Hexbuffer
Traffic & Diagnostics

Live Traffic & HTTP History

Real-time HTTP/HTTPS request monitoring, session management, scope filtering, advanced search, and quick workflow actions.

Live Traffic & HTTP History

The Live Traffic module is the central diagnostic center of Hexbuffer. It provides real-time visibility into all HTTP and HTTPS communication passing between your client applications, browsers, or automated scripts and remote backend servers.


Key Features & Capabilities

Real-Time Request Grid

The main traffic grid displays incoming and outgoing network events as they occur with sub-millisecond precision:

  • Status & Method: Color-coded HTTP status badges (200 OK, 302 Found, 401 Unauthorized, 403 Forbidden, 500 Server Error) and request methods (GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD).
  • Host & URL Path: Full endpoint URL path resolution with host indicators and SSL/TLS status.
  • Latency & Performance: Precise round-trip timing in milliseconds to identify backend bottlenecks.
  • Content Size: Exact byte counts for request headers, request bodies, response headers, and response payloads.
  • MIME & Content-Type: Instant detection of JSON, XML, HTML, GraphQL, JavaScript, CSS, images, and raw binary streams.
  • Request Body Preview: Preview request bodies directly from log table entries without opening the full detail view.

Powerful Search & Scope Filtering

When auditing complex microservices or modern single-page applications, eliminating background noise is essential:

1. Target Scope Filtering

Define in-scope and out-of-scope domain patterns (e.g., *.api.example.com). Toggle Filter by Scope to hide all operating system, browser telemetry, or non-target domain traffic.

2. Full-Text Search & Regex Filtering

Search through request and response URLs, headers, POST parameters, cookies, or body content in real time. Full regex support enables precise pattern extraction (e.g., detecting exposed API keys, JWT signatures, or stack traces).

3. Status Range & Content-Type Filters

Filter requests by HTTP status categories (2xx, 3xx, 4xx, 5xx), MIME types (JSON, HTML, Media), or minimum/maximum response sizes.


Context Menu & Quick Actions

Right-click any request in the Live Traffic grid to access workflow triggers:

  • Send to Repeater (Cmd+R / Ctrl+R): Clone the request into an interactive crafting tab.
  • Send to Intruder: Load the request into the payload fuzzer for attack configuration.
  • Send to Intercept: Pause matching requests in the interception queue.
  • Send to API Override: Add the request's host as a response override target.
  • Send to Notes: Save request material into a scratchpad note.
  • Copy as cURL / Copy URL: Generate ready-to-run shell commands or reuse endpoint URLs.
  • Pin, Group & Highlight: Pin rows, organize requests into groups, highlight hosts with custom colors, or blacklist hosts and host+path combinations.
  • Add to Target Scope: Instantly whitelist the request host in your scope settings.

Session Management & Storage

Traffic history is organized into sessions backed by a local SQLite database:

  • Multiple Sessions: Create, rename, and switch between capture sessions; each session tracks its own request count and total capture size.
  • Storage Modes: Choose between persistent sessions (history survives app restarts) and ephemeral sessions (kept only for the current run) per session. Ephemeral sessions are flagged in the UI so you always know what is being retained.
  • Chunked Pagination: Large sessions load 60 items per page with a dismissible warning banner. Log filters apply to the currently loaded page; use pagination to navigate through the full history.
  • Expanded Detail Modal: Open any request in an expanded modal view showing raw request/response editors plus structured tables for headers, parameters, cookies, and response bodies.

Best Practices

[!TIP] Use Sessions for Test Phases: Create a new session for each test phase (reconnaissance, authenticated testing, regression checks) and switch storage modes to ephemeral for throwaway captures so they never clutter persistent history!

On this page