← All cheat sheets

CAIDO

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Modern web security testing proxy. Fast, lightweight alternative
to Burp Suite with a clean UI and efficient workflow.

INSTALLATION#

# Download from https://caido.io/download
# Available for: Linux, macOS, Windows

# Linux (AppImage)
chmod +x caido-desktop-linux-x86_64.AppImage
./caido-desktop-linux-x86_64.AppImage

# macOS
# Download .dmg, drag to Applications

# CLI version (headless)
./caido-cli --listen 127.0.0.1:8080

# Docker
docker run -p 8080:8080 caido/caido

SETUP#

# 1. Start Caido
# 2. Access UI at http://127.0.0.1:8080 (or desktop app)
# 3. Configure browser proxy: 127.0.0.1:8080
# 4. Install CA certificate for HTTPS interception:
#    Settings > CA Certificate > Download
#    Import into browser/system trust store

# FoxyProxy (browser extension) recommended for proxy toggling

CORE FEATURES#


    

INTERCEPT (PROXY)#

# Similar to Burp Proxy
  - Intercept HTTP/S requests and responses
  - Forward, drop, or modify intercepted traffic
  - Breakpoints: pause on matching requests
  - WebSocket support

# Keyboard shortcuts
  Forward request:     Enter
  Drop request:        Delete
  Send to Replay:      R
  Send to Automate:    A

HTTP HISTORY#

# View all proxied traffic
  - Filter by method, status, host, path
  - Search request/response content
  - Color-coded status codes
  - Sort by any column

# Filters
  host:example.com                          # By hostname
  method:POST                               # By HTTP method
  status:200                                # By status code
  path:/api                                 # By path
  ext:json                                  # By extension
  body:password                             # By body content

# Scope
  - Define target scope (domains/paths)
  - Filter history to in-scope only
  - Reduces noise from out-of-scope traffic

REPLAY (REPEATER)#

# Manual request manipulation and resending
  1. Select request from History or Intercept
  2. Send to Replay (right-click or keyboard shortcut)
  3. Modify request as needed
  4. Click Send
  5. Compare responses side-by-side

# Features
  - Multiple tabs for different requests
  - Request/response highlighting
  - Auto-content-length update
  - Follow redirects toggle

AUTOMATE (INTRUDER/FUZZER)#

# Automated request fuzzing and testing
  1. Send request to Automate
  2. Mark insertion points (select text, click Mark)
  3. Choose payload source:
     - Wordlist file
     - Numbers range
     - Custom list
  4. Configure settings:
     - Concurrent connections
     - Delay between requests
     - Follow redirects
  5. Start automation
  6. Analyze results (filter, sort, compare)

# Payload positions
  - Single position: test one parameter
  - Multiple positions: test combinations

# Analysis columns
  - Status code
  - Response length
  - Response time
  - Content-type
  - Custom match (regex/string)

MATCH & REPLACE#

# Auto-modify requests/responses in transit
  - Add/modify headers
  - Replace body content
  - Change methods
  - Useful for:
    - Adding auth headers automatically
    - Bypassing client-side checks
    - Modifying Content-Type
    - Testing header injections

SITEMAP#

# Hierarchical view of discovered content
  - Tree view of hosts and paths
  - Discovered via proxy history
  - Shows HTTP methods per path
  - Useful for understanding application structure

WORKFLOWS (PLUGINS)#

# Caido supports workflow automation
  - Custom JavaScript/TypeScript plugins
  - Convert/encode/decode data
  - Chain operations together
  - Community workflows available

# Built-in conversions
  - Base64 encode/decode
  - URL encode/decode
  - HTML encode/decode
  - Hex encode/decode
  - JSON prettify
  - Hash generation (MD5, SHA1, SHA256)

COMPARE#

# Diff two responses
  - Side-by-side comparison
  - Highlighted differences
  - Useful for testing parameter effects
  - Compare baseline vs modified requests

EXPORT#

# Export requests/responses
  - Copy as cURL command
  - Copy as raw HTTP
  - Export filtered history
  - Save for reporting

TIPS FOR WEB TESTING#

# Authentication testing
  1. Capture login request in History
  2. Send to Replay
  3. Test credential variations
  4. Check for rate limiting
  5. Test session token handling

# Parameter fuzzing
  1. Capture request with parameters
  2. Send to Automate
  3. Mark parameter value
  4. Load wordlist (SecLists recommended)
  5. Analyze response differences

# API testing
  1. Set scope to API base URL
  2. Browse/interact with the app
  3. Review API calls in History
  4. Replay with modified parameters
  5. Test for IDOR, injection, auth bypass

# Header manipulation
  - Add X-Forwarded-For, X-Original-URL headers
  - Test Host header injection
  - Modify Accept, Content-Type headers
  - Test CORS with Origin header

CAIDO VS BURP SUITE#

Feature          Caido              Burp Suite
-------          -----              ----------
Price            Free + Pro ($)     Free + Pro ($449/yr)
Language         Rust               Java
Speed            Very fast          Moderate
UI               Modern, clean      Functional, dated
Extensions       Workflows          BApp Store (huge)
Scanner          Coming/limited     Comprehensive
Intruder         Automate           Intruder
Repeater         Replay             Repeater
Memory           Low                High (Java)
Learning curve   Easy               Moderate
Maturity         Newer              Very mature
Collaboration    Coming             Burp Enterprise
Community        Growing            Very large

KEYBOARD SHORTCUTS#

Ctrl+I          Toggle intercept
Enter           Forward intercepted request
Delete          Drop intercepted request
Ctrl+R          Send to Replay
Ctrl+A          Send to Automate
Ctrl+F          Search/filter
Ctrl+L          Clear history
Ctrl+,          Settings

TIPS#

  - Much faster than Burp due to Rust backend
  - Lower memory footprint than Java-based tools
  - Define scope early to reduce noise
  - Use Match & Replace for persistent header injection
  - Automate is powerful but simpler than Burp Intruder
  - Great for API testing and quick manual testing
  - Export as cURL for scripting/automation
  - Combine with Nuclei for automated vuln scanning
  - Growing ecosystem; check for new workflows regularly
  - Free tier is generous for most pentest needs