Becoming a Caido Power User
Justin Gardner (Adviser for Caido)
Bug Bounty Village @ DEF CON 33 · Day 1 · Bug Bounty Village
Overview
In this insightful presentation, Justin Gardner, a prominent bug bounty hunter, podcast host, and adviser for Caido, takes the stage to illuminate how security researchers can transform into "Caido power users." The talk centers on Caido, an advanced HTTP proxy designed to be a seamless extension of the hacker, aiming to reduce friction and enhance efficiency in understanding applications and implementing attack vectors. Gardner, a fervent daily user of Caido even before his advisory role, passionately asserts its revolutionary impact on his hacking methodology and success.

Key moments
- 0:00 Introduction to Caido and talk's core goal
- 1:00 Where hackers spend 90% of their time
- 2:00 Caido features addressing common hacking challenges
- 4:05 Sneak peek: Caido's new micro-agent framework
- 4:15 "Life-changing" navigation highlighter for HTTP history
- 5:30 New "Jump to Row" button for efficient history navigation
Becoming a Caido Power User
Speakers: Justin Gardner (Adviser for Caido)
Conference: Bug Bounty Village
YouTube: https://www.youtube.com/watch?v=_Y0oexpt-R8
Overview
In this insightful presentation, Justin Gardner, a prominent bug bounty hunter, podcast host, and adviser for Caido, takes the stage to illuminate how security researchers can transform into "Caido power users." The talk centers on Caido, an advanced HTTP proxy designed to be a seamless extension of the hacker, aiming to reduce friction and enhance efficiency in understanding applications and implementing attack vectors. Gardner, a fervent daily user of Caido even before his advisory role, passionately asserts its revolutionary impact on his hacking methodology and success.
The core objective of the talk is to highlight specific features within Caido that address common pain points experienced by web hackers using HTTP proxies. These include challenges in orienting oneself within vast HTTP history, effectively filtering irrelevant traffic, comprehending complex application flows, reducing friction in testing difficult configurations, and maintaining organization across numerous requests and findings. By tackling these areas, Caido strives to enable more thorough testing, allowing hackers to uncover impactful vulnerabilities often hidden in hard-to-reach parts of applications.
Gardner’s presentation delves into a comprehensive suite of Caido’s capabilities, ranging from fundamental quality-of-life improvements in navigation and filtering to advanced automation through workflows, AI integration, and collaborative plugins. He emphasizes how these features collectively empower hackers to navigate, analyze, and manipulate web traffic with unprecedented speed and precision, ultimately fostering a state of flow that is crucial for creative and effective vulnerability research, particularly within competitive bug bounty environments.
Background
▶ Watch: Introduction to Caido and talk's core goal (0:00)
The landscape of web application hacking, particularly within the realm of bug bounty programs, demands tools that not only capture and replay HTTP traffic but also facilitate deep analysis and rapid iteration. Justin Gardner observes that hackers typically spend approximately 90% of their time within two primary areas of HTTP proxies: HTTP history and replay. HTTP history is crucial for understanding the application's flow, observing data movement, and comprehending its overall functionality. Replay, on the other hand, is where identified interesting requests are modified and attack vectors are implemented.
Despite their fundamental importance, traditional HTTP proxies often present significant challenges in these core areas. Gardner identifies five key problems that Caido aims to resolve:
- Orientation: Modern web applications generate an enormous volume of requests, including analytics endpoints, third-party APIs, and advertising calls. Navigating this "blown up" HTTP history to pinpoint requests relevant to specific user actions is a major hurdle.
- Filtering: The sheer volume of traffic necessitates advanced filtering capabilities to focus solely on the critical APIs and endpoints that contain potential vulnerabilities, rather than being distracted by noise.
- Comprehension: Beyond individual requests, understanding the holistic function of an application from its HTTP flow can be complex, especially with numerous interdependent requests.
- Implementing Attack Vectors (Reducing Friction): High-friction testing environments, characterized by complex configurations, intricate encoding requirements, or frequent session expiration, often deter thorough testing. This leads to missed vulnerabilities, as impactful bugs frequently reside in these harder-to-reach areas.
- Organization: For many hackers, maintaining organized notes, tracking important requests, and managing numerous replay tabs across different targets is an ongoing struggle, leading to lost context and inefficiency.
Caido's development philosophy directly addresses these issues by focusing on quality-of-life improvements and innovative features, aiming to provide a more intuitive and powerful environment for web penetration testing and bug hunting.
Key Findings
▶ Watch: Caido features addressing common hacking challenges (2:00)
Justin Gardner’s talk unveils a rich array of Caido features designed to elevate a hacker's efficiency and effectiveness, presenting them as key findings and contributions to the field:
- HTTP Request Navigation & Orientation: The Navigation Highlighter workflow, utilizing
sec-fetch-navheaders, visually distinguishes top-level and iframe navigations in HTTP history, enabling rapid orientation. The Jump to Row feature further enhances this by allowing instant navigation to specific requests, saving crucial seconds. - Advanced Filtering with HTTPQL: Caido's HTTPQL (HTTP Query Language) provides a structured, powerful way to search and filter traffic based on granular request/response components, including regex support and time-based queries (e.g.,
created_at). Filters and presets, including custom "common filters" like "1 hour ago," streamline frequently used queries. - Enhanced Organization: The Notes++ plugin offers full Markdown support, image embedding, and crucial context attachment, linking notes directly to specific replay tabs. Collections allow for grouping and managing replay tabs, with quality-of-life features like "open all sessions" and "close left/right" mirroring IDE functionalities.
