Hello world 👋
We’re proud to announce Caido: A high-performance / low memory usage web
#security
auditing
#tool
written in Rust 🎉
Interested? Register on our website to reserve your spot in our upcoming beta
#pentest
#bugbounty
#infosec
We're excited to announce that Caido, our web security auditing toolkit, is now available in public beta 🚀
We're grateful for your support and can't wait for you to give it a try. Let us know your thoughts and help us improve the tool 🙏
📝 Introducing "Findings"
Release v0.34.0 is out with a new "Create Finding" workflow node.
Flag interesting requests and make your own passive scanner rules, such as:
- Source code disclosure
- Software version disclosure
- Credit card/email/IP disclosure
🎉 Exciting update! 🎅
Ever felt overwhelmed by endless HTTP requests? 😅 We've been there. That's why we created HTTPQL - a quick, easy way to filter through the noise.
🎉 Release v0.33.0 is up!
Desktop users can now launch a browser with the correct certificate and proxy settings! No need to setup FoxyProxy anymore.
The launcher lets you select Chrome/Edge browsers on your device. You may need to install one of them for this feature to work.
🤖 v0.35.0 is out!
We've introduced a new JavaScript node for passive/convert workflows,
enabling you to send HTTP requests, receive responses, and create
findings programmatically.
This allows for making more complicated workflows such as XSS and auth bypass checks.
We're back with a new release! 🎉
This update focuses on UI improvements and the usual bug fixes.
• Brand new sidebar
• CSS/HTML/XML/JS pretty in responses
• Simplified panel resizing system
Excited to announce I've joined the
@CaidoIO
team as an Advisor!
I'll be taking a trip out to Montreal here within the next couple of weeks to meet with the team, brainstorm, and get oriented.
Excited to have the opportunity to be a part of this fantastic product!
🚀 New Plugin Alert!
"403Bypasser" by
@bebiksior
is now available in the Plugin Store!
Bypass 403 status codes by transforming HTTP requests with custom templates.
When we started Caido 3 years ago, we never would have believed our software would become what it is today.
We are still the same 3 people working on it, it's not easy every day but our community and videos like these are what makes it all worth it ❤️
The slides and the full code from our
@defcon
workshop is now available on Github 😎
It goes over creating a python tool using the Caido API and building a plugin frontend/backend.
Check it out 🫡
🤖 v0.38.0 is out!
Pro users can now filter Automate results with HTTPQL directly from the Automate page. This should make it easier to pinpoint interesting requests/responses during testing.
New community workflows added by
@ryotkak
- Generate CSRF PoC
- HTML Decode Everything
- HTML Encode Everything
- Form Data to JSON
- JSON to Form Data
- JSON to XML
- JSON Escape
- JSON Unescape
Check them out at
Thank you
@ryotkak
for the submissions!
🎉 v0.32.1 is out with a new shell node for passive workflows!
Run bash/zsh/cmd/powershell commands when a request or response is intercepted.
This was a highly requested feature following the release of passive workflows. More nodes will be included in the upcoming weeks.
v0.41.0 is live! 🚀
We’re excited to introduce the new Community Plugin Store! Browse and install open-source plugins with a single click.
Interested in publishing a plugin? Visit to learn how!
v0.39.0 is here with a new workflow integration for Replay!
Automatically run workflows and preprocessors during manual testing. Use it to encode payloads, generate signatures, run shell commands, and more.
Smaller release with some much-requested features 😎
• Copy as cURL
• Change between GET and POST in Replay/Forward
• Timestamp of requests
• Fix unicode support
• (Pro) Fix bug for unlimited projects
v0.37.0 is finally here!
Introducing our official plugin manager. Users can now develop their own plugins and share them with the community.
If you're interested in creating a Caido plugin, checkout and join our Discord to get started.
In our latest update, we've included a powerful new feature: Automate Preprocessors.
Add custom transformations to your automate payloads with preprocessors like:
- Suffix
- Prefix
- URL Encode
- Workflows (available to Pro users)
🎉 Passive workflows are here!
