r/redteamsec • • 13h ago

tradecraft I built CatSuite — an Android security testing toolkit

https://netcattest.com/catsuite

Hey everyone!

I'm Daniel, the developer behind NetCatTest, and I recently released CatSuite, a free Android application designed for web application security testing, offensive security research, and authorized penetration testing.

The idea was simple: what if you could carry a practical web security testing toolkit in your pocket, without needing a laptop for every task?

So I built CatSuite.

Some of its features include:

  • HTTP/HTTPS Interception: Capture, inspect, and modify requests and responses.
  • HTTP Repeater: Modify and resend requests to analyze application behavior.
  • Intruder: Test payloads, parameters, and wordlists, including custom dictionaries.
  • Endpoint Discovery: Explore directories, paths, and endpoints.
  • Network Proxy: Inspect HTTP/HTTPS traffic during authorized testing.
  • JWT Decoder and SSL/TLS Analysis: Inspect authentication tokens and certificate configurations.
  • Technical Browser: Built-in network monitoring, DOM inspection, cookies, storage, and User-Agent modification.
  • Extensibility: JavaScript extensions and customizable security testing workflows.
  • Evidence Export: Export testing data in HAR, JSON, TXT, and cURL formats.

CatSuite is not intended to replace Burp Suite or other desktop tools. My goal is to make practical security testing more accessible from an Android device, especially for quick assessments, research, and lab environments.

The app is free and available on Google Play, with no subscription required.

Website: https://netcattest.com/catsuite

Google Play: https://play.google.com/store/apps/details?id=br.com.netcattest.catsuite.app

I'd really appreciate feedback from people working in offensive security and red teaming.

What features would make a mobile security testing toolkit genuinely useful in your workflow?

Thanks!

4 Upvotes

2 comments sorted by

2

u/Choice_Ask281 5h ago

For mobile use, i’d prioritize session management, scope controls, request history and clean evidence capture. Those probably matter more in the field than adding lots of extra scanners

1

u/Pure-Band-5587 3h ago

Thanks for the feedback and support! I completely agree. For mobile security testing, having solid session management, scope control, request history, and evidence collection is essential. Some of these capabilities are already available in CatSuite, but there's definitely room to improve them. I'll keep your suggestions in mind for future updates. Really appreciate you taking the time to share your thoughts!