The local-first web security proxy built for modern bug hunting.
HTTP/2, WebSocket replay, mobile interception, Frida cert-pinning bypass, response diffing, and IDOR/BOLA replay in one desktop app.
Alpha testing is closed. Private beta is next.
- Burp-compatible project import. Bring existing traffic forward without rebuilding scope.
- Modern protocol coverage. HTTP/2 upstream, WebSocket replay, response diffing, and local project history in one app.
- Mobile and identity workflows built in. Frida, APK lab, identity replay, Beacon/OAST, JA3, MCP, and plugins share the same local project.
.js: hook + form + right-click + CLI. Hot-reload. Share as a gist.sql, hunt, llm. Your agent does real work.Find the workflow for the bug class.
Crusader is broad on purpose: proxy, mobile, identity replay, JA3 transport, SQL, plugins, and agents all feed the same local project. These hubs collect the best starting points by testing job.
Web security proxy
Capture HTTP/2 and WebSocket traffic, replay requests, query history, scan passively, import projects, and automate from one local workspace.
Mobile app security testing
Android lab setup, system CA trust, Frida cert-pinning bypass, mTLS extraction, and APK/XAPK/APKS static analysis.
IDOR and BOLA testing
Capture two actors, replay scoped requests across identities, compare responses, and promote evidenced authorization findings.
JA3 browser fingerprinting
Understand JA3, JA4, HTTP/2, header order, FoxyProxy tradeoffs, and when the built-in browser is the right path.
Agentic security testing
MCP, JSON CLI, read-only SQL, local project memory, plugins, scoped planning, and human-gated active workflows.
Not a deck.
The actual workstation.
Real screens from Crusader running a live session — intercept proxy, Repeater with response diffing, a full Site Map, and analysis a stock proxy doesn't ship.
Capture → Replay →
Attack → Promote.
A whole bug-bounty session, in four moves. The same captured exchange flows from the proxy into the Repeater, into Attack Studio, into a finding — without leaving the project, without re-pasting, without three windows on top of each other.
Capture.
From any actor.
Browse through the proxy. Pipe a curl through crusader send. Hit a mobile app with Frida-killed pinning. Let your agent do it through MCP. Every capture lands in one shared history.
Replay.
Diffed automatically.
Right-click → Send to Repeater. Tweak. Send. The new response is diffed against the last — line-level inserts, deletes, token changes colored. Token placeholders mean you don't paste a bearer into a hundred requests.
Attack.
Clustered, not dumped.
One click into Attack Studio. Sweep IDs, fuzz params, brute paths. Anomalies cluster by response signature — you scan five rows instead of fifty. The outlier is the lead. Or hit crusader hunt and the agent does the whole pass.
Promote.
To finding or plugin.
The interesting capture becomes a tracked finding, a JavaScript plugin (so it runs on every future request), a CLI command (so CI catches the regression), or an MCP tool call. Same captured truth. Different actor.
Yesterday's traffic.
Today's attacks.
Drop a .burp file on Crusader's startup screen and it becomes a live workspace. Proxy history, site map, scope, scanner issues, notes all read in and re-indexed against Crusader's SQLite. Then every Crusader feature works against that captured history — diffs, Attack Studio, Frida replays, Identity Shadow Replay, plugins, agents. The switching cost is one drag-and-drop.
Fourteen days of Pro.
Email only. No card.
Beta access starts with the Free tier and no account or card. When you're ready, start the 14-day Hunter Pro trial inside the app with email only — every feature unlocked, every workflow available, no card and no sales call.
The moat is architectural.
Most proxy features are surface-level — a button you didn't have, a panel you wanted. These four are foundational. Each one used to mean another tool, another script, or a workflow you didn't have time for.
Everything Burp Pro does.
Then the part it can't.
The real fear in switching proxies isn't learning a new UI — it's the one feature you rely on quietly going missing. So here's the whole checklist: every Burp Pro capability, matched line for line, before we get to the four things Burp doesn't ship at all.
Write it once.
Call it from anywhere.