Writing plugins can be tedious to many. Passive workflows is our attempt to fix that.
By simplifying the steps it takes to customize Caido, we're hoping to encourage more people to tailor the tool to their needs. 🧵
🎨 New release: You can now customize the Caido UI with custom CSS and JS!
We've also added column hiding and re-ordering in the Intercept, HTTP History, Search, and Sitemap tables.
Plus, we've added a few community-requested shortcuts 🎉
🚀 We're back with a new release!
Introducing Convert Workflows: Drag and drop blocks to create complex conversion pipelines.
Workflows is the new system that will enable you to create custom plugins with little to no code 🔥.
🔥 v0.36.1 is out!
Introducing "Active Workflows", a new workflow type to execute actions against individual requests.
Run CLI tools, analyze requests/responses with JS, modify/send new requests, and more.
Time for a new release 🚀
• (Pro) Introducing the Caido Assistant, our implementation of ChatGPT tailored for security use
• Highlight in requests/responses is easier to see
• Font-size is now configurable
• Collections UI supports Drag and Drop
Caido intercepts web traffic, acts as a fuzzing engine, traffic replayer, & more.
@appSecExp
demos
@CaidoIO
's updates, highlighting the JS engine in the Workflows module. Is Caido worth adding to your workflow? Watch & find out!
v0.40.0 is now live! 🚀
This release focuses on improving performance and responsiveness for desktop users, especially on Linux. If you’ve found the desktop experience sluggish on Linux, give it another try.
It's release time 🎃
- Responses can now be intercepted and modified
- Delete requests from HTTP History
- [Pro] Import/export your projects using our new "backups" page
- [Pro] Add shell commands to your convert workflows with the new "Shell" node
Missed our workshop at Hackfest? The full presentation and the exercises are available on Github 💪
We go in depth about Workflows, Plugins and the GraphQL API 👀
After months of work, we've hit a new milestone: we're launching our first beta to a lucky few 🥳
Make sure to check your emails as we increase our beta program in the coming weeks/months.
Our second beta testers is underway 🎉
We already have a lot of feature requests and bug reports in our public tracker, what an awesome community 🤩
Special shoutout to
@sw33tLie
,
@Rhynorater
and
@dee__see
who are going above and beyond 🙏
It's release time 🤩
- We have websocket support! View messages that pass through the proxy
- Shortcuts are now configurable
- Easy access to convert workflows using the right-click menu
- Scopes now use the glob patterns instead of SQL LIKE syntax
Thanks to our awesome community, we reached an important milestone 🥳
We passed the 100 pro users mark! To all of you, thank you for making this journey possible ❤️
Time for a new release 🚀
• Unicode support in the editor
• Request/response exporting
• Multiple bugs fixed & improved stability
• (Pro) Unlimited projects and filtered exports
Had an absolutely stellar time at
@Hacker0x01
's
#h1305
! The
@CapitalOne
team was a real joy to work with, and Miami felt like just the perfect location.
As this was my 16th LHE, I was beginning to think I would never make MVH, but having a positive attitude, grit, and
It's release time ❄️
- Intercept supports scopes
- Clear all added to HTTP History
- Fixed login issue for linux desktop user
- Various quality of life improvements
🚀 v0.42.0 is out!
You can now route traffic through SOCKS proxies, with the ability to assign different proxies based on the destination target.
Check all the details about the latest release here:
🎉 New Plugin Release!
"EvenBetter" by
@bebiksior
is now available in the Plugin Store!
A collection of tweaks and improvements for Caido.
Check it out:
🚀 v0.30.1 is out!
We've added support for upstream proxies. We've also put in some work to improve how we handle HTTP requests, making Caido faster and more efficient.
⌨️ v0.32.1 introduces a new command palette!
Easily run commands and browse different sections without relying on your mouse or shortcuts.
We'll be expanding on this to allow users to run custom actions and workflows.
🤖 Introducing Workflows v2!
