The Intruder is CatSuite's request automation module: it takes a base request, replaces the marked positions with each payload from a wordlist or a generator, fires the sends at the pace you set and keeps every response for you to trim and filter. It is the right tool for value enumeration, parameter testing, controlled fuzzing and behavior checks whenever you need to repeat the same request dozens or thousands of times changing only one piece. This page explains each concept, each option and how to configure the Intruder step by step, always against an authorized target.
What the Intruder is and what it is for #
The Intruder solves a simple repetition problem: instead of editing and resending a request by hand in the Repeater, you mark where the value changes, choose which values to test and let the module walk the whole list. Each send becomes a row in the attack log, with status, size and time, ready for comparison.
Typical use cases:
- Enumerate sequential identifiers (for example
id=1toid=500) to check access control. - Test a list of usernames, paths or parameters against an endpoint.
- Vary the value of a header or form field and watch how the response changes.
- Measure size and time differences between the normal response (the probe) and each variation.
The Intruder is a local HTTP client: it builds and sends the requests from the device itself, with no intermediate servers. The session history is saved in the app storage, so you can pause and resume without losing progress.
Essential Intruder concepts #
Before you configure anything, it helps to understand the terms on screen. Each concept below maps directly to a button or panel in the module.
Payload markers: marking the positions #
A payload marker indicates the exact point in the request where each value from your list will go. In the Intruder you do not type the marker by hand: the AUTO-DETECT and MARK SELECTION buttons wrap the chosen span in a pair of markers, and each position then shows up as a P1, P2, P3… chip in the CURRENT MARKERS list. In the editor, the marked span is highlighted between the delimiter pair (§value§).
Auto-detection understands three field formats:
- Query string in the URL (
?key=value&key2=value2). - Form
application/x-www-form-urlencodedin the body (field=value). - JSON in the body (it marks the values of each
"key": valuepair).
Wordlists and payload generators #
The values that go into the positions come from one of two sources:
- Wordlist — a list of lines, built in or imported by you. The built-in lists and the ones created in the app settings appear in the INTRUDER WORDLIST picker. Importing, the
.txtformat and validation are covered in Wordlists and payloads. - Dynamic generator — builds a numeric sequence on the fly, from a range and affixes. Useful when you do not have a file, only a range (for example
user-001touser-250).
Distribution modes #
When there is more than one marked position, the distribution mode decides how the lists are combined across the markers. There are four modes, each with a different total estimate, detailed in the Distribution and combination modes table below.
Payload processors #
A processor is a transformation applied to each payload before the send. You build a chain of steps (URL encoding, Base64, hashing, case change, Unicode escaping, affixes) and the steps are applied in the order they appear. It is the same mechanism as the Decoder, reused to prepare the values at attack time.
Probe and baseline #
On start, the Intruder first sends the request without markers — the probe. The probe response becomes the baseline against which each variation is compared. From it the module computes, for each result:
- Size delta — the difference, in bytes, between the response and the probe.
- Similarity — a 0 to 100 index (by bigrams) between the response body and the probe body.
- Different from probe — whether the body equals or differs from the baseline.
Result trimming and filtering #
Trimming and filtering refine what the log shows, without resending anything. You can filter by status, size, time, search for words anywhere in the result and apply GREP (keep what matches a pattern) or EXTRACT (pull a span of the response via regex).
Pacing and session #
Pacing combines two options: the delay (fixed wait between attempts) and the requests per second (rate cap). The Intruder honors the larger interval of the two. The session is persisted to disk, so pausing, leaving and coming back keeps request, markers, payloads and results.
The Intruder screen: pages, tabs and panels #
The Intruder has two pages: Preparation (where you build the attack) and Flow (where you follow the results). You switch between them with VIEW FLOW and with the back button on the flow page.
Preparation page #
Preparation is split into three tabs at the top: TARGET, REQUEST and PAYLOADS. The REQUEST tab shows a counter with the number of active markers.
TARGET tab #
Defines the destination and the network. The MAIN TARGET field accepts a host (target.example) or a full URL — the Intruder keeps only host, protocol and port, discarding path, query and extra slashes. Below it are the PROTOCOL (HTTPS/HTTP), the PORT, the DELAY, the REQUESTS PER SECOND and the TLS tolerance switch. The chips at the top summarize the current setup (target, delay, pace and strict/flexible TLS).
REQUEST tab #
Holds the base-request editor and the marking actions: AUTO-DETECT, MARK SELECTION and CLEAR. Right below, CURRENT MARKERS lists the P1, P2… chips and a preview with the positions highlighted. When the request arrives imported from the Interceptor or the Repeater, the Intruder already tries to mark the fields automatically.
PAYLOADS tab #
Gathers, in this order: the distribution-mode tiles; (when there are two or more markers in Aligned or Combinations mode) the per-marker source chips; the PAYLOAD SOURCE choice (WORDLIST or DYNAMIC GENERATOR); the configuration of the chosen source; and the PROCESSORS.
