Back to browse
Chiral – Pentesting inside Chrome webtools

Chiral – Pentesting inside Chrome webtools

by Parkado·Apr 12, 2026·1 point·0 comments

AI Analysis

●●SolidSolve My ProblemNiche Gem

Burp-lite inside Chrome DevTools without proxy certificates or Java dependencies.

Strengths
  • CDP-powered in-flight interception means zero proxy certificate configuration needed
  • Intruder fuzzing with four attack types built into DevTools panel
Weaknesses
  • Chrome Web Store shows item currently unavailable, can't verify installation
  • Browser-based security testing has inherent limitations versus standalone proxies
Category
Target Audience

Security researchers, web developers doing penetration testing

Similar To

Burp Suite · OWASP ZAP · Requestly

Post Description

I was tired of spinning up Burp for every smaller test I needed to do so I created something that has "Burp-lite" set of features but lives inside Chrome DevTools. Everything is user adjustable, no bloat, no AI, no registration or login, no suspicious cloud connect, no licenses. Just pure Chrome debug API based intercept, fuzzing, attack sequences etc. Added a test for websockets also but out of ideas what to do with it.

Similar Projects

Security●●●Banger

Pentesting Tool Using Claude

Autonomous hunting with Burp MCP integration beats manual recon workflows.

Ship ItSolve My ProblemSlick
ishqdehlvi
312mo ago