# Intruder

> CatSuite Intruder: how to use and configure payload markers, wordlists, generators, payload processors, attack pacing and result filtering by status and size.

- Language: en
- Canonical URL: https://netcattest.com/catsuite/en/docs/modules/intruder
- Section: Modules
- Updated: 2026-10-06
- Other language (pt-BR): https://netcattest.com/catsuite/docs/modulos/intruso

The **Intruder** is CatSuite's request automation module: it takes a **base request**, replaces the **marked positions** with each **payload** from a wordlist or a generator, fires the sends at the pace you set and keeps every response for you to **trim and filter**. It is the right tool for value enumeration, parameter testing, controlled fuzzing and behavior checks whenever you need to repeat the same request dozens or thousands of times changing only one piece. This page explains each concept, each option and how to configure the Intruder step by step, always against an authorized target.

> [!WARNING]
> The Intruder generates real automated traffic. Use it only against systems you have written authorization to test and keep the pace responsible. See [Security and responsible use](https://netcattest.com/catsuite/en/docs/security).

## What the Intruder is and what it is for

The Intruder solves a simple repetition problem: instead of editing and resending a request by hand in the [Repeater](https://netcattest.com/catsuite/en/docs/modules/repeater), you mark **where** the value changes, choose **which** values to test and let the module walk the whole list. Each send becomes a row in the **attack log**, with status, size and time, ready for comparison.

Typical use cases:

- Enumerate sequential identifiers (for example `id=1` to `id=500`) to check access control.
- Test a list of usernames, paths or parameters against an endpoint.
- Vary the value of a header or form field and watch how the response changes.
- Measure size and time differences between the normal response (the **probe**) and each variation.

The Intruder is a **local HTTP client**: it builds and sends the requests from the device itself, with no intermediate servers. The session history is saved in the app storage, so you can **pause and resume** without losing progress.

## Essential Intruder concepts

Before you configure anything, it helps to understand the terms on screen. Each concept below maps directly to a button or panel in the module.

### Payload markers: marking the positions

A **payload marker** indicates the exact point in the request where each value from your list will go. In the Intruder you do **not** type the marker by hand: the **AUTO-DETECT** and **MARK SELECTION** buttons wrap the chosen span in a **pair of markers**, and each position then shows up as a `P1`, `P2`, `P3`… chip in the **CURRENT MARKERS** list. In the editor, the marked span is highlighted between the delimiter pair (`§value§`).

> [!NOTE]
> The payload marker is the same idea as the `$CAT$` token that the [Discoverer](https://netcattest.com/catsuite/en/docs/modules/discoverer) uses literally in the URL. The difference is that in the Intruder the marker is inserted by the buttons around an existing span, instead of typed. To remove all markers, use **CLEAR** on the REQUEST tab.

Auto-detection understands three field formats:

- **Query string** in the URL (`?key=value&key2=value2`).
- **Form** `application/x-www-form-urlencoded` in the body (`field=value`).
- **JSON** in the body (it marks the values of each `"key": value` pair).

### Wordlists and payload generators

The values that go into the positions come from one of two **sources**:

- **Wordlist** — a list of lines, built in or imported by you. The built-in lists and the ones created in the app settings appear in the **INTRUDER WORDLIST** picker. Importing, the `.txt` format and validation are covered in [Wordlists and payloads](https://netcattest.com/catsuite/en/docs/modules/wordlists).
- **Dynamic generator** — builds a numeric sequence on the fly, from a range and affixes. Useful when you do not have a file, only a range (for example `user-001` to `user-250`).

### Distribution modes

When there is **more than one marked position**, the **distribution mode** decides how the lists are combined across the markers. There are four modes, each with a different total estimate, detailed in the **Distribution and combination modes** table below.

### Payload processors

A **processor** is a transformation applied to each payload **before** the send. You build a **chain** of steps (URL encoding, Base64, hashing, case change, Unicode escaping, affixes) and the steps are applied **in the order** they appear. It is the same mechanism as the [Decoder](https://netcattest.com/catsuite/en/docs/modules/decoder), reused to prepare the values at attack time.

### Probe and baseline

On start, the Intruder first sends the request **without markers** — the **probe**. The probe response becomes the **baseline** against which each variation is compared. From it the module computes, for each result:

- **Size delta** — the difference, in bytes, between the response and the probe.
- **Similarity** — a 0 to 100 index (by bigrams) between the response body and the probe body.
- **Different from probe** — whether the body equals or differs from the baseline.