Nodes now take up less space, are color-coded, and have more flexible inputs/outputs. We've also added default base64 and URL encoding workflows to all projects.
Next step is passive workflows, which will bring even more customization to Caido.
New community workflow "Linkfinder" added by
@bytehx343
This workflow finds paths inside in-scope responses.
Check it out at
Thank you
@bytehx343
for the submission!
With version 0.35.0, using workflows just got easier.
Create your workflow once, and it will instantly be accessible across all current and future projects.
We are trying a new concept: Monthly Town Hall
Once per month we will unlock a town hall channel for 1 hour ⌛
We want you to bring issues that might not have too many upvotes to our attention 👀
See you Discord!
As part of the the
@BugBountyDEFCON
village, we are presenting a workshop on Caido internals. It will be a unique chance to ask all your questions around the API, Workflow, Plugins and more 🎉
#Workshop
#Defcon
We've achieved a new milestone: two releases in a week!
This latest update solves the login issues mentioned by people on our Discord, as well as introducing a new "Display hidden characters" toggle on the replay page.
EvenBetter v2.0 released!
Changelog:
- Quick Decode: new feature that allows you to quickly decode text just by selecting or hovering over it on the Replay page
- Send to Match & Replace: new context menu button page that allows you to quickly send
Have you seen the newcomer in our dashboard? 👀
We now have a referral program 🔥
We are looking for content creators/community leaders/partners to launch this new program and get feedback.
If you like Caido and want to share it, get in touch ❤️
In an effort to increase transparency, we are now publishing the OpenAPI specification of the cloud API used by Caido instances. We are also working on documentation on the subject.
Do contact us if you have concerns/suggestions around that subject!
Did you know you can create custom workflows in Caido and execute them from anywhere? 🔥
With workflows, you can customize Caido with minimal programming experience:
- Chain encoders/decoders
- Analyze text with custom Javascript snippets
- Soon: Run text through CLI tools
🎉 Another day, another new plugin!
"Caido Themes" by
@bebiksior
is now available in the Plugin Store.
Manage and customize themes. Pick from a selection of default themes or create your own.
Check it out:
EvenBetter v1.3 is out!
Changelog:
- v1.3: [BETA] Exporting/Importing Scope Presets: You can now share your scope presets with your team by exporting and importing them. Note that while this feature is in BETA, it should mostly work well, though there might be some UI issues.
-
The Caido team would like to wish you a happy new year 🎉
We have a lot in store for you in 2022: more testers, a full-time dev team, and a host of new features!
Stay safe and hack on 😎
New community workflow "Autochrome Colors" added by
@0xRTH
This workflow adds support for Autochrome colored sessions.
Check it out at
Thank you
@0xRTH
for the submission!
Apparently, we've missed our deadline 😅
We've hit a few (many) roadblocks, but we're making good progress towards the open beta 🚀
Here are a few stats on where we're at so far:
@securibee
@sw33tLie
We are very slowly expanding the beta. We have over 2000 people on the list and sent emails to around 120 people. We will eventually reach public beta in ~2 months, but feel free to DM us if you want to try it earlier 😀
Another day, another bug squashed 😅
We have been made aware of some problems when using Caido with Burp as an upstream proxy.
If you're using Caido that way, please update to v0.30.3!
A new month, a new town hall ✨
Once per month we unlock the town hall channel for 1 hour ⌛
We want you to bring issues that might not have too many upvotes to our attention 👀
See you on Discord tomorrow!
Thanks to you all for the amazing year 🥳
This year we built many cool features, made (a few) mistakes, earned our first dollars and learned a whole lot in the process 😅
2023 will bring exciting stuff for us and we can't wait to release Caido to the world!
Happy new year 🎉
@Agarri_FR
@zaproxy
@Burp_Suite
Competition is always good, drives innovation.
There is a difference in means (we are 2 people vs whatever hundreds of ppl on Burp) at the moment. As a business, getting copied on a feature means it was not defensible so we have to shift priority on stuff that is unique.