Every JavaScript plugin you write is automatically a side-panel form, a right-click action, a CLI verb, and an MCP tool. Every CLI verb emits structured JSON on stdout. Every MCP call returns the same JSON, awaited. Pipe through shell. Chain through an agent. Same primitives.
Three hackers.
One workspace.
Bug-bounty crews shouldn't email project files around. Squad publishes a redacted project snapshot — findings, Repeater & Intruder tabs, identities — to a shared team endpoint, so the whole crew works from one workspace. Live presence, soft locks, and claimable tabs are rolling out during early access.
Free for the work.
Paid for the team.
Hunter Pro is $499/year — exactly what Burp Pro costs. Your AppSec budget doesn't change to switch. The free tier ships a daily-driver proxy. Squad replaces passing project files around. Founder's Edition is the cheapest seat this product will ever sell.
Free
Local proxy. HTTP/2 + WebSocket. History. Repeater (with diff). Decoder. Comparer. Unlimited JS plugins. CLI basics. Project import. Forever.
Hunter Pro
Everything in Free, unlocked. Attack Studio, Scanner, Beacon/OAST, Mobile + Frida, JA3 transport, Identity Shadow Replay, One-Button Hunt, MCP server, full CLI. Commercial use.
Squad early access
A full Hunter Pro seat for everyone + a shared team workspace. Publish findings, Repeater/Intruder tabs, and identities to one project. Live presence, soft locks & tab-claiming are rolling out in early access.
Team Pro
Squad for a whole org. SSO / SAML / SCIM, role-based access, assignment boards, a full audit trail, private extension packs, and a pooled Beacon quota across the team.
Self-Hosted Team
Team Pro on your own infrastructure. The shared workspace and Beacon run inside your network — nothing leaves your perimeter. Built for regulated and air-gapped teams.
Enterprise
Everything, plus data residency, a private extension registry, hosted AI credits, and SSO at scale — with procurement, MSA, security review, and priority support.
The questions
everyone asks first.
Do I lose my Burp work if I switch?
No. Drag a .burp file onto Crusader's startup screen and it becomes a live workspace — history, site map, scope, scanner issues, notes and highlights all import and re-index. Caido (beta), HAR, and Fiddler SAZ work the same way. Your original file stays untouched on disk.
What do I actually get for free, forever?
A real daily driver: the HTTP/2 + WebSocket proxy, history, Repeater with diff, Decoder, Comparer, unlimited JavaScript plugins, CLI basics, and project import. No account, no app usage telemetry, no time-bomb — and it out-features Burp Community.
How do I get beta access?
Public alpha testing is closed. Join the beta waitlist for upcoming Windows, Debian/Ubuntu Linux, and macOS testing invitations. Existing alpha testers keep access to their current builds and software updates.
Is my data private?
Local-first. Everything lives in a SQLite database on your machine, and the app has no product analytics or usage telemetry. Its Crusader service calls are limited to optional software update checks and paid licensing checks. User-triggered Team Mode and “Review diff” send only the data needed for the feature you configured.
Does it have a Collaborator / OAST server?
Yes — Beacon is built in. DNS, HTTP, and SMTP callbacks with geo/ASN, email alerts, and one-click promote-to-finding for blind SSRF, XXE, and out-of-band injection. No separate hosted add-on to configure — and you can run Beacon on your own server: self-hosted OAST is included on a single Hunter Pro seat, not gated behind a team or enterprise plan. (Burp's private Collaborator server is Enterprise-only.)
What happens when the 14 days end?
You drop to the free tier and keep everything you captured — history, identities, comments, and every plugin you wrote keep running. The trial never took a card, so there's nothing to cancel. Upgrade is one click whenever you're ready.
Alpha proved it.
Beta sharpens it.
Public alpha testing is closed. Join the list for the next testing wave and tell us where Crusader can matter most in your workflow.
- Invitations will roll out in controlled groups.
- Windows, Debian/Ubuntu Linux, and macOS interest is open.
- Existing alpha testers keep their current builds and update access.
Request beta access
Tell us what you test so the right builds reach the right people first.