IoT Traffic Interception: MQTT, CoAP, DTLS and QUIC (Guide Hub)
A starting point for intercepting IoT and embedded device traffic: what MQTT, CoAP, DTLS and QUIC need, how to route a device through a proxy, and the guides to follow.
InterceptSuite Team
IoT devices rarely speak HTTP. They use MQTT over TCP, CoAP and DTLS over UDP, and increasingly QUIC. A web proxy sees none of it. This hub explains what each needs and links to the step-by-step guides.
Last updated 6 October 2026.
1. Get the device's traffic into the proxy
Most embedded devices have no proxy setting. Your options:
- Put the device behind a gateway you control. Route its traffic through a machine running a transparent redirector into InterceptSuite's SOCKS5 listener. ProxyBridge is a free open-source redirector for Windows, macOS and Linux.
- Use the companion app. If a phone or desktop app controls the device, intercept that app instead.
- Point the device at your listener when it lets you set a broker or server address.
2. Pick the protocol
| Protocol | Transport | What to look for | Guide |
|---|---|---|---|
| MQTT | TCP 1883, TLS 8883 | Client ID, credentials, topics, payloads, retained messages | Intercepting MQTT traffic |
| CoAP over DTLS | UDP 5684 | Resource paths, pre-shared keys in use, unauthenticated writes | IoT DTLS and UDP testing |
| Custom TCP or UDP | Any | Length fields, command bytes, replayable messages | Replay for custom protocols |
| QUIC / HTTP/3 | UDP 443 | Streams, ALPN h3, raw payloads |
QUIC and HTTP/3 guide |
| STARTTLS services | TCP | Plain commands before the TLS upgrade | STARTTLS with Replay |
3. Test like a protocol, not a website
- Check whether credentials or tokens appear in plain text.
- Resend a captured command from Replay to see if the device accepts duplicates.
- Edit one field at a time in the hex editor and watch the reply.
- Map findings to the OWASP Desktop App Top 10 insecure-communication checks in this DA7 guide.
Protocol limits to know
DTLS 1.0 and 1.2 are supported, DTLS 1.3 is not yet. QUIC v1 is supported, QUIC v2 is not yet. Devices using Encrypted Client Hello cannot be intercepted. See the compatibility matrix.
