Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ferret — The collaborative web app pentest suite | Kitploit
Tools/GitHubGitHub/synlace/ferret
ReconnaissanceDynamic Analysis (Sandboxing)Vulnerability AnalysisWeb Proxies & InterceptionAPI Security TestingInformation GatheringWeb SecurityPenetration TestingAI Security
GitHubsynlace/ferret

ferret

The collaborative web app pentest suite

573142 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View RepositoryWebsite

Ferret

Ferret

The collaborative MITM proxy for security testers.

Capture HTTP traffic, annotate requests with AI, run hunt sessions, replay traffic, and track findings from one interface.

Latest Release Discord License: MIT Build Status Docker on GHCR GitHub Stars

Quick start · Features · Screenshots · Configuration · Security · Contributing


Quick start

Install

git clone https://github.com/synlace/ferret.git
cd ferret

cp .env.example .env   # optional
just up

Or use Docker Compose directly:

docker compose up --build -d

Open Ferret

ServiceURL
UIhttp://localhost:3000
APIhttp://localhost:8000
Proxy127.0.0.1:1337

Open:

http://localhost:3000

The first-run setup wizard will ask you to set a password and choose an AI provider.

Requirements

  • Docker
  • Docker Compose
  • just

Overview

Ferret is an AI-assisted HTTP interception proxy built for security testers.

Point your browser, CLI tool, or testing workflow at:

127.0.0.1:1337

Ferret captures requests and responses, stores them locally, annotates traffic with AI, and gives you tools to replay, modify, test, and turn interesting behaviour into findings.

It is designed for workflows where you want more than a passive proxy: you want something that helps you think, test, and document as you go.


Features

FeatureDescription
Intercepting proxyCapture HTTP and HTTPS traffic through mitmproxy.
Request historyBrowse, filter, inspect, and replay captured traffic.
AI annotationsEnrich requests with security-relevant context.
HuntsRun AI-assisted hunt sessions across captured traffic.
FindingsTrack vulnerabilities with severity, host, type, evidence, and status.
SnareIntercept and modify requests or responses in-flight.
GnawRepeater-style tabs for editing and resending HTTP requests.
WorkspacesPer-session scripts/, tests/, and notes/ directories.
ProjectsSeparate request history, findings, workspaces, and API keys.
AuthenticationPassword login, session cookies, optional API key access, and TOTP 2FA.
Local-first storageSQLite-backed data stored in a local bind-mounted directory.

Screenshots

Hunts

Hunts - AI-assisted hunt sessions that search request history, write and run tests, and create findings.


History

History - A full proxied request log with AI annotations, timings, status codes, and inline request/response editors.


Findings

Findings - A vulnerability tracker with severity, host, type, AI-generated descriptions, and evidence snippets.


Settings

Settings - Manage the CA certificate, password, 2FA, AI provider, API keys, and proxy status.


Setup

Setup wizard - First-run setup for password creation and AI provider configuration.


Using the proxy

Configure your browser, CLI tool, or test client to use:

HTTP proxy:  127.0.0.1:1337
HTTPS proxy: 127.0.0.1:1337

For HTTPS interception, download and install the mitmproxy CA certificate from the Settings page.


Authentication

Ferret requires authentication on every install.

Browser login

  1. Open the UI for the first time.
  2. Set a password in the setup wizard.
  3. Complete AI provider setup.
  4. Log in at /login.
  5. Ferret issues a 24-hour HttpOnly SameSite=Strict session cookie.

Two-factor authentication

TOTP-based 2FA can be enabled from the Settings page.

Once enabled, a valid authenticator code is required at login.

API access

Set a static API key in .env:

FERRET_API_KEY=your-random-secret

Then use it as a Bearer token:

curl -H "Authorization: Bearer your-random-secret" \
  http://localhost:8000/api/requests

Session cookies and Bearer tokens are checked independently.


Configuration

Copy .env.example to .env to preconfigure Ferret.

Most AI provider settings can also be configured from the setup wizard.

VariableDefaultDescription
FERRET_API_KEY-Static Bearer token for programmatic API access
OPENROUTER_MODELgoogle/gemini-3-flash-previewDefault OpenRouter model
PROXY_HOST0.0.0.0Proxy bind address
PROXY_PORT1337Proxy port
UI_PORT3000UI port
FERRET_DATA_DIR./dataPersistent data directory
NEXT_PUBLIC_API_URLhttp://localhost:8000API URL used by the browser
NEXT_PUBLIC_SIGINT_URL-Optional SIGINT/news feed JSON URL

Supported AI providers

Download Tool