Testing tools for web development and security
Hexbuffer lets you capture HTTP traffic, modify requests mid-flight, replay and fuzz endpoints, and organize notes in a single local desktop workspace.
See FeaturesWhat Can You Do?
Essential tools for inspecting, tampering, replaying, and testing web application traffic in one workspace.
HTTP & HTTPS History
Capture, inspect, and filter real-time HTTP and HTTPS network traffic with detailed header and body viewers.
Intercept & Tamper
Pause traffic mid-flight. Edit raw request and response headers, parameters, and bodies before they resolve.
Request Repeater
Modify HTTP requests, reissue them instantly, and analyze response status, headers, and bodies side-by-side.
Intruder & Fuzzer
Set payload positions, configure wordlists, and run automated attack iterations against target endpoints.
Notes & Scratchpad
Write markdown notes, record reproduction steps, and keep context organized within your testing session.
Proxy Configuration
Configure custom proxy listeners, install trusted CA root certificates, and tune application preferences.
Who Is It For?
Built for anyone who needs to inspect, test, and document web applications.
Penetration Testers
A dedicated local workstation for inspecting and manipulating HTTP traffic.
Security Researchers
Deep HTTP request and response inspection with manual payload tampering.
Developers & QA
Debug APIs and test endpoint behavior with immediate request replay.
Try hexbuffer on your next target.
A fast desktop app for HTTP traffic inspection, request interception, and endpoint testing.
macOS available now — Windows coming soon