Intercepting QUIC and HTTP/3 Traffic When mitmproxy Isn't Enough
How to intercept QUIC v1 and raw HTTP/3 traffic from desktop apps with InterceptSuite, and how it compares with mitmproxy's experimental QUIC support.
InterceptSuite Team
QUIC is the UDP-based transport behind HTTP/3. More desktop apps, SDKs and background services now use it, and TCP-oriented proxies cannot see it. Many testers fall back to blocking UDP/443 so the app downgrades to TCP, which changes the behaviour you are trying to study.
What the options look like
- mitmproxy supports HTTP/3 and QUIC v1 (full HTTP/3 support arrived in version 11), but only in its reverse proxy, transparent, WireGuard and local capture modes. It does not support QUIC in its regular (HTTP CONNECT) or SOCKS5 modes, because those carry TCP only. Its docs also note that client replay for HTTP/3 is broken and that HTTP/3 has mostly been tested with cURL. If you can capture traffic with one of those modes and your target works, it is a reasonable first try.
- Blocking QUIC forces a fallback to HTTP/2 over TLS. It is simple, but you no longer observe the real QUIC path.
- InterceptSuite intercepts QUIC v1 as an active MITM through its normal SOCKS5 proxy, so you can point an application at it like any SOCKS5 proxy. Every stream of a connection is relayed, and several connections from one application work together. HTTP/3 over QUIC is shown as raw bytes in History, Intercept and Replay, and the HTTP/3 extension decodes and re-encodes it as readable HTTP.
Intercepting QUIC with InterceptSuite
- Start InterceptSuite and trust its CA as described in the quick start.
- Point the target at the SOCKS5 listener, or route a proxy-unaware app through ProxyBridge with a UDP rule.
- Open Proxy History. QUIC connections appear with host, port and ALPN (
h3for HTTP/3). - Select a packet to read the stream bytes. Use the hex editor to change them when Intercept is on.
- Right-click a packet and choose Send to Replay to resend it, or open the Replay tab and enter the host and port yourself. Set ALPN to
h3for HTTP/3.
Decode HTTP/3 with an extension
The core shows the raw QUIC stream bytes. To read HTTP/3 as plain HTTP, add the official HTTP/3 extension. It decodes request and response streams into readable text (method, URL, QPACK headers and the decompressed body) in its own tab, and re-encodes your edits, including headers, frame lengths and content-length, so you can change a request and forward or replay it. Get it from the Extension repository.
Need a different view? Extensions are plain Python files, so you can write your own decoder for any protocol. See the extension API reference.
Things to know
- QUIC v1 only. QUIC v2 is not supported yet.
- ECH. Connections that use Encrypted Client Hello cannot be intercepted.
- Your SOCKS5 proxy must handle UDP. A SOCKS5 server that offers UDP ASSOCIATE does not by itself handle QUIC. InterceptSuite does, and ProxyBridge's UDP rules send the traffic to it.
Which should you use?
If you need decoded HTTP/3 in a browser-style, HTTP-centred workflow and can use reverse, transparent, WireGuard or local capture mode, try mitmproxy first. If you want to point an application at a regular SOCKS5 proxy, the traffic comes from a desktop app, it mixes in DTLS or raw UDP, or you want Replay and rules in a GUI, use InterceptSuite. See the protocol compatibility matrix for the current limits, or the full comparison.
Start the 7-day trial and test it on your own target.