### Result trimming and filtering

**Trimming** and **filtering** refine what the log shows, without resending anything. You can filter by **status**, **size**, **time**, search for **words** anywhere in the result and apply **GREP** (keep what matches a pattern) or **EXTRACT** (pull a span of the response via regex).

### Pacing and session

**Pacing** combines two options: the **delay** (fixed wait between attempts) and the **requests per second** (rate cap). The Intruder honors the larger interval of the two. The **session** is persisted to disk, so pausing, leaving and coming back keeps request, markers, payloads and results.

## The Intruder screen: pages, tabs and panels

The Intruder has two pages: **Preparation** (where you build the attack) and **Flow** (where you follow the results). You switch between them with **VIEW FLOW** and with the back button on the flow page.

### Preparation page

Preparation is split into three tabs at the top: **TARGET**, **REQUEST** and **PAYLOADS**. The REQUEST tab shows a counter with the number of active markers.

### TARGET tab

Defines the destination and the network. The **MAIN TARGET** field accepts a host (`target.example`) or a full URL — the Intruder keeps only **host, protocol and port**, discarding path, query and extra slashes. Below it are the **PROTOCOL** (HTTPS/HTTP), the **PORT**, the **DELAY**, the **REQUESTS PER SECOND** and the **TLS tolerance** switch. The chips at the top summarize the current setup (target, delay, pace and strict/flexible TLS).

### REQUEST tab

Holds the base-request editor and the marking actions: **AUTO-DETECT**, **MARK SELECTION** and **CLEAR**. Right below, **CURRENT MARKERS** lists the `P1`, `P2`… chips and a **preview** with the positions highlighted. When the request arrives imported from the [Interceptor](https://netcattest.com/catsuite/en/docs/modules/interceptor) or the [Repeater](https://netcattest.com/catsuite/en/docs/modules/repeater), the Intruder already tries to mark the fields automatically.

### PAYLOADS tab

Gathers, in this order: the **distribution-mode tiles**; (when there are two or more markers in Aligned or Combinations mode) the **per-marker source chips**; the **PAYLOAD SOURCE** choice (WORDLIST or DYNAMIC GENERATOR); the configuration of the chosen source; and the **PROCESSORS**.

### Flow page (results)

Shows three counters — **PROCESSED**, **RESPONSES** and **FAILURES** — and the **ATTACK LOG**. Each result is a card with the run `#`, status, size, time, the payload and a snippet of the response. The **FILTERS** button opens the trimming panel; **CLEAR** resets the active filters. Long-press a result to open the copy and send menu.

## Intruder options and how to configure them

The table below gathers the target, network and pacing options on the TARGET tab.

| Option | Values | Default | What it does |
| --- | --- | --- | --- |
| Protocol | HTTPS, HTTP | HTTPS | Sets the send scheme and suggests the port (443 or 80) |
| Port | 1 to 65535 | 443 (HTTPS) / 80 (HTTP) | Destination port; drops from the `Host` header when it is the protocol default |
| Main target | host or URL | empty | Attack destination; keeps only host, protocol and port |
| Delay | 0, 50, 100, 250, 500, 750, 1000 ms | 0 (no delay) | Fixed wait before starting the next attempt (accepts 0 to 60000) |
| Requests per second | 0, 1, 2, 3, 5, 10, 20 | 0 (free) | Rate cap; 0 does not limit and honors only the delay (accepts 0 to 1000) |
| Ignore certificate errors | On, Off | Off (strict TLS) | Accepts invalid or self-signed TLS certificates |

To **configure the target**, paste the host or URL into the MAIN TARGET field; if you paste a URL with protocol and port, the Intruder adjusts the buttons and the field automatically. Choose **HTTPS** or **HTTP** — when you switch, the default port (443/80) is filled in when the field is empty or holds the other protocol's default port. Leave **Ignore certificate errors** off on public targets; turn it on only in test environments with your own certificate.

To **adjust the pace**, think of two stacked brakes. The **delay** guarantees a minimum pause after each send; use larger values (250 to 1000 ms) on sensitive targets. The **requests per second** cap the peak: at `5 REQ/S`, the Intruder spaces the sends to at most five per second. At `0` (free), there is no rate cap and the only brake is the delay plus the natural response time.

> [!TIP]
> When both are active, the larger interval wins. `DELAY 500 MS` with `5 REQ/S` results in one send every 500 ms, because 500 ms is greater than the 200 ms required by 5 req/s.

### Payload source: wordlist and dynamic generator

On the PAYLOADS tab, choose **WORDLIST** to use a ready list or **DYNAMIC GENERATOR** to build a sequence. With WORDLIST selected, tap **WORDLIST** to open the **INTRUDER WORDLIST** picker: the built-in lists appear first and yours, created in the settings, right below. The picker refreshes the lists every time it opens.

