Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
Aresius — Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing, and HTTPQL filtering. | Kitploit
Herramientas/GitHubGitHub/0xmarik/aresius
Vulnerability AnalysisWeb Proxies & InterceptionWeb Application ExploitationAPI Security TestingInformation GatheringWeb SecurityFuzzingPenetration TestingUtilities & Frameworks
GitHub0xmarik/aresius

Aresius

Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing, and HTTPQL filtering.

779hace 18 díasAún no revisado
Ver Repositorio

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.
Aresius Logo

Aresius

The lightweight, native interception proxy for security testing.

Fast. Cross-platform. 100% Open Source.

License Release Stars Reddit Community Built with Tauri + Rust

Quick Start · Features · Why Aresius · Install · Roadmap · Community · Releases

Aresius screenshot

⚡ What is Aresius?

Aresius is a native, modern desktop HTTP/HTTPS interception proxy designed for penetration testers and bug bounty hunters.

Intercept and modify requests in real-time, fuzz without artificial rate limits, replay complex sessions with side-by-side diffing, and filter thousands of captured requests using HTTPQL—all with a minimal memory footprint and zero license fees.

Built on Tauri + Rust instead of Java or Electron, Aresius launches in under a second and stays light during long engagements.


🚀 Quick Start

git clone https://github.com/0xMarik/Aresius.git
cd Aresius
bun install
bun run tauri dev

On first launch, Aresius automatically generates a local Root CA certificate. Trust it in your browser or operating system, point your proxy to 127.0.0.1:8080, and you're ready to intercept HTTPS traffic.


✨ Features

FeatureDescription
📡 Live InterceptorIntercept, inspect, tamper with, forward, or drop HTTP/HTTPS requests and responses in real time.
🔁 Request ReplayerEdit and resend captured requests, organize into collections and sessions, and compare responses side-by-side with visual diffing.
🎯 High-Speed FuzzerPowerful payload generator supporting Rotator, Zipped, Echo, and Combinatorial fuzzing with real-time dynamic thread scaling.
🔍 HTTPQL & Full-Text SearchQuery and filter proxy history in real-time using expressive HTTPQL syntax and SQLite-powered full-text search.
🌲 Sitemap & Scope ManagerAutomatic hierarchical endpoint discovery with granular domain and regex-based in-scope/out-of-scope rules.
🔄 Match & ReplaceCreate automatic replacement rules for incoming and outgoing headers, parameters, and bodies.
🪶 Native PerformanceNative Rust backend, tiny installation size, instant startup, and low idle memory consumption (~60–80 MB).
🖥️ Cross-PlatformConsistent, fluid native desktop experience across Windows, macOS, and Linux.

🥊 Why Aresius?

FeatureAresiusBurp Suite (Community)Caido (Free)
100% Open Source✅ (AGPL-3.0)❌ Proprietary❌ Proprietary Core
Native Architecture✅ Rust + Tauri❌ Heavy JVM✅ Rust + Web
Idle Memory Footprint✅ ~60–80 MB❌ 1.5 GB – 3 GB+✅ ~100–200 MB
Unrestricted Fuzzing✅ No limits❌ Throttled rate✅ Fast
Full Project Persistence✅ SQLite .ares❌ Paid Pro only⚠️ Limited in free tier
Custom Match & Replace✅ Yes✅ Yes✅ Yes
Side-by-Side Response Diff✅ Built-in⚠️ Plugin required✅ Built-in

📦 Installation

Prebuilt Binaries

Download the latest prebuilt installer or binary for your operating system from Releases.

🍎 Note for macOS Users (macOS 15 Sequoia & Gatekeeper):
Because Aresius binaries are distributed directly as open-source community releases without paid Apple notarization, macOS 15 may display a dialog stating "Aresius is damaged and can't be opened".
To open Aresius on macOS:

  • Either run this one-line command in your terminal to remove the quarantine attribute:
    xattr -cr /Applications/Aresius.app
    
  • Or open System Settings > Privacy & Security, scroll to Security, and click Open Anyway.

🪟 Note for Windows Users (SmartScreen):
When first launching, Windows SmartScreen may present an "Unrecognized app" warning. Click More info → Run anyway.

Build from Source

Prerequisites:

  • Rust (stable)
  • Bun (or Node.js)
  • Tauri Prerequisites for your OS
git clone https://github.com/0xMarik/Aresius.git
cd Aresius
bun install
bun run tauri build

The compiled binaries will be generated under src-tauri/target/release/bundle/.


🛠️ Development

Run in development mode with live hot-reloading:

# Run dev server
bun run tauri dev

To run Rust backend unit tests:

cargo test --manifest-path src-tauri/Cargo.toml

🗺️ Roadmap

  • Plugin Ecosystem: Extensible JavaScript/TypeScript SDK for custom sidebar views, context menus, and workflow automation.
  • Business Logic Flow Mapper: Visual node-graph canvas to model multi-step user journeys and detect IDORs, BOLA, and state bypasses.
  • Modular Scanner Engine: Passive vulnerability inspection (CORS, sensitive leaks, missing headers) and active check plugins.
  • WebSocket Interception: Deep inspection, tampering, and replay for WebSocket frames.

Have a feature request or idea? Open a Discussion or join our subreddit!


💬 Community

  • Reddit: r/aresius — Join for weekly feature demos, development updates, and tips.
  • GitHub Discussions: Discussions — Ask questions, suggest features, and discuss workflows.
  • Issue Tracker: Issues — Report bugs or submit feature suggestions.

🔒 Security & Root CA Storage

Aresius decrypts and inspects HTTPS traffic locally on your machine. To maintain strong security hygiene:

  • Per-installation CA: A unique Root CA certificate is generated per installation—no shared, hardcoded, or static private keys.
  • Protected at rest:
    • On Windows, the CA private key is encrypted at rest using Windows DPAPI (CryptProtectData), tying decryption to your authenticated Windows user session.
    • On macOS & Linux, the private key file is created with strict POSIX 0600 permissions (restricted exclusively to your user UID).
  • One-click Revocation: You can regenerate or uninstall the CA certificate from the OS trust store at any time directly in Aresius Settings.

Found a security issue in Aresius itself? Please report it responsibly according to SECURITY.md.


🤝 Contributing

Descargar herramienta