Coming from Burp or Caido
Your existing workflow maps almost one-to-one. Here is the translation, and what differs.
If you have used Burp Suite or Caido, you already know the model: a proxy feeds a history, and you send requests on to specialised tools. In Hugin the names and a few shortcuts differ; the workflow doesn't.
The translation
| You know | In Hugin |
|---|---|
| Proxy → HTTP history | Proxy → HTTP History (each entry is a flow) |
| Repeater | Repeater (tabs, saved versions, render-in-browser) |
| Intruder | Intruder (Sniper / Battering Ram / Pitchfork / Cluster Bomb + Content Discovery, Custom, Single-Packet) |
| Scanner / active scan | Scanner — 55 active + 48 passive checks |
| Sequencer | Sequencer (FIPS 140-2 + NIST SP 800-22) |
| Decoder | Decoder (+ JWT, Smart Decode) |
| Collaborator / OAST | Oastify |
| Match and replace | Match & Replace (Quick + Advanced rules) |
| Target scope | Scope |
| Turbo Intruder / race tooling | RatRace, and Intruder's Single-Packet mode |
What differs
- The Scanner is free. Active and passive checks ship in Community, not behind a paid tier.
- Intruder has more modes — beyond the classic four, a Single-Packet (HTTP/2) race mode and a Custom cross-and-zip mode.
- Races are first-class — RatRace does single-packet, last-byte, and barrier sync (Pro).
- AI agents drive it — Hugin exposes its tools over MCP, so an agent can run the same tools you do.
A few capabilities are Pro: the built-in Browser, Nerve, RatRace, extensions, collaboration, and mobile.
Keep your instincts. Send to Repeater, fuzz with Intruder, confirm blind bugs with Oastify — the muscle memory carries over.
Start with the quickstart.