The **dynamic generator** builds numbers over a range. The fields are:

| Field | Values | Default | What it does |
| --- | --- | --- | --- |
| Start | integer | 1 | First number in the sequence |
| End | integer greater than or equal to the start | 25 | Last number (inclusive) |
| Step | integer greater than 0 | 1 | Increment from one number to the next |
| Padding | integer | 0 | Left-pads with zeros up to this width (0 disables) |
| Prefix | text | empty | Fixed text before the number |
| Suffix | text | empty | Fixed text after the number |

The **Current estimate** line shows how many payloads the configuration will generate. The total is `((end - start) / step) + 1`. With Start `1`, End `5`, Step `1` and Padding `3`, the sequence is `001, 002, 003, 004, 005`; with Prefix `user-`, it becomes `user-001`… `user-005`.

### Distribution and combination modes

With two or more marked positions, the mode decides how the lists cross. The estimated total appears on the Combinations tile.

| Mode | What it does | Estimated total |
| --- | --- | --- |
| Per marker | One list, one marker at a time (the others keep the original value) | Sum of the sizes |
| All markers | The same item in all markers at once | Size of the first list |
| Aligned | One list per marker, by the same index | Smallest size among the lists |
| Combinations | Cartesian product of all lists | Product of the sizes |

**All markers** is the default. **Combinations** has a cap of **10,000** combinations; above that the attack is blocked to avoid huge runs. In **Aligned** and **Combinations** modes with two or more markers, the **per-marker source chips** appear, letting you use a different list in each position; without an override, each marker uses the global source.

### Payload processors and the transformation chain

In the **PROCESSORS** section, tap the add button and pick a step. Each chip can be reordered (up/down) or removed; the chain is applied **in order**.

| Processor | Options | What it does |
| --- | --- | --- |
| URL | — | Encodes the payload in percent-encoding |
| BASE64 | — | Encodes the payload in Base64 |
| JSON | — | Escapes the payload as a JSON string |
| HASH | MD5, SHA-1, SHA-256, SHA-512 | Replaces the payload with its hash |
| AFFIXES | prefix, suffix | Adds text before and/or after the payload |
| CASE | UPPERCASE, LOWERCASE, INVERT | Changes letter case |
| UNICODE | — | Escapes non-ASCII characters as `\uXXXX` |

> [!TIP]
> Order matters. `AFFIXES` after `BASE64` adds the text to the already encoded value; before it, it encodes the text together with the affixes. Build the chain around the format the target expects.

## Buttons and actions

| Button | Where | What it does |
| --- | --- | --- |
| AUTO-DETECT | REQUEST tab | Detects and marks query, form and JSON fields |
| MARK SELECTION | REQUEST tab | Marks the selected span in the editor as a position |
| CLEAR | REQUEST tab | Removes all markers from the request |
| WORDLIST / DYNAMIC GENERATOR | PAYLOADS tab | Switches the payload source |
| WORDLIST (picker) | PAYLOADS tab | Opens the list of built-in and user wordlists |
| Add processor | PAYLOADS tab | Appends a transformation step to the chain |
| VIEW FLOW | Preparation | Opens the results page |
| START INTRUSION | Preparation | Sends the probe and fires the attack |
| PAUSE / RESUME | During the run | Pauses and resumes without losing progress |
| STOP INTRUSION | During the run | Ends the running session |
| FILTERS | Flow | Opens the trimming and filtering panel |
| CLEAR (filters) | Flow | Removes all active filters |
| Long-press a result | Flow | Opens the copy and send-to-Repeater menu |

The result menu (long-press) offers: **Send to the Repeater**, **Copy URL**, **Copy request**, **Copy headers**, **Copy body**, **Copy response**, **Copy payload** and **Copy cURL**.

## Step by step

### 1. Send a request and mark automatically

1. In the [Interceptor](https://netcattest.com/catsuite/en/docs/modules/interceptor) or the [Repeater](https://netcattest.com/catsuite/en/docs/modules/repeater), use **Send to the Intruder**.
2. The Intruder opens with the request already pasted and tries to mark the fields. Check the `P1`, `P2`… chips in CURRENT MARKERS.
3. If something was missed, select the span in the editor and tap **MARK SELECTION**. To start over, tap **CLEAR** and then **AUTO-DETECT**.

