Hexbuffer

Welcome to Hexbuffer

The Unified Application Security, Traffic Diagnostics, and API Testing Workspace

Redefining Web Application Reconnaissance & Security Testing

Hexbuffer (v1.1.1) is a high-performance desktop platform designed to unify web application security diagnostics, network traffic analysis, API request crafting, mock server management, and response overrides into a single, seamless environment.

Built with a high-speed Rust backend core and a reactive modern UI, Hexbuffer eliminates tool sprawl by bringing network proxying, traffic interception, automated parameter fuzzing, API mocking, and local response overrides under one roof.


Why Choose Hexbuffer?

Traditional web application testing often requires switching between disjointed browser extensions, standalone API clients, separate mock servers, and isolated notes applications. Hexbuffer replaces this fragmented experience with an intuitive, integrated desktop suite.


Core Capabilities at a Glance

1. Modular Desktop Dashboard

Customize your workspace with draggable widgets—monitor target scopes, proxy status, VPN connections, system clipboard history, request collections, recent apps, scratchpads, and keyboard shortcuts from a central hub.

2. Real-Time Traffic & Interception

Capture complete web interactions, monitor live HTTP requests with session management and persistent or ephemeral storage, filter by domain scope, and pause in-flight traffic with active interception to edit payloads before they reach the server.

3. Request Crafting & Fuzzing

Replay and modify requests in the multi-tab Repeater with collections, environment contexts, and pre/post-request scripting, then execute sequential payload injection attacks with Intruder—mark § positions, assign wordlists or numeric generators, and analyze results with grep matchers and a multi-layout inspector.

4. API Mocking & Response Overrides

Run a standalone API Mock server on localhost with dynamic route parameters, response templating, CORS handling, and chaos engineering (latency and error injection), or intercept proxy traffic with API Override rules to return fake responses for matched requests. Both are new in this release.

5. Security & Productivity Utilities

Inspect and sign JSON Web Tokens with the tabbed JWT tool, map open ports and services with the Port Scanner, keep quick notes and architecture sketches in the reworked Notes scratchpad with its built-in drawing canvas, and configure proxy certificates, themes, and app preferences in Settings.


Explore the Documentation

Get up and running quickly or dive deep into specific feature modules:

  • Getting Started: Install Hexbuffer, configure the local MITM proxy, set up your root CA certificate, and capture your first request.
  • Traffic & Diagnostics: Master live HTTP history, session management, active interception, and deep message inspection.
  • Request Crafting & Testing: Learn how to replay requests in Repeater, fuzz parameters with Intruder, and scan ports.
  • API Tools & Security: Build mock servers, override live proxy responses, and decode or sign JWTs.
  • Notes & Workspace: Organize quick notes, markdown documents, and architecture sketches with the drawing canvas.
  • User Guide & Best Practices: Tips for maximizing productivity, keyboard shortcuts, performance tuning, and FAQs.

On this page