Interception Rules
Hold only the packets you care about, separately for client to server and server to client.
Interception Rules
Choose which packets are held in the Intercept tab instead of holding every one.
Rules and the direction switches live in Proxy > Settings > Interception Rules.
How a packet is held
A packet is held only if all three checks say yes, in this order:
- Intercept button (Intercept tab) is ON. If it is off, everything is forwarded and the rules are ignored.
- Direction is ticked: Client → Server, Server → Client, or both.
- Rules for that direction:
- No rules: every packet in that direction is held.
- Rules: only packets that match are held.
No rules means everything, not nothing. The direction tick says whether you care about a direction at all; rules narrow it down.
Defaults
| Intercept button | Client → Server | Server → Client | |
|---|---|---|---|
| Fresh install | Off | Ticked, no rules | Unticked, no rules |
The first time you turn Intercept on, every request is held and no responses are.
Each direction has its own rules
The Settings tab shows two lists, one for Client → Server and one for Server → Client. A rule in one list never affects the other. Use this to, for example, hold every request to one host but only the large responses.
Writing a rule
Click Add under a list. Each rule has:
| Column | Meaning |
|---|---|
| Enabled | Untick to switch a rule off without deleting it |
| Combine | How this rule joins the one above: And / Or (not shown on the first rule) |
| Check | What to look at |
| Comparison | How to compare it |
| Value | What to compare against |
The dialog reads the rule back as a sentence before you save, for example Holds packets where: Port is in range 8000-9000.
Checks
| Check | Looks at | Comparisons |
|---|---|---|
| Server host or IP | The server's IP address or host name | is, is not, in CIDR range, starts with, contains |
| Port | The server's port (in both directions) | is, is not, in range, greater than, less than |
| Protocol | TCP, TLS, UDP, DTLS, QUIC |
is, is not |
| Packet size | Payload size in bytes | is, is not, in range, greater than, less than |
| Payload | The packet bytes | contains, does not contain |
| Scope | in scope or out of scope (see Scope) |
is, is not |
Only the comparisons that make sense for the chosen check are offered.
Host names
Server host or IP accepts a host name as well as an address. example.com is compared with the name the client asked for (the TLS server name, or the domain it gave the SOCKS5 proxy) and with the IP.
is notanddoes not containhold only when neither the address nor the name matches.- A name is known only if the client sent one. Plain TCP through
curl --socks5sends an IP, so only the address is seen; use--socks5-hostnameto pass the name.
Evaluation order
Rules are evaluated top to bottom, left to right, with no precedence, like Burp:
row 1: port is 443 -> true
row 2: Or port is 80 -> (true or false) = true
row 3: And protocol is UDP -> (true and false) = false (not held)
a or b and c means ((a or b) and c). To group differently, reorder the rows.
Examples
Port is 443 hold only HTTPS
Server host is api.example.com
Server host in CIDR range 10.0.0.0/8
Protocol is not QUIC
Packet size greater than 4096 skip small control messages
Payload contains password
Scope is in scope only the target you are testing
Notes
- STARTTLS: before the upgrade the traffic is
TCP, after itTLS.Protocol is TCPcatches the plain phase,Protocol is TLSthe rest. - Connection ID is not a check. It is a counter that changes between sessions, so it cannot identify a conversation reliably. Use host, port or protocol instead.
- Rules are saved with your project.
