Skip to content
CatSuite

Language

Choose whether the site follows your browser or always uses Brazilian Portuguese or English.

Get it free

Modules

Repeater

Complete guide to the CatSuite Repeater module: how to use the highlighted HTTP editor, header autocomplete, resend, compare responses and configure SSL/TLS.

12 min read

The Repeater is CatSuite's manual traffic module. It combines an HTTP editor with syntax highlighting, header autocomplete, unlimited resending of the same request, a side-by-side response comparison mode and per-send SSL/TLS control. It is the ideal workbench to change one field at a time, fire again and understand the exact effect of each adjustment on the target's behavior. This page explains what each feature does, how to configure the module and how to use the Repeater in real authorized testing flows.

What the Repeater module is and what it is for #

The Repeater receives a raw request — from the Interceptor, the Browser, History, the Discoverer or an Intruder result — and lets you edit it freely in raw form (request line, headers and body). Each time you tap SEND, the module fires the request and keeps the full response, with status, time, size and content type. You can resend as many times as you want, step back and forward through the edit history and turn on comparison mode to measure the difference between two variations.

The screen header makes the module's intent clear: the MANUAL TRAFFIC tag, the REPEATER title and the summary "Edit, review versions and compare responses."

Core Repeater concepts #

Before opening the screen, it helps to fix the terms that appear in buttons, chips and settings.

Raw request and the HTTP editor with syntax highlighting #

The raw request is the HTTP text exactly as it goes on the wire: the request line (METHOD target HTTP/1.1), the headers (one per line, in Name: value form), a blank line and finally the body. The Repeater editor applies syntax highlighting to that text: the method is shown in yellow, the HTTP/… version in gray, the target in blue, header names in cyan, the colons in light gray and the values in green. The Intruder payload markers, in the §chunk§ form, appear highlighted on a cyan background, which lets you prepare positions without leaving the Repeater.

Header autocomplete #

When you are on a header line that does not yet have a colon, the Repeater shows HEADER SUGGESTIONS chips with the most common headers (Authorization, Content-Type, User-Agent, Accept, Cookie, Origin, Referer and others). Tapping a chip inserts the header name and the : on the current line, with the cursor ready for the value. The list is filtered by what you typed: start writing Au and only the headers that begin with that prefix appear.

Manual resending and edit history #

Each send is a manual, independent fire. The editor keeps an edit history of the request: the back and forward arrows walk through the versions you have typed (the panel subtitle shows history N/total), working like request-specific undo and redo. This way you try a variation, fire it, go back to the previous text and try another, without losing the path you took.

Response comparison mode (A/B) #

With comparison mode on, a separate request B appears. You keep request A intact, edit B as a variation and compare request and response in a table: method, host, target, header count (and how many differ), body size and changed lines; and, for the responses, status, time, size, content type and whether the body ended up the same or different.

Per-send SSL/TLS control #

The Repeater lets you decide, per send, how to treat the transport layer. With SSL/TLS on, the HTTPS send negotiates TLS normally; off, the send forces HTTP even if the original target was on HTTPS. There is also the option to ignore certificate errors, useful in the lab when the target presents an invalid or self-signed certificate. For a dedicated inspection of certificate, chain and protocol, use the SSL/TLS Analyzer.

View modes: Raw, Hex and Render #

Both the request and the response have a view switcher. RAW shows the editable text (on the request) or the full response with status, headers and body (on the response). HEX shows a read-only hexadecimal dump. RENDER, available only on the response, does a local render for HTML and shows a formatted tree for JSON.

TermWhat it isWhere it appears
Raw requestRaw HTTP text, editable line by lineREQUEST panel
Syntax highlightingColors by method, header, value and markerRAW editor
AutocompleteCommon header chips on the current lineREQUEST panel
A/B comparisonSeparate request B and difference tableA/B COMPARISON panel
Per-send SSL/TLSTLS and certificate switchesSettings

The Repeater screen: panels, tabs and modes #

The screen is a scrollable column with four main blocks, from top to bottom.

Manual execution card #

The first card, MANUAL EXECUTION, holds the fire controls: the SEND button, the CLEAR button and the settings icon that opens the configuration. During a send, SEND becomes CANCEL (and CANCELING while the interruption completes).

REQUEST panel #

The REQUEST panel holds the editor of the main request. At the top there are summary chips (METHOD, HOST, TARGET and BODY size), the history arrows, the RAW/HEX switcher, the COPY button and, when it makes sense, the header suggestion chips. If the first line does not yet have method, target and HTTP/1.1, the panel shows a notice explaining what is missing instead of the technical summary.

A/B comparison panel #

When comparison mode is on, the A/B COMPARISON panel appears between the request and the response. It shows a B READY or B EMPTY badge, the REQUEST and RESPONSE summary tables, the comparison action buttons, the request B chips and the REQUEST B editor.

RESPONSE panel #

The RESPONSE panel shows the response of the last send. It brings STATUS, TIME, SIZE and TYPE chips, the RAW/HEX/RENDER switcher, the COPY button and, when CatSuite detects formats in the body (JWT, Base64, JSON and the like), a DETECTED CONTENT strip with chips that open the decode of that chunk.

Repeater options and how to configure them #

Tap the settings icon on the execution card to open the REPEATER SETTINGS sheet ("Configure the editor, SSL/TLS and the cURL export."). The switches are persistent: CatSuite keeps your choice across sessions.

