Automate browsing, discover application endpoints with recon, and inspect or edit HTTP traffic with websec. Configure sandbox limits and audit the resulting sessions.
The browser runs on its own; recon and websec are optional plugins. Plugin installation →
@ref handles for clicking, typing, and extracting data. Delta snapshots return changes between actions.Build an endpoint inventory from the application and its traffic. Recon reference →
Inspect and test browser traffic for authorized web red teaming, pentesting, and CTFs. Web security guide →
Sandbox the entire red-teaming workflow to constrain tools. Policy guide →
Review actions and network activity, including blocked requests. The dashboard brings active sessions, isolation settings, and resource usage into one view.
br_9f3k2a2m agobr_1qf62pjust nowbr_e3263j14m agobr_txrqd11h agobr_9f3k2a
waiting on you
6 refused
req_109GET200req_108, order=1042Install h5i with the recon and websec plugins. Local-first, open source, Apache 2.0.
curl -fsSL https://h5i.dev/install.sh | sh -s -- --websec --recon
Compare with Burp Suite, OWASP ZAP, or Caido.