Active Traffic Interception
Pause, modify, and drop live HTTP requests in transit with multi-tab capture filters.
Active Traffic Interception
Active Interception gives you full control as a live gatekeeper between your client application (web browser, mobile app, CLI tool) and the destination server. Instead of passively recording traffic, interception pauses requests in-flight, allowing you to inspect headers and parameters, modify payloads on the fly, and test how the server handles altered data.
How Active Interception Works
Client ──► [ Paused in Hexbuffer Intercept ] ──► (Modified Request) ──► Target Server- Client Dispatches Request: Your browser or API client sends an HTTP/HTTPS request.
- Hexbuffer Pauses Traffic: When Intercept is enabled, the request is held before transmission.
- Inspect & Alter: Modify headers, authentication tokens, JSON bodies, or form parameters in the request editor.
- Action Executed: Choose to Forward (transmit modified data) or Drop (terminate the request).
The Intercept module is tied directly to the MITM proxy—if the proxy is not connected when you enable interception, Hexbuffer prompts you to start it first.
Interception Tabs & Capture Filters
Avoid getting overwhelmed by high-traffic web applications by organizing interception into targeted tabs:
- Multiple Intercept Tabs: Add, rename, and close interception tabs (including close-to-left/right and close-all) so you can run separate interception configurations for different targets or test phases.
- Per-Tab Host Filters: Each tab maintains its own capture host filter patterns. Add or remove patterns inline, and only requests matching the tab's filters are held.
- Send to Intercept: Right-click a request in Live Traffic and choose Send to Intercept to pre-load a matching request into an interception tab.
Queue & Request Editor
The Intercept view is split into two panels:
- Queue Panel: Lists all currently held requests. Review pending items, select one to edit, and forward or drop it.
- Request Panel: Opens the selected request in a full editor for inspecting and modifying method, URL, headers, and body before dispatch.
Common Use Cases & Testing Scenarios
1. Client-Side Restriction Bypasses
Test whether backend APIs properly validate inputs by removing read-only flags, bypassing disabled form inputs, or modifying hidden form fields that the frontend UI attempts to restrict.
2. Privilege Escalation & Role Tampering
Alter session cookies, user IDs, or role claims in transit to verify whether unauthorized users can perform administrative operations.
3. Server Error & Resilience Simulation
Drop critical requests to evaluate whether your frontend displays graceful fallback UI or crashes unexpectedly.
Best Practices
[!WARNING] Remember to Disable Interception: Leaving interception active with pending paused requests will cause browser tabs or API clients to hang until forwarded or dropped!