Five parts, one session.
Capture a website or an Android app, work the traffic, and leave with a spec.
The whole thing, in five stops
Each stop is the real app. Click through, or let it play.
apiaxess
Go to surface, flow, endpoint or command⌘K
api.northwind-retail.ioLive control connected
Input · web domain
Web capture
Declare the target and your authorization, capture live traffic through the bundled browser, and see what was actually observed in an API surface.
Launch browser
TargetNOT STARTED
Web target
https://northwind-retail.io
Tick the authorization to start.
Active discoveryIDLE
Discovery typeDirectories / pathsWordlistSecLists common.txt · 4,751
Found paths land in the same session.
Intercept queue 0Diagnostics 0Control · reliable
No paused requestsWith intercept on, matching requests pause here until you forward, modify or drop them.
WEB CAPTUREsession:2l1a434f3f6b1aControlTelemetry127.0.0.1
A throwaway Chromium, already routed through the proxy. Name the target and start.
See this part →
Go deeper
Web capture
A disposable Chromium that records every request: HTTP/1.1, HTTP/2, WebSocket, SSE, gRPC-Web and GraphQL, labelled against your scope.
Read more →
Android & APK
Static APK analysis, plus an Android target that boots already trusting the session.
Read more →
Workbench
The live traffic queue and Resend: edit, replay and branch any request.
Read more →
Fuzz
Four attack types, 17 payload types, grep, pause and resume. Free.
Read more →
API surface
Every endpoint in one view, exported as OpenAPI 3.1, Postman, HAR and a Python client.
Read more →
What you are installing
- Listens
127.0.0.1:7777workbench ·127.0.0.1:8080proxy- In the box
- Its own Chromium for web capture, and ffuf for fast fuzzing
- Add-ons
- The analysis runtime (about 1.2 GB) and the Android target (about 1.3 GB), downloaded in the app when you click to get them
- Stores
- A local SQLite session file, plus your exports
- License
- Apache-2.0