Flow page (results) #
Shows three counters — PROCESSED, RESPONSES and FAILURES — and the ATTACK LOG. Each result is a card with the run #, status, size, time, the payload and a snippet of the response. The FILTERS button opens the trimming panel; CLEAR resets the active filters. Long-press a result to open the copy and send menu.
Intruder options and how to configure them #
The table below gathers the target, network and pacing options on the TARGET tab.
| Option | Values | Default | What it does |
|---|---|---|---|
| Protocol | HTTPS, HTTP | HTTPS | Sets the send scheme and suggests the port (443 or 80) |
| Port | 1 to 65535 | 443 (HTTPS) / 80 (HTTP) | Destination port; drops from the Host header when it is the protocol default |
| Main target | host or URL | empty | Attack destination; keeps only host, protocol and port |
| Delay | 0, 50, 100, 250, 500, 750, 1000 ms | 0 (no delay) | Fixed wait before starting the next attempt (accepts 0 to 60000) |
| Requests per second | 0, 1, 2, 3, 5, 10, 20 | 0 (free) | Rate cap; 0 does not limit and honors only the delay (accepts 0 to 1000) |
| Ignore certificate errors | On, Off | Off (strict TLS) | Accepts invalid or self-signed TLS certificates |
To configure the target, paste the host or URL into the MAIN TARGET field; if you paste a URL with protocol and port, the Intruder adjusts the buttons and the field automatically. Choose HTTPS or HTTP — when you switch, the default port (443/80) is filled in when the field is empty or holds the other protocol's default port. Leave Ignore certificate errors off on public targets; turn it on only in test environments with your own certificate.
To adjust the pace, think of two stacked brakes. The delay guarantees a minimum pause after each send; use larger values (250 to 1000 ms) on sensitive targets. The requests per second cap the peak: at 5 REQ/S, the Intruder spaces the sends to at most five per second. At 0 (free), there is no rate cap and the only brake is the delay plus the natural response time.
Payload source: wordlist and dynamic generator #
On the PAYLOADS tab, choose WORDLIST to use a ready list or DYNAMIC GENERATOR to build a sequence. With WORDLIST selected, tap WORDLIST to open the INTRUDER WORDLIST picker: the built-in lists appear first and yours, created in the settings, right below. The picker refreshes the lists every time it opens.
The dynamic generator builds numbers over a range. The fields are:
| Field | Values | Default | What it does |
|---|---|---|---|
| Start | integer | 1 | First number in the sequence |
| End | integer greater than or equal to the start | 25 | Last number (inclusive) |
| Step | integer greater than 0 | 1 | Increment from one number to the next |
| Padding | integer | 0 | Left-pads with zeros up to this width (0 disables) |
| Prefix | text | empty | Fixed text before the number |
| Suffix | text | empty | Fixed text after the number |
The Current estimate line shows how many payloads the configuration will generate. The total is ((end - start) / step) + 1. With Start 1, End 5, Step 1 and Padding 3, the sequence is 001, 002, 003, 004, 005; with Prefix user-, it becomes user-001… user-005.
Distribution and combination modes #
With two or more marked positions, the mode decides how the lists cross. The estimated total appears on the Combinations tile.
| Mode | What it does | Estimated total |
|---|---|---|
| Per marker | One list, one marker at a time (the others keep the original value) | Sum of the sizes |
| All markers | The same item in all markers at once | Size of the first list |
| Aligned | One list per marker, by the same index | Smallest size among the lists |
| Combinations | Cartesian product of all lists | Product of the sizes |
All markers is the default. Combinations has a cap of 10,000 combinations; above that the attack is blocked to avoid huge runs. In Aligned and Combinations modes with two or more markers, the per-marker source chips appear, letting you use a different list in each position; without an override, each marker uses the global source.
Payload processors and the transformation chain #
In the PROCESSORS section, tap the add button and pick a step. Each chip can be reordered (up/down) or removed; the chain is applied in order.
