Home/Docs/Features/Interception Rules
Features

Interception Rules

Hold only the packets you care about, separately for client to server and server to client.

Interception Rules

Choose which packets are held in the Intercept tab instead of holding every one.

Rules and the direction switches live in Proxy > Settings > Interception Rules.

How a packet is held

A packet is held only if all three checks say yes, in this order:

  1. Intercept button (Intercept tab) is ON. If it is off, everything is forwarded and the rules are ignored.
  2. Direction is ticked: Client → Server, Server → Client, or both.
  3. Rules for that direction:
    • No rules: every packet in that direction is held.
    • Rules: only packets that match are held.

No rules means everything, not nothing. The direction tick says whether you care about a direction at all; rules narrow it down.

Defaults

Intercept button Client → Server Server → Client
Fresh install Off Ticked, no rules Unticked, no rules

The first time you turn Intercept on, every request is held and no responses are.

Each direction has its own rules

The Settings tab shows two lists, one for Client → Server and one for Server → Client. A rule in one list never affects the other. Use this to, for example, hold every request to one host but only the large responses.

Writing a rule

Click Add under a list. Each rule has:

Column Meaning
Enabled Untick to switch a rule off without deleting it
Combine How this rule joins the one above: And / Or (not shown on the first rule)
Check What to look at
Comparison How to compare it
Value What to compare against

The dialog reads the rule back as a sentence before you save, for example Holds packets where: Port is in range 8000-9000.

Checks

Check Looks at Comparisons
Server host or IP The server's IP address or host name is, is not, in CIDR range, starts with, contains
Port The server's port (in both directions) is, is not, in range, greater than, less than
Protocol TCP, TLS, UDP, DTLS, QUIC is, is not
Packet size Payload size in bytes is, is not, in range, greater than, less than
Payload The packet bytes contains, does not contain
Scope in scope or out of scope (see Scope) is, is not

Only the comparisons that make sense for the chosen check are offered.

Host names

Server host or IP accepts a host name as well as an address. example.com is compared with the name the client asked for (the TLS server name, or the domain it gave the SOCKS5 proxy) and with the IP.

  • is not and does not contain hold only when neither the address nor the name matches.
  • A name is known only if the client sent one. Plain TCP through curl --socks5 sends an IP, so only the address is seen; use --socks5-hostname to pass the name.

Evaluation order

Rules are evaluated top to bottom, left to right, with no precedence, like Burp:

row 1:        port is 443           -> true
row 2:  Or    port is 80            -> (true or false)  = true
row 3:  And   protocol is UDP       -> (true and false) = false   (not held)

a or b and c means ((a or b) and c). To group differently, reorder the rows.

Examples

Port           is               443            hold only HTTPS
Server host    is               api.example.com
Server host    in CIDR range    10.0.0.0/8
Protocol       is not           QUIC
Packet size    greater than     4096           skip small control messages
Payload        contains         password
Scope          is               in scope       only the target you are testing

Notes

  • STARTTLS: before the upgrade the traffic is TCP, after it TLS. Protocol is TCP catches the plain phase, Protocol is TLS the rest.
  • Connection ID is not a check. It is a counter that changes between sessions, so it cannot identify a conversation reliably. Use host, port or protocol instead.
  • Rules are saved with your project.