docs

HTTP History

The flow table where every captured request lands — filter it with HTTPQL and right-click any flow into your attack tools.

HTTP History is the default view and where you spend most of your time. Every request your browser sends to the target, with the response that came back, lands here as a flow the moment it is captured. From this one table you read traffic, spot what is worth attacking, and send it to the right tool.

Read the table

Each row is one flow. The columns that earn a first look:

  • Host and Path & Query — where the request went. Scan for /admin, /api, internal hosts, and id parameters.
  • Method — POST, PUT, and DELETE change state; line them up for IDOR, CSRF, and authorization tests.
  • Status — 401 and 403 mark an auth boundary, 500 hints at injection or a broken handler, 3xx flags redirects worth an open-redirect or SSRF look.
  • Resp. Size and Resp. Time — an odd size or a slow response is the tell for differential and time-based bugs.

A scope dot flags in or out of scope. Open Column settings to add hidden columns: Protocol (find HTTP/2 hosts for smuggling and desync), TLS, Server IP, Tags, and Comment.

Filter with HTTPQL

Type a query in the filter bar to narrow the table. It speaks the same HTTPQL as the command line — stack terms with a space for AND:

method:POST status:>400 host:*.example.com

Status-class chips (2xx, 4xx, 5xx) filter in one click, and the In Scope toggle drops third-party noise. Save a query you reuse as a preset and manage them in Filters.

Export writes the flows that match your current filter, not the whole capture — narrow the table first, then export the set you care about as HAR.

Triage and send onward

Flag a flow, set a highlight colour, add a comment, or edit tags, then filter to just those rows. Double-click a flow to read the request and response side by side — dock the pane to the right or the bottom. Right-click to move it onward without copy-paste:

Send to Repeater

Replay and hand-tamper a single request in Repeater.

Send to Intruder

Fuzz a parameter across hundreds of payloads in Intruder.

Scan or compare

Run checks with the Scanner, or diff two flows in the Comparer.

The same menu copies a flow as cURL or a raw request and adds its host to scope.

When a flow looks promising, send it to Repeater and confirm the bug by hand.

Last updated 2026-06-16.