OptionValuesDefaultWhat it does
Header autocompleteOn / OffOnSuggests Authorization, Content-Type, User-Agent and other common headers while you type a header name.
HTTP colorsOn / OffOnTurns the visual highlight of method, request line, headers and values on or off in the editor.
Enable SSL/TLSOn / OffOnWhen off, the send forces HTTP even if the original target is on HTTPS.
Ignore certificate errorsOn / OffOffAccepts invalid certificates during the HTTPS send; only available with SSL/TLS on.
Keep default template on clearOn / OffOnSets whether CLEAR returns to the GET exemplo.com template or leaves the editor empty.
Comparison modeOn / OffOffShows a separate request B to compare variations without overwriting the main request.

To adjust each one: keep Header autocomplete on while building requests from scratch and turn it off if the chips get in the way of typing. HTTP colors is only visual comfort — turn it off if you prefer monochrome text. Enable SSL/TLS should stay on for real HTTPS targets; turn it off only to force HTTP in lab tests. Ignore certificate errors should be used only in your own authorized environment, because it disables a transport protection. Keep default template on clear is a productivity preference. And Comparison mode you turn on when you want to measure two variations in parallel.

At the bottom of the sheet there is the EXPORT AS cURL button, which generates the curl command equivalent to the current request (respecting the SSL/TLS choice) and copies it to the clipboard.

Repeater buttons and actions #

Execution card buttons #

ButtonWhat it does
SENDFires request A. During the send it becomes CANCEL; while interrupting, it shows CANCELING.
CLEAREmpties the response and the editor, respecting the "Keep default template on clear" option.
Settings iconOpens the REPEATER SETTINGS sheet.

REQUEST panel buttons #

ButtonWhat it does
Back arrowGoes back one version in the request edit history (undo).
Forward arrowGoes forward one version in the edit history (redo).
RAW / HEXSwitches the editor between editable raw text and a read-only hexadecimal dump.
COPYCopies the current request to the clipboard.
Header suggestion chipInserts the chosen header on the current line, ready for the value.

A/B comparison buttons #

ButtonWhat it does
USE A AS BCopies request A into the request B field.
SWAP A/BSwaps requests A and B (and their fallback URLs).
SEND B / CANCEL BFires request B; during the send it becomes CANCEL B.
COPY BCopies request B.
CLEAR BResets request B and its response.

Editor context menu #

When you select text in the editor, a Repeater-specific action bar appears.

ActionWhat it does
COPYCopies the selection.
PASTEPastes the clipboard content (only in the editable editor).
DECODESends the selection to the Decoder.
NOTESSends the selection to the Notepad.
ALLSelects the whole text of the block.
REQUEST / RESPONSECopies the entire block (request or response).

Step by step: how to use the Repeater #

Resend a request several times #

  1. Send a request to the Repeater from the Interceptor, History or another module.
  2. Check the METHOD, HOST and TARGET chips and adjust the raw request in the editor.
  3. Tap SEND and read the STATUS, TIME, SIZE and TYPE chips in the RESPONSE panel.
  4. Change one field, fire again and use the history arrows to compare with the previous version.

Compare two responses side by side #

  1. Open the settings and turn on Comparison mode.
  2. In the A/B COMPARISON panel, tap USE A AS B to clone the current request or paste a second full request into the REQUEST B editor.
  3. Edit request B with the variation you want to test.
  4. Tap SEND (A) and SEND B and read the summary tables to see where A and B diverge in status, size, type and body lines.

Adjust the SSL/TLS of a send #

  1. Open the Repeater settings.
  2. For a real HTTPS target, keep Enable SSL/TLS on.
  3. In a lab with an invalid certificate, turn on Ignore certificate errors.
  4. To test the behavior without TLS, turn off Enable SSL/TLS and resend; the module then uses HTTP.

Take the request to the Intruder #

  1. In the editor, mark the payload positions by wrapping the chunk with the § delimiter, in the §value§ form. The markers are highlighted on a cyan background.
  2. Check the result — the Repeater shows where each marker falls in the request.
  3. Forward the request to the Intruder using the "Send to the Intruder" shortcut available in the Interceptor, or copy the request and paste it into the Intruder editor.
  4. In the Intruder, use AUTODETECT or MARK SELECTION to confirm the positions and configure the attack.

Request examples #

A simple GET request in raw form, same as the module's initial template.

Raw GET requestHTTP
GET / HTTP/1.1
Host: exemplo.com
User-Agent: Cat Suite
Accept: */*

A POST request with a JSON body. Note the blank line separating the headers from the body.

POST request with JSON bodyHTTP
POST /api/login HTTP/1.1
Host: exemplo.com
Content-Type: application/json
Accept: application/json

{"user":"alice","password":"change"}

A request with a position marked for the Intruder using the § delimiter.

Position marked for the IntruderHTTP
GET /account/§id§ HTTP/1.1
Host: exemplo.com
User-Agent: Cat Suite

The command generated by the EXPORT AS cURL action.

cURL export exampleShell
curl --request GET 'https://exemplo.com/' --header 'User-Agent: Cat Suite' --header 'Accept: */*'

Common problems and frequently asked questions (FAQ) #

The send says "Paste a valid request to send". The editor is empty. Paste or type a complete raw request before tapping SEND.

The technical summary does not appear. The first line needs method, target and HTTP/1.1, and the request needs a Host header (or a full URL on the first line). The panel shows exactly what is missing.

The send failed with a TLS error. The target may have an invalid certificate or an incompatible protocol. In an authorized environment, turn on Ignore certificate errors; to diagnose the connection, use the SSL/TLS Analyzer.

I canceled the send by mistake. The module shows "Send canceled." and keeps the request intact. Just tap SEND again.

I need to test many variations. The Repeater is for manual replay. To walk through payload lists automatically, take the request to the Intruder with the Wordlists.

Request B disappeared when another module sent a new request. Request B stays separate from the main one and remains intact: the imported request replaces only A.

Next step #