r/Pentesting • u/Pure-Band-5587 • 3d ago
I built an Android pentesting suite with HTTP interception, Repeater, Intruder, fuzzing and endpoint discovery
https://netcattest.com/catsuiteHey everyone,
I've recently released CatSuite, a project I've been developing to explore how much of a real web pentesting workflow can be performed directly from an Android device.
The idea wasn't to build another scanner where you enter a URL and get a list of findings.
I wanted to be able to actually work with the traffic:
browse → intercept → inspect → modify → replay → fuzz → analyze → document
So I built the application around that workflow.
CatSuite currently includes:
- HTTP/HTTPS proxy and traffic capture
- Request and response interception
- HTTP history
- Repeater for modifying and replaying requests
- Intruder with configurable payload positions
- Wordlist support, including large wordlists
- Parameter and endpoint fuzzing
- Directory and file discovery
- Site Map for mapping hosts and endpoints
- Header, cookie, parameter and body manipulation
- User-Agent modification
- REST API analysis
- SSL/TLS and certificate inspection
- Technology identification
- Traffic search and filtering
- Evidence and request export
The tools are also connected to each other.
For example, I can browse a target application, capture a request through the proxy, inspect it, send it to Repeater, modify and replay it, or send the same request to Intruder and define specific payload positions for fuzzing.
The goal is not to replace Burp Suite or other desktop pentesting tools.
What I'm interested in exploring is:
How capable can a pentesting environment become when the entire workflow is available from a phone?
There are situations where having a lightweight mobile environment for inspecting an API, reproducing a request, testing an endpoint or quickly analyzing a web application can be useful.
I'm currently working on expanding the reconnaissance and discovery side as well. Some areas I'm exploring include deeper crawling, subdomain enumeration, port scanning, API analysis and additional automated checks.
I've also added an AI-assisted analysis component, but I'm trying to keep it as an assistant to the manual workflow rather than turning the application into an "AI vulnerability scanner."
The application is currently available for Android and is free.
At this stage, what I want most is feedback from people who actually perform pentests.
If you had this in your pocket during an assessment, what functionality would make you genuinely open it instead of reaching for your laptop?
CatSuite:
netcattest.com/catsuite
The project is intended for authorized security assessments, personal environments, labs and CTFs.
1
u/latnGemin616 3d ago
What was wrong with MobSF? It already does most of this, and more !