forwards or discards the response |

### In the History tab

| Button / Action | What it does |
| --- | --- |
| Search field | Filters by site, domain, method, URL or status |
| Site tree | Opens or closes the Site Map |
| Interesting only | Shows only captures marked as interesting |
| Network Proxy | Shows only [Network Proxy](https://netcattest.com/catsuite/en/docs/modules/proxy) traffic |
| Filters menu | Opens **HISTORY OPTIONS** |
| Long press on a capture | Opens the copy, share and send menu |

The **HISTORY OPTIONS** menu brings **ADVANCED SEARCH** (Search by regex, Match case, Search in body, Clear filters, Clear history) and the filters **METHOD** (GET, POST, PUT, DELETE), **STATUS**, **DOMAIN** (Select Domains) and **TYPE** (HTML, JSON, Image, JS, CSS).

The long-press menu on a capture offers: **Copy** (URL, Request headers, Request body, Full request, Response headers, Response body, Full response, Request and response, **cURL**, **fetch (JavaScript)**, **Python requests**, **HTTPie**); **Share**; **Compare with another**; **Mark as interesting**; **Explain here** (AI explanation); and sending to [Repeater](https://netcattest.com/catsuite/en/docs/modules/repeater), [Intruder](https://netcattest.com/catsuite/en/docs/modules/intruder), [SSL/TLS Analyzer](https://netcattest.com/catsuite/en/docs/modules/ssl-tls), [Decoder](https://netcattest.com/catsuite/en/docs/modules/decoder) and the notepad.

### In export (Download and share)

| Button / Action | What it does |
| --- | --- |
| EXPORT FORMAT | Chooses TXT, cURL .txt, JSON or .HAR |
| DOWNLOAD | Saves the file with the current filters |
| SHARE | Sends the file through the system share sheet |
| CLEAR FILTERS | Removes the selected method, status, domain, type, day and time |

### In the A/B comparison

| Button / Action | What it does |
| --- | --- |
| REQUEST / RESPONSE | Chooses which part to compare between A and B |
| A → REPEATER / B → REPEATER | Sends capture A or B to the [Repeater](https://netcattest.com/catsuite/en/docs/modules/repeater) |
| A → INTERCEPT / B → INTERCEPT | Loads capture A or B into the queue for editing |

## Step by step

### 1. Turn interception on and hold the first request

1. Capture traffic with the [Network Proxy](https://netcattest.com/catsuite/en/docs/modules/proxy) or browse with the [Browser](https://netcattest.com/catsuite/en/docs/modules/browser).
2. On the **INTERCEPT** tab, flip the **interception switch**.
3. Trigger an action on the target (a click, a form submit). The message appears in the **INTERCEPTION QUEUE**.
4. Tap the item to open the **REQUEST EDITOR** or decide right away: **SEND** or **DROP**.

### 2. Edit method, URL, headers, cookies and body

1. With the request open in the editor, go to the **Raw** tab to adjust the **initial line** (method and path) or paste a full request.
2. Go to **Headers** to change key/value pairs. Edit the `Cookie` header to swap cookies and `Authorization` for the token.
3. Go to **Body** to edit the body in the detected format (form urlencoded, JSON or text).
4. Check everything and tap **APPLY AND SEND**.

### 3. Intercept and edit the response

1. On the **OPTIONS** tab, turn on **Intercept response**.
2. Forward a request normally. When the reply arrives, the **PAUSED RESPONSE** section opens.
3. Adjust **STATUS**, **HEADERS** or **BODY**; use **FORMAT JSON** to read better; if needed, **INJECT JS** from **QUICK ACTIONS**.
4. Tap **EDIT AND SEND** (or **INJECT AND SEND**) to return the response to the client.

### 4. Explore the Site Map by host and endpoint

1. On the **HISTORY** tab, tap the **site tree** icon.
2. Expand a **host** to see its **paths**, with methods, statuses and counts.
3. Tap a host's filter icon (or a path) to apply that slice to history and close the Site Map.

### 5. Filter history and compare two captures

1. On the **HISTORY** tab, use the search field or open the **filters menu** and choose method, status, domain and type.
2. For precise text, turn on **Search by regex** and, if you want, **Search in body**.
3. On a capture, long press and choose **Compare with another**; then tap another capture.
4. On the comparison screen, switch **REQUEST/RESPONSE** and watch the **different lines** highlighted.

