Home/Blog/mitm_relay, NoPE, PETEP and Deluder Alternatives: Non-HTTP MITM Proxies Compared
mitm_relayNoPEPETEPDeluderThick ClientBurp SuiteAlternatives

mitm_relay, NoPE, PETEP and Deluder Alternatives: Non-HTTP MITM Proxies Compared

An honest comparison of the free tools pentesters use to intercept non-HTTP thick client traffic - mitm_relay, NoPE, PETEP and Deluder - and where InterceptSuite fits as a native GUI alternative.

I

InterceptSuite Team

October 6, 2026·7 min read

Burp Suite is built for HTTP. When a thick client speaks raw TCP, TLS or a custom binary protocol, testers reach for a small set of tools that bolt non-HTTP support onto Burp or replace it: mitm_relay, NoPE, PETEP and Deluder. They are all free, they all work, and each makes a different trade-off.

This page compares them fairly, including where they are the better choice, and where InterceptSuite fits.

The short version

Tool How it works You need Typical use
mitm_relay A Python script that relays raw TCP/UDP and hands the data to Burp (or another tool) Python, Burp, a way to redirect the client Quick TCP/TLS relaying into an existing Burp workflow
NoPE Proxy A Burp extension that adds a non-HTTP proxy and shows packets in Burp Burp Suite Staying inside Burp for HTTP and non-HTTP together
PETEP A Java tool for penetration testing of non-HTTP thick clients, with its own proxy and editor Java A dedicated, free non-HTTP testing tool
Deluder Hooks the application's own network and TLS calls so a proxy-unaware app can be intercepted Per-process hooking Apps that ignore proxy settings and certificate stores
InterceptSuite A native desktop SOCKS5 MITM proxy for TCP, TLS, DTLS, QUIC and UDP, with rules, Replay and Scope A licence after the 7-day trial One GUI for non-HTTP interception, with ProxyBridge to route proxy-unaware apps

When the free tools are the right call

  • You already live in Burp and only need occasional non-HTTP traffic. NoPE or mitm_relay keep everything in one window and cost nothing.
  • You want to script it yourself. mitm_relay is small and easy to read and change.
  • You need to hook a specific application. Deluder's approach of working inside the process helps when the app pins certificates or ignores the system proxy.

If one of those describes your job, use them. They are good tools.

Where people outgrow them

The same issues come up again and again in thick client engagements:

  • DTLS and QUIC. Datagram-based encrypted protocols are the awkward part of most relay-style setups. InterceptSuite handles DTLS 1.0/1.2 and QUIC v1 directly.
  • Everything in one place. With a relay or an extension you are juggling a script, Burp and a redirect rule. InterceptSuite is one app: a SOCKS5 listener, Proxy History with a search box that takes expressions like port == 443 and data contains "token", and interception rules that hold only the packets you care about, per direction.
  • Repeater for non-HTTP. Replay lets you resend and edit packets over TCP, TLS, STARTTLS, UDP, DTLS and QUIC, the way Burp's Repeater does for HTTP.
  • Scope and noise. Scope filters history and interception to your targets, so background traffic does not bury the test.
  • Pinned apps. TLS pass-through relays selected targets untouched while you work on everything else.
  • Python decoding. Extensions decode and edit a protocol in a custom tab.

Proxy-unaware applications

Most thick clients do not honour proxy settings. The usual answers are hooking (Deluder), DNS or hosts tricks, or a transparent redirect. InterceptSuite uses ProxyBridge, a free open-source tool that redirects TCP and UDP from chosen processes into the SOCKS5 listener on Windows, macOS and Linux, with no changes to the target app.

Try it on a real target

Start the 7-day trial, route one thick client through ProxyBridge, and compare the result with your current setup. For a longer walkthrough, read Burp Suite Not Intercepting Thick Client Traffic? or the full comparison with mitmproxy, Burp Suite and Echo Mirage.

Ready to intercept non-HTTP traffic?

InterceptSuite is the only native GUI MITM proxy for TCP, TLS, DTLS & UDP - used by penetration testers and protocol engineers worldwide.