Welcome to Hexbuffer
The Unified Application Security, Traffic Diagnostics, and API Testing Workspace
Redefining Web Application Reconnaissance & Security Testing
Hexbuffer (v1.1.1) is a high-performance desktop platform designed to unify web application security diagnostics, network traffic analysis, API request crafting, mock server management, and response overrides into a single, seamless environment.
Built with a high-speed Rust backend core and a reactive modern UI, Hexbuffer eliminates tool sprawl by bringing network proxying, traffic interception, automated parameter fuzzing, API mocking, and local response overrides under one roof.
Why Choose Hexbuffer?
Traditional web application testing often requires switching between disjointed browser extensions, standalone API clients, separate mock servers, and isolated notes applications. Hexbuffer replaces this fragmented experience with an intuitive, integrated desktop suite.
No Web Tool Sprawl
Access your proxy, API client, fuzzer, mock servers, and documentation in a unified workspace without context switching.
API Mock & Response Override
Spin up a standalone local mock server with templated responses and chaos testing, or override live proxy responses with Map Local-style rules.
High-Speed Traffic Diagnostics
Intercept, inspect, and modify HTTP/HTTPS traffic on the fly with millisecond responsiveness and deep message analysis.
Request Crafting & Fuzzing
Replay requests in Repeater and stress-test parameters with the Intruder engine, all backed by a multi-threaded Rust core.
Core Capabilities at a Glance
1. Modular Desktop Dashboard
Customize your workspace with draggable widgets—monitor target scopes, proxy status, VPN connections, system clipboard history, request collections, recent apps, scratchpads, and keyboard shortcuts from a central hub.
2. Real-Time Traffic & Interception
Capture complete web interactions, monitor live HTTP requests with session management and persistent or ephemeral storage, filter by domain scope, and pause in-flight traffic with active interception to edit payloads before they reach the server.
3. Request Crafting & Fuzzing
Replay and modify requests in the multi-tab Repeater with collections, environment contexts, and pre/post-request scripting, then execute sequential payload injection attacks with Intruder—mark § positions, assign wordlists or numeric generators, and analyze results with grep matchers and a multi-layout inspector.
4. API Mocking & Response Overrides
Run a standalone API Mock server on localhost with dynamic route parameters, response templating, CORS handling, and chaos engineering (latency and error injection), or intercept proxy traffic with API Override rules to return fake responses for matched requests. Both are new in this release.
5. Security & Productivity Utilities
Inspect and sign JSON Web Tokens with the tabbed JWT tool, map open ports and services with the Port Scanner, keep quick notes and architecture sketches in the reworked Notes scratchpad with its built-in drawing canvas, and configure proxy certificates, themes, and app preferences in Settings.
Explore the Documentation
Get up and running quickly or dive deep into specific feature modules:
- Getting Started: Install Hexbuffer, configure the local MITM proxy, set up your root CA certificate, and capture your first request.
- Traffic & Diagnostics: Master live HTTP history, session management, active interception, and deep message inspection.
- Request Crafting & Testing: Learn how to replay requests in Repeater, fuzz parameters with Intruder, and scan ports.
- API Tools & Security: Build mock servers, override live proxy responses, and decode or sign JWTs.
- Notes & Workspace: Organize quick notes, markdown documents, and architecture sketches with the drawing canvas.
- User Guide & Best Practices: Tips for maximizing productivity, keyboard shortcuts, performance tuning, and FAQs.