### 2. Attack with a wordlist on one position

1. On the **TARGET** tab, confirm host, protocol and port.
2. On the **REQUEST** tab, mark the position (a single marker).
3. On the **PAYLOADS** tab, keep **WORDLIST**, tap the picker and choose the list.
4. Adjust the pace on the TARGET tab (for example `DELAY 250 MS` and `5 REQ/S`).
5. Tap **START INTRUSION** and watch the **ATTACK LOG** on the flow page.

### 3. Dynamic generator with processors

1. Mark the position that takes the number (for example `id=` in the body or query).
2. On the PAYLOADS tab, choose **DYNAMIC GENERATOR** and fill in Start, End, Step and Padding.
3. Check the **Current estimate**.
4. Under **PROCESSORS**, add the steps you need (for example `AFFIXES` and then `BASE64`).
5. Start the attack.

### 4. Two positions with Aligned or Combinations modes

1. Mark **two** positions (for example username and password).
2. On the PAYLOADS tab, choose the mode: **Aligned** to test pairs by index, **Combinations** to cross everything.
3. Use the **per-marker source chips** to give one list to each position.
4. Check the estimate (remember the 10,000 cap in Combinations) and start.

### 5. Trim and filter the results

1. On the flow page, tap **FILTERS**.
2. Under **TRIM**, turn on **DIFFERENT** to see only what changed from the probe, or **SIZE** and enter the `|delta| min.`.
3. For text, turn on **GREP** (keep what matches) or **EXTRACT** (pull a group) and type the regex.
4. Under **METHOD AND STATUS**, select codes like `200` or classes like client/server.
5. Tap **APPLY**; the button shows how many results remain. Use **CLEAR** to return to the full list.

## Examples

Base request before marking, with an ID field in the query:

```http
GET /api/orders?id=1024 HTTP/1.1
Host: target.example
Accept: application/json
```

After **AUTO-DETECT**, the value of `id` is wrapped by the marker pair (the position shows up as `P1`):

```http
GET /api/orders?id=§1024§ HTTP/1.1
Host: target.example
Accept: application/json
```

Dynamic-generator sequence with Start 1, End 5, Step 1, Padding 3 and Prefix `user-`:

```text
user-001
user-002
user-003
user-004
user-005
```

Request actually sent in one of the runs, with the payload in place of the marker:

```http
GET /api/orders?id=1031 HTTP/1.1
Host: target.example
Accept: application/json
```

## Common problems and FAQ

**The attack does not start and I am sent back to the PAYLOADS tab.** There are no valid payloads: choose a wordlist with lines or check the generator (End must be greater than or equal to Start). Blank lines are ignored.

**I typed the marker in the editor and it did not work.** In the Intruder the marker is not typed. Select the span and use **MARK SELECTION**, or **AUTO-DETECT**. The literal `$CAT$` token belongs to the [Discoverer](https://netcattest.com/catsuite/en/docs/modules/discoverer).

**Combinations got blocked.** The product of the lists exceeded 10,000. Reduce the lists, switch to **Aligned** or use **Per marker**.

**All results disappear when I filter.** Some filter is too strict (a regex that does not match, a high delta, a narrow status). Tap **CLEAR** in the filters panel and refine little by little.

**I keep getting certificate errors.** In a test environment with your own certificate, turn on **Ignore certificate errors**. In production, keep TLS strict and investigate the certificate.

**I closed the app mid-attack.** The session is saved to disk: when you reopen the Intruder, request, markers, payloads and results come back, and you can **RESUME**.

> [!IMPORTANT]
> Always start with a small list and a low pace to validate the markers and the probe response. Only then scale up the volume. This avoids firing thousands of requests over a marking mistake.

## Best practices and security

> [!DANGER]
> High-volume automation can take a service down. Fire the Intruder only against targets you are authorized to test and agree on the pace with the system owner.

- Prefer the smallest volume that answers your question; do not test the whole range when a sample is enough.
- Use delay and a requests-per-second cap on third-party targets.
- Always compare against the **probe**: a size or status delta outside the pattern is more informative than the raw list.
- Forward the interesting results to the [Repeater](https://netcattest.com/catsuite/en/docs/modules/repeater) and dig into them one by one.

## Next step

- [Wordlists and payloads](https://netcattest.com/catsuite/en/docs/modules/wordlists)
- [Discoverer](https://netcattest.com/catsuite/en/docs/modules/discoverer)
- [Repeater](https://netcattest.com/catsuite/en/docs/modules/repeater)
- [Interceptor](https://netcattest.com/catsuite/en/docs/modules/interceptor)
- [Security and responsible use](https://netcattest.com/catsuite/en/docs/security)
