Intruder
Automate a request into many variations — seven attack modes, 21 payload generators, 32 chainable processors, rate and evasion controls, and a sortable results table.
Intruder takes one request, marks the parts to vary (the § markers), and fires
it many times with payloads swapped in. It is how you go from one request in
Repeater to a campaign. It ships in the free Community
tier.

Attack modes (seven)
One position at a time, same payload set each — the default for fuzzing a single parameter.
The same payload in every marked position at once.
One payload set per position, advanced in lockstep (with stop-at-shortest / cycle / pad policies).
Every combination of every set — the full matrix.
A directory/file brute-forcer mode.
Cross-multiply some sets and zip the rest — the Turbo-Intruder style.
A single-packet race attack over one HTTP/2 connection.
Payload generators (21)
Every position draws from a generator. Pick one per position; the generator decides what gets swapped in.
Simple List for a static set. Runtime File streams a wordlist off disk at attack time, so a 10M-line list never has to load into memory first. Custom Iterator cross-multiplies several small lists into one set. Paired Lists drive credential stuffing — usernames against passwords, as lockstep pairs or the full product. Username Generator builds name permutations from first/last name and common-name lists.
Numbers walks a range with a step and an optional format — IDOR id enumeration.
Dates walks a date range with a strftime format. Character Blocks repeats one
character N to M times (A, AA, AAA, …) for length and overflow probing.
Brute Forcer emits every string over a charset between a minimum and maximum
length.
Take a base value and warp it: Case Variant (per-word upper/lower/proper/invert), Character Substitution (leet-style rules), Char Frobber (toggle case, increment, decrement, or reverse each character), Bit Flipper (single-bit and single-byte flips, for padding-oracle and signed-token work), Havoc Mutator (random byte flips, inserts, deletes, arithmetic, slice swaps), and Null Payloads (empty and NULL variants to test how a parameter handles an absent value).
Illegal Unicode emits overlong UTF-8, null bytes, BOM markers, right-to-left
overrides, illegal continuation bytes, directory-traversal sequences, and
homoglyphs — parser confusion and bypassing a web application firewall (WAF).
ECB Block Shuffler reorders, duplicates, drops, or permutes the 16-byte blocks of
a hex or base64 ciphertext, so you can forge a valid token — flip role=user to
role=admin — without ever holding the key.
Recursive Grep extracts a value from response N with a regex and feeds it into payload N+1 — how you ride a rotating CSRF token, a pagination cursor, or a one-time nonce across a sequence of requests. Copy Other Payload mirrors one position's payload into another when the same value must appear twice. Extension Generated hands payload generation to your own extension. Oastify Payloads mint out-of-band (OOB) callback tokens over DNS, HTTP, SMTP, LDAP, FTP, or SMB to confirm blind bugs.
Payload processors (32)
Each set runs its payloads through an ordered chain of processors before they hit the wire. Stack as many as you want; they apply top to bottom.
URL, HTML, Base64, Base32, hex, and gzip — each with an encode rule and a decode rule. Chain them: Base64-encode then URL-encode to slip a payload past a filter that only inspects the outer layer.
Hash (MD5, SHA-1, SHA-256, SHA-512) and keyed HMAC — for when a parameter is a checksum or signature over its own value and the server recomputes it.
Add a prefix or suffix, match-and-replace (regex with $1 backreferences),
substring, reverse the whole string, reverse a substring in place, and case
modification (upper, lower, capitalize, invert).
Timestamp (unix seconds/ms/µs or ISO-8601), UUID v4, random string (alpha/alphanumeric/hex/digits), and a monotonic counter with zero-padding. Anti-replay and nonce checks reject a repeated value — these hand every request a new one.
Base Value Placeholder swaps {base} for the original value between the markers,
so you can wrap it: prefix{base}suffix. Add Raw Payload sends the processed and
the untouched value together in one parameter. Constructed String renders the
payload as character codes — String.fromCharCode(...), SQL CHAR(...), Python
chr(...) — to get SQLi, XSS, or SSTI past quote and keyword filters. Hackvertor
evaluates nested inline tags (<@base64>...</@base64>, <@uuid/>). Invoke
Extension calls a processor you registered, and an {oastify} placeholder mints a
fresh OOB token on every request.
Skip If Match drops any payload matching a regex. Skip If Bambda gates each
payload through a Bambda predicate — the same expression language as intercept
rules, with the payload mounted as req.body. Cull the payloads you never wanted
to send.
Reliability and evasion
Cap requests per second with a token bucket, or ramp linearly from a slow start to a target rate over a set number of seconds and then hold — a warmup that avoids the thundering-herd spike a rate-aware WAF watches for. Add a fixed throttle between requests, with optional random jitter.
Adaptive auto-throttle adds delay every time the target returns a status you name (usually 429 or 503) and recovers after 100 clean responses. Failed requests retry with exponential backoff.
Set the worker count and a per-host cap, or use the turbo path with per-host connections and an HTTP/1.1 pipeline depth. The single-packet race mode dispatches its window (default 20) as concurrent HTTP/2 streams on one connection.
Snapshot the cookie jar per attack so one request's Set-Cookie can't bleed into
the next and skew a differential test. Route a single attack through its own
upstream proxy (HTTP, HTTPS, or SOCKS5). Shuffle payload order with a seed —
random, but repeatable.
Abort after N errors or N grep matches, so a broken target or an early hit doesn't burn the whole run. A resume cursor restarts a killed attack from the last completed request instead of from zero.
Reading results
The results table is one row per request — index, payload, status, length, time, TTFB, retries, a response hash, and any error. Sort by any column; the outliers are the story (a different length, a 200 in a wall of 403s, a slow response). Add grep match/extract rules (over headers or body, contains/regex/equals) to pull a token or flag a marker into its own column.
Triage
Group every probe by a hash of its response body. A 100k-request run collapses into the handful of distinct responses behind it, and the smallest bucket — the one response that didn't look like the other 99,000 — is usually the bug.
Status-code and response-time distributions show the shape of a run at a glance: the lone 200 in a wall of 403s, or the request that took ten times as long as the rest.
Send any row to Findings as evidence. Auto-finding rules promote a row the moment its status code or body matches a pattern you set, so you don't click through 100k rows to catch the one that landed.
Dry-run shows the request count and the exact payloads before you send anything — catch a million-request Cluster Bomb before it leaves your machine. Export results to CSV or JSON, and save an attack config to reload and re-run later.
Cluster Bomb is multiplicative — two lists of 1,000 is a million requests. Start small, watch the rate, and keep it in scope.
For randomness testing use Sequencer; for payload encoding use Decoder.