| Processor | Options | What it does |
|---|---|---|
| URL | — | Encodes the payload in percent-encoding |
| BASE64 | — | Encodes the payload in Base64 |
| JSON | — | Escapes the payload as a JSON string |
| HASH | MD5, SHA-1, SHA-256, SHA-512 | Replaces the payload with its hash |
| AFFIXES | prefix, suffix | Adds text before and/or after the payload |
| CASE | UPPERCASE, LOWERCASE, INVERT | Changes letter case |
| UNICODE | — | Escapes non-ASCII characters as \uXXXX |
Buttons and actions #
| Button | Where | What it does |
|---|---|---|
| AUTO-DETECT | REQUEST tab | Detects and marks query, form and JSON fields |
| MARK SELECTION | REQUEST tab | Marks the selected span in the editor as a position |
| CLEAR | REQUEST tab | Removes all markers from the request |
| WORDLIST / DYNAMIC GENERATOR | PAYLOADS tab | Switches the payload source |
| WORDLIST (picker) | PAYLOADS tab | Opens the list of built-in and user wordlists |
| Add processor | PAYLOADS tab | Appends a transformation step to the chain |
| VIEW FLOW | Preparation | Opens the results page |
| START INTRUSION | Preparation | Sends the probe and fires the attack |
| PAUSE / RESUME | During the run | Pauses and resumes without losing progress |
| STOP INTRUSION | During the run | Ends the running session |
| FILTERS | Flow | Opens the trimming and filtering panel |
| CLEAR (filters) | Flow | Removes all active filters |
| Long-press a result | Flow | Opens the copy and send-to-Repeater menu |
The result menu (long-press) offers: Send to the Repeater, Copy URL, Copy request, Copy headers, Copy body, Copy response, Copy payload and Copy cURL.
Step by step #
1. Send a request and mark automatically #
- In the Interceptor or the Repeater, use Send to the Intruder.
- The Intruder opens with the request already pasted and tries to mark the fields. Check the
P1,P2… chips in CURRENT MARKERS. - If something was missed, select the span in the editor and tap MARK SELECTION. To start over, tap CLEAR and then AUTO-DETECT.
2. Attack with a wordlist on one position #
- On the TARGET tab, confirm host, protocol and port.
- On the REQUEST tab, mark the position (a single marker).
- On the PAYLOADS tab, keep WORDLIST, tap the picker and choose the list.
- Adjust the pace on the TARGET tab (for example
DELAY 250 MSand5 REQ/S). - Tap START INTRUSION and watch the ATTACK LOG on the flow page.
3. Dynamic generator with processors #
- Mark the position that takes the number (for example
id=in the body or query). - On the PAYLOADS tab, choose DYNAMIC GENERATOR and fill in Start, End, Step and Padding.
- Check the Current estimate.
- Under PROCESSORS, add the steps you need (for example
AFFIXESand thenBASE64). - Start the attack.
4. Two positions with Aligned or Combinations modes #
- Mark two positions (for example username and password).
- On the PAYLOADS tab, choose the mode: Aligned to test pairs by index, Combinations to cross everything.
- Use the per-marker source chips to give one list to each position.
- Check the estimate (remember the 10,000 cap in Combinations) and start.
5. Trim and filter the results #
- On the flow page, tap FILTERS.
- Under TRIM, turn on DIFFERENT to see only what changed from the probe, or SIZE and enter the
|delta| min.. - For text, turn on GREP (keep what matches) or EXTRACT (pull a group) and type the regex.
- Under METHOD AND STATUS, select codes like
200or classes like client/server. - Tap APPLY; the button shows how many results remain. Use CLEAR to return to the full list.
Examples #
Base request before marking, with an ID field in the query:
GET /api/orders?id=1024 HTTP/1.1
Host: target.example
Accept: application/jsonAfter AUTO-DETECT, the value of id is wrapped by the marker pair (the position shows up as P1):
GET /api/orders?id=§1024§ HTTP/1.1
Host: target.example
Accept: application/jsonDynamic-generator sequence with Start 1, End 5, Step 1, Padding 3 and Prefix user-:
user-001
user-002
user-003
user-004
user-005Request actually sent in one of the runs, with the payload in place of the marker:
GET /api/orders?id=1031 HTTP/1.1
Host: target.example
Accept: application/jsonCommon problems and FAQ #
The attack does not start and I am sent back to the PAYLOADS tab. There are no valid payloads: choose a wordlist with lines or check the generator (End must be greater than or equal to Start). Blank lines are ignored.
I typed the marker in the editor and it did not work. In the Intruder the marker is not typed. Select the span and use MARK SELECTION, or AUTO-DETECT. The literal $CAT$ token belongs to the Discoverer.
Combinations got blocked. The product of the lists exceeded 10,000. Reduce the lists, switch to Aligned or use Per marker.
All results disappear when I filter. Some filter is too strict (a regex that does not match, a high delta, a narrow status). Tap CLEAR in the filters panel and refine little by little.
I keep getting certificate errors. In a test environment with your own certificate, turn on Ignore certificate errors. In production, keep TLS strict and investigate the certificate.
I closed the app mid-attack. The session is saved to disk: when you reopen the Intruder, request, markers, payloads and results come back, and you can RESUME.
Best practices and security #
- Prefer the smallest volume that answers your question; do not test the whole range when a sample is enough.
- Use delay and a requests-per-second cap on third-party targets.
- Always compare against the probe: a size or status delta outside the pattern is more informative than the raw list.
- Forward the interesting results to the Repeater and dig into them one by one.