### 6. Export in HAR, JSON, TXT or cURL

1. On the **OPTIONS** tab, open **DOWNLOAD AND SHARE**.
2. Adjust the filters (method, status, domain, type, day and time) and watch the **TOTAL**, **SELECTED** and **FILTERS** counters.
3. Tap **EXPORT FORMAT** and choose **.HAR**, **JSON**, **TXT** or **cURL .txt**.
4. Tap **DOWNLOAD** or **SHARE**.

### 7. Send to the Repeater and the Intruder

1. In history (or in the editor), long press a capture.
2. Choose **Send to the Repeater** for manual, precise replay, or **Send to the Intruder** for automation with wordlists.
3. Dig deeper in the destination module.

> [!TIP]
> When you want to repeat variations of the same request, forward it to the [Repeater](https://netcattest.com/catsuite/en/docs/modules/repeater) or the [Intruder](https://netcattest.com/catsuite/en/docs/modules/intruder) instead of editing it by hand several times in the queue.

## Examples

Original request paused in the queue, before any edit:

```http
POST /api/login HTTP/1.1
Host: target.example
Content-Type: application/json
Cookie: session=abc123

{"user":"ann","password":"123456"}
```

The same request after editing the cookie and body in the Headers/Body tabs:

```http
POST /api/login HTTP/1.1
Host: target.example
Content-Type: application/json
Cookie: session=new_value

{"user":"ann","password":"another-password"}
```

Command produced by **Copy cURL** from a history capture:

```bash
curl -i -X POST "https://target.example/api/login" \
  -H "Content-Type: application/json" \
  -H "Cookie: session=abc123" \
  -d '{"user":"ann","password":"123456"}'
```

Snippet of an exported **.HAR** file, in the format HTTP analysis tools accept:

```json
{
  "log": {
    "version": "1.2",
    "creator": { "name": "CatSuite", "version": "1.3" },
    "entries": [
      {
        "request": {
          "method": "POST",
          "url": "https://target.example/api/login"
        },
        "response": {
          "status": 200
        }
      }
    ]
  }
}
```

## Common problems and FAQ

**I turned interception on and the app froze all traffic.** That is the expected behavior: the queue holds everything until you act. Resolve the queue items with **SEND** or **DROP**, or turn interception off.

**The queue does not hold only the target I want.** Turn on **Pause only in scope** and add the hosts in **Scope management**. With no hosts, the pause is global on purpose.

**I turned on Intercept response and nothing shows up.** The response only pauses **after** the matching request is forwarded. Forward the request and wait for the reply.

**History records nothing.** Check that **Interceptor history** is on and that the [History and notes](https://netcattest.com/catsuite/en/docs/modules/history) module is active in settings. Also check the **capture conditions** (Wi-Fi, Data, Charging).

**History search does not find what I expect.** If **Search by regex** is on and the expression is invalid, the panel warns you. Fix the regex or turn off regex mode. Turn on **Search in body** to look inside the contents.

**The export came out empty.** Some filter is too strict. Tap **CLEAR FILTERS** and check the **TOTAL** and **SELECTED** counters before downloading.

**Full Capture will not turn on.** It depends on device support. When unavailable, the app warns you and interception keeps working normally, only without the broad capture.

> [!IMPORTANT]
> When you copy, export or share content, the destination becomes your decision. Treat requests, cookies and bodies as sensitive data.

## Best practices and security

> [!DANGER]
> Changing requests and responses can end sessions, corrupt data and affect services. Do this only on authorized targets and with awareness of the effect of each edit.

- Keep interception off when you only want to observe; turn it on only to hold traffic on purpose.
- Use the **scope** so you do not stop traffic from other apps and services on the device.
- Prefer editing in **Headers** and **Body** over rewriting the whole **Raw** request, so you do not break the structure.
- Compare two captures before concluding that an edit had an effect.
- Export in **.HAR** or **JSON** to keep evidence; use **cURL** to reproduce the request outside the app.

## Next step

- [Network Proxy](https://netcattest.com/catsuite/en/docs/modules/proxy)
- [Browser](https://netcattest.com/catsuite/en/docs/modules/browser)
- [Repeater](https://netcattest.com/catsuite/en/docs/modules/repeater)
- [Intruder](https://netcattest.com/catsuite/en/docs/modules/intruder)
- [History and notes](https://netcattest.com/catsuite/en/docs/modules/history)
- [Modules overview](https://netcattest.com/catsuite/en/docs/modules)
- [Security and responsible use](https://netcattest.com/catsuite/en/docs/security)
