Intruder-class fuzzing. No throttle, no paid tier.
Mark the positions, pick an attack, and read the results while the job runs.
Run an attack
From a captured request to results.
apiaxess
Go to surface, flow, endpoint or command⌘K
api.northwind-retail.ioLive control connected
Positions
GET /v1/checkout/§orders§ host: api.northwind-retail.io authorization: Bearer §token§
Payload typeNumbers + wordlistGrep-match"insufficient"Grep-extractorder_id
#PayloadStatusLength
No results yetPick an attack type and start. Results stream in here.
Intercept queue 0Diagnostics 0Control · reliable
No paused requestsWith intercept on, matching requests pause here until you forward, modify or drop them.
WORKBENCHsession:2l1a434f3f6b1aControlTelemetry127.0.0.1
Wrap the parts to vary in §markers§: a path segment, a token, a field.
The details
- Attacks
- Sniper, battering ram, pitchfork and cluster bomb
- Payloads
- 17 types: wordlists, numbers, dates, brute force, case and character permutations, recursive grep, your own files
- Processing
- Encode, hash, prefix, suffix, match-and-replace or skip, per payload
- Reading
- Grep-match, grep-extract, sort by status, length or time
- Runs
- Locally, through
127.0.0.1:8080. No cloud runner and no per-request limit - Price
- Free, and Apache-2.0 licensed