
Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing, and HTTPQL filtering.
Fast. Cross-platform. 100% Open Source.
Quick Start · Features · Why Aresius · Install · Roadmap · Community · Releases
Aresius is a native, modern desktop HTTP/HTTPS interception proxy designed for penetration testers and bug bounty hunters.
Intercept and modify requests in real-time, fuzz without artificial rate limits, replay complex sessions with side-by-side diffing, and filter thousands of captured requests using HTTPQL—all with a minimal memory footprint and zero license fees.
Built on Tauri + Rust instead of Java or Electron, Aresius launches in under a second and stays light during long engagements.
git clone https://github.com/0xMarik/Aresius.git
cd Aresius
bun install
bun run tauri dev
On first launch, Aresius automatically generates a local Root CA certificate. Trust it in your browser or operating system, point your proxy to 127.0.0.1:8080, and you're ready to intercept HTTPS traffic.
| Feature | Description |
|---|---|
| 📡 Live Interceptor | Intercept, inspect, tamper with, forward, or drop HTTP/HTTPS requests and responses in real time. |
| 🔁 Request Replayer | Edit and resend captured requests, organize into collections and sessions, and compare responses side-by-side with visual diffing. |
| 🎯 High-Speed Fuzzer | Powerful payload generator supporting Rotator, Zipped, Echo, and Combinatorial fuzzing with real-time dynamic thread scaling. |
| 🔍 HTTPQL & Full-Text Search | Query and filter proxy history in real-time using expressive HTTPQL syntax and SQLite-powered full-text search. |
| 🌲 Sitemap & Scope Manager | Automatic hierarchical endpoint discovery with granular domain and regex-based in-scope/out-of-scope rules. |
| 🔄 Match & Replace | Create automatic replacement rules for incoming and outgoing headers, parameters, and bodies. |
| 🪶 Native Performance | Native Rust backend, tiny installation size, instant startup, and low idle memory consumption (~60–80 MB). |
| 🖥️ Cross-Platform | Consistent, fluid native desktop experience across Windows, macOS, and Linux. |
| Feature | Aresius | Burp Suite (Community) | Caido (Free) |
|---|---|---|---|
| 100% Open Source | ✅ (AGPL-3.0) | ❌ Proprietary | ❌ Proprietary Core |
| Native Architecture | ✅ Rust + Tauri | ❌ Heavy JVM | ✅ Rust + Web |
| Idle Memory Footprint | ✅ ~60–80 MB | ❌ 1.5 GB – 3 GB+ | ✅ ~100–200 MB |
| Unrestricted Fuzzing | ✅ No limits | ❌ Throttled rate | ✅ Fast |
| Full Project Persistence | ✅ SQLite .ares | ❌ Paid Pro only | ⚠️ Limited in free tier |
| Custom Match & Replace | ✅ Yes | ✅ Yes | ✅ Yes |
| Side-by-Side Response Diff | ✅ Built-in | ⚠️ Plugin required | ✅ Built-in |
Download the latest prebuilt installer or binary for your operating system from Releases.
🍎 Note for macOS Users (macOS 15 Sequoia & Gatekeeper):
Because Aresius binaries are distributed directly as open-source community releases without paid Apple notarization, macOS 15 may display a dialog stating "Aresius is damaged and can't be opened".
To open Aresius on macOS:
- Either run this one-line command in your terminal to remove the quarantine attribute:
xattr -cr /Applications/Aresius.app- Or open System Settings > Privacy & Security, scroll to Security, and click Open Anyway.
🪟 Note for Windows Users (SmartScreen):
When first launching, Windows SmartScreen may present an "Unrecognized app" warning. Click More info → Run anyway.
Prerequisites:
git clone https://github.com/0xMarik/Aresius.git
cd Aresius
bun install
bun run tauri build
The compiled binaries will be generated under src-tauri/target/release/bundle/.
Run in development mode with live hot-reloading:
# Run dev server
bun run tauri dev
To run Rust backend unit tests:
cargo test --manifest-path src-tauri/Cargo.toml
Have a feature request or idea? Open a Discussion or join our subreddit!
Aresius decrypts and inspects HTTPS traffic locally on your machine. To maintain strong security hygiene:
CryptProtectData), tying decryption to your authenticated Windows user session.0600 permissions (restricted exclusively to your user UID).Found a security issue in Aresius itself? Please report it responsibly according to SECURITY.md.