Run checks in the background or scan specific requests on demand to find issues like reflected XSS, SQL injection, and CORS misconfigurations.
All checks are open source. Add your own and help the list grow 💪
Run checks in the background or scan specific requests on demand to find issues like reflected XSS, SQL injection, and CORS misconfigurations.
All checks are open source. Add your own and help the list grow 💪
Introducing "Chatio" by @amrelsagaei
Ask AI questions with prompt templates, files, code or screenshots. You can also hit CTRL + SPACE to edit requests, create filters and more using natural language.
Check out more details: github.com/amrelsagaei/...
Introducing "Chatio" by @amrelsagaei
Ask AI questions with prompt templates, files, code or screenshots. You can also hit CTRL + SPACE to edit requests, create filters and more using natural language.
Check out more details: github.com/amrelsagaei/...
Introducing "NewRequests" by @ntrm.bsky.social
Identify which requests follow a certain action by filtering out the HTTP History table with a hotkey.
Check out more details: github.com/martinhaunsc...
Introducing "NewRequests" by @ntrm.bsky.social
Identify which requests follow a certain action by filtering out the HTTP History table with a hotkey.
Check out more details: github.com/martinhaunsc...
Introducing "Notes++" by _StaticFlow_ and bebiksior.
Markdown-powered notes within Caido! Embed replay sessions and insert selected text directly into your notes.
Check out more details: github.com/caido-commun...
Introducing "Notes++" by _StaticFlow_ and bebiksior.
Markdown-powered notes within Caido! Embed replay sessions and insert selected text directly into your notes.
Check out more details: github.com/caido-commun...
Introducing "Exploit Generator" by @stealthcopter
Generate executable proof-of-concept (PoC) code from intercepted requests, in multiple languages and frameworks, such as Python, JavaScript, and Bash/cURL.
Check out more details: github.com/stealthcopte...
Introducing "Exploit Generator" by @stealthcopter
Generate executable proof-of-concept (PoC) code from intercepted requests, in multiple languages and frameworks, such as Python, JavaScript, and Bash/cURL.
Check out more details: github.com/stealthcopte...
Introducing "Drop" by @Rhynorater
Get connected to your collaborator’s instance and share objects back and forth such as Replay tabs, M&R rules, scopes and filters.
Check out more details: github.com/caido-commun...
Introducing "Drop" by @Rhynorater
Get connected to your collaborator’s instance and share objects back and forth such as Replay tabs, M&R rules, scopes and filters.
Check out more details: github.com/caido-commun...
Introducing "JWT Analyzer" by @amrelsagaei
Detect, inspect, and test JSON Web Tokens for vulnerabilities during live traffic analysis.
Check out more details: github.com/amrelsagaei/...
Introducing "JWT Analyzer" by @amrelsagaei
Detect, inspect, and test JSON Web Tokens for vulnerabilities during live traffic analysis.
Check out more details: github.com/amrelsagaei/...
✅ Redesigned Match & Replace + Workflow support
✅ Built-in logs for better debugging
✅ DNS entry overrides
✅ Invisible proxying
✅ Request / replay response in browser
✅ Default project selection
Here’s everything you need to know 🧵👇
✅ Redesigned Match & Replace + Workflow support
✅ Built-in logs for better debugging
✅ DNS entry overrides
✅ Invisible proxying
✅ Request / replay response in browser
✅ Default project selection
Here’s everything you need to know 🧵👇
Caido will now be pre-installed on Parrot OS and we will work toward more native integrations with the OS.
Read all about it on our blog!
https://buff.ly/3DXI5XD
Caido will now be pre-installed on Parrot OS and we will work toward more native integrations with the OS.
Read all about it on our blog!
https://buff.ly/3DXI5XD
You can now filter intercepted requests with HTTPQL to focus on the ones that matter to you.
We’ve also added manual Finding creation, URL decoding on hover, and more.
Full list of changes: https://buff.ly/3Whf3Z6
You can now filter intercepted requests with HTTPQL to focus on the ones that matter to you.
We’ve also added manual Finding creation, URL decoding on hover, and more.
Full list of changes: https://buff.ly/3Whf3Z6
Introducing “Param Finder” by bebiksior—discover hidden parameters in Caido with ease.
Check it out: https://buff.ly/4a6ASjS
Introducing “Param Finder” by bebiksior—discover hidden parameters in Caido with ease.
Check it out: https://buff.ly/4a6ASjS
Introducing “Param Finder” by bebiksior—discover hidden parameters in Caido with ease.
Check it out: https://buff.ly/4a6ASjS
AI seamlessly integrated into your HTTP proxy.
Use cases:
"Take this JS and build the JSON request body"
"Fill in these IDs from my notes - UserA"
"Create a match and replace rule to turn on this feature flag"
"Generate a wordlist with all HTTP Verbs"
AI seamlessly integrated into your HTTP proxy.
Use cases:
"Take this JS and build the JSON request body"
"Fill in these IDs from my notes - UserA"
"Create a match and replace rule to turn on this feature flag"
"Generate a wordlist with all HTTP Verbs"
Introducing "QuickSSRF" by w2xim3.
Perform out-of-band testing with interactsh to detect vulnerabilities like blind SSRF.
Check it out: https://buff.ly/4eU28Tz
Introducing "QuickSSRF" by w2xim3.
Perform out-of-band testing with interactsh to detect vulnerabilities like blind SSRF.
Check it out: https://buff.ly/4eU28Tz
You can now buy Caido Vouchers directly from our site https://buff.ly/3Zzozcg
You can now buy Caido Vouchers directly from our site https://buff.ly/3Zzozcg
I run a free hacking newsletter every week called MonkeHacks, where I talk about what I've done for the week, list some useful resources I've read, and talk about research I've done. If you're subscribed already - thanks! If not - please sub!
I run a free hacking newsletter every week called MonkeHacks, where I talk about what I've done for the week, list some useful resources I've read, and talk about research I've done. If you're subscribed already - thanks! If not - please sub!
@caido.io
@sensepost.com
@portswigger.net
@sansisc.bsky.social
@compasssecurity.bsky.social
@caido.io
@sensepost.com
@portswigger.net
@sansisc.bsky.social
@compasssecurity.bsky.social
👉 it enables some very cool integrations, like auto curated feeds and starter packs for contributors and tech
👉 it enables some very cool integrations, like auto curated feeds and starter packs for contributors and tech
If you are in Brazil on the 14-15th of December, it is a must 🎉
If you are in Brazil on the 14-15th of December, it is a must 🎉