docs

Coming from Burp or Caido

Your existing workflow maps almost one-to-one. Here is the translation, and what differs.

If you have used Burp Suite or Caido, you already know the model: a proxy feeds a history, and you send requests on to specialised tools. In Hugin the names and a few shortcuts differ; the workflow doesn't.

The translation

You knowIn Hugin
Proxy → HTTP historyProxy → HTTP History (each entry is a flow)
RepeaterRepeater (tabs, saved versions, render-in-browser)
IntruderIntruder (Sniper / Battering Ram / Pitchfork / Cluster Bomb + Content Discovery, Custom, Single-Packet)
Scanner / active scanScanner — 55 active + 48 passive checks
SequencerSequencer (FIPS 140-2 + NIST SP 800-22)
DecoderDecoder (+ JWT, Smart Decode)
Collaborator / OASTOastify
Match and replaceMatch & Replace (Quick + Advanced rules)
Target scopeScope
Turbo Intruder / race toolingRatRace, and Intruder's Single-Packet mode

What differs

  • The Scanner is free. Active and passive checks ship in Community, not behind a paid tier.
  • Intruder has more modes — beyond the classic four, a Single-Packet (HTTP/2) race mode and a Custom cross-and-zip mode.
  • Races are first-class — RatRace does single-packet, last-byte, and barrier sync (Pro).
  • AI agents drive it — Hugin exposes its tools over MCP, so an agent can run the same tools you do.

A few capabilities are Pro: the built-in Browser, Nerve, RatRace, extensions, collaboration, and mobile.

Keep your instincts. Send to Repeater, fuzz with Intruder, confirm blind bugs with Oastify — the muscle memory carries over.

Start with the quickstart.

Last updated 2026-06-07.