- Friction Reduction in Replay: Replay Placeholders enable dynamic modification of request values at send time, supporting conversion workflows (e.g., URL encoding, Base64), environmental variables, and automation for tasks like OAuth refreshing or request signing in complex environments.
- Environments as Data Stores: Caido's Environments feature, initially for user-specific configurations, is repurposed by Gardner as a flexible key-value data store, crucial for managing dynamic data like session cookies or API mappings.
- Workflow-Powered Automation: Passive Workflows execute JavaScript nodes (or future dedicated nodes) on every request, allowing for powerful automation like the Auto Session Refresher that continuously updates session cookies in environment variables. Convert Workflows can be assigned to keyboard shortcuts and integrated into the command pallet for instant transformations.
- AI-Assisted Hacking:
- Caido Workflow Developer GPT: A custom OpenAI GPT trained on Caido's JS node documentation to generate complex workflow code.
- Cursor Integration: Allows slurping Caido documentation into Cursor for AI-assisted plugin development.
- Shift Plugin: Caido's integrated AI, accessible via
Shift+Space, can perform actions like converting request formats (e.g., URL-encoded to JSON), capitalizing JSON keys, generating request bodies from JavaScript snippets, creating match and replace rules from natural language prompts, and intelligently renaming replay tabs (e.g., using GraphQL operation names or Google RPC IDs). - Shift Agents (Micro Agent Framework): This pre-release plugin enables the creation of highly specialized AI agents with specific prompts and knowledge bases (e.g., XSS, IDOR, SSRF). These agents can autonomously generate testing plans, execute requests in replay, and identify findings, operating in a "human-in-the-loop" model.
- Collaborative Hacking: The Drop plugin facilitates secure, end-to-end encrypted (PGP) sharing of any Caido object (requests, filters, scope) between collaborators, instantaneously synchronizing work across instances.
- Growing Plugin Ecosystem: A vibrant and accessible plugin development environment is actively fostered, with notable community plugins like Squash (HTTP request cleanup), 403 Bypasser (AI-generated bypass templates), Pam Finder (parameter brute-forcer), Matrix (Authorize.ly equivalent), Data GP (data extraction), Chattio (AI chat), Quick SSRF Compare, and JWT Analyzer.
These findings collectively present Caido not just as an HTTP proxy, but as an integrated, intelligent, and extensible platform designed to maximize hacker productivity and uncover vulnerabilities that might otherwise remain hidden due to tool limitations or workflow friction.
Technical Deep Dive
▶ Watch: Sneak peek: Caido's new micro-agent framework (4:05)
Caido's power stems from its sophisticated architecture and the integration of various components that streamline complex hacking tasks.
HTTPQL: The Query Language for Traffic Analysis
HTTPQL is Caido's structured query language, enabling precise filtering of HTTP history. It operates on four core components: namespace, field, operator, and value. For example, request.extension contains JS targets JavaScript files. Its true power lies in advanced use cases:
- Cookie Source Tracing:
request.raw does not contain ABC123 and response.contains set cookie x abc123identifies the initial request that sets a specific cookie (x abc123), even if it's reflected in subsequent responses. This is crucial for understanding cookie pollution vectors. - API Version Filtering:
rec.path.re_regex ^/v[1-3]/uses regular expressions (re_regex) to focus on specific API versions (v1 through v3), ignoring newer or irrelevant versions. - CSRF Vulnerability Identification:
rec.host contains API.site.com and request.query_param not contains csurf_param and rec.method not contains gethelps pinpoint non-GET requests to an API host that lack a common CSRF token parameter, potentially indicating a vulnerability. - Client-Side Path Traversal (CSPT) to CSRF:
request.host contains API.site.com and request.method contains putsearches for PUT requests to an API, which could be leveraged in a CSPT scenario to achieve Cross-Site Request Forgery by manipulating the endpoint. - Time-Based Filtering:
created_at.greater_than "2023-10-26T10:00:00Z"allows filtering traffic by creation timestamp. This is simplified by common filters (e.g.,from today,1 hour ago) which dynamically generate the timestamp, making it easy to focus on recent activity in large datasets (even 50GB Caido files).
Navigation and Orientation
The Navigation Highlighter workflow leverages sec-fetch-nav HTTP headers, sent by browsers, to identify top-level page navigations and iframe loads. This workflow marks these primary navigation points in HTTP history, allowing a hacker to quickly orient themselves by looking for the "red line" indicating the last top-level navigation. The Jump to Row feature, while seemingly simple, saves significant time by instantly taking the user to a previously selected request, overcoming the challenge of navigating through thousands of chunked JS files.
Replay Placeholders and Environments
Replay Placeholders allow dynamic modification of request elements (e.g., Authorization: Bearer token) at send time. Users select a value in the replay tab and associate it with a workflow or environmental variable. This enables:
- Automated Token Generation: A workflow can inject a random UUID into a header for fuzzing.
- OAuth Refreshing: A workflow can automatically grab a fresh session cookie from HTTP history and update a global environment variable, which then gets substituted into all relevant replay requests, preventing session expiration.
- Complex Encoding: Workflows can perform multi-stage encoding (e.g., URL encode a payload, then Base64 encode it) before insertion.
Environments, originally for user-specific settings, are effectively used as key-value data stores. These variables can be manually set or dynamically updated by workflows, providing a central repository for dynamic data necessary for complex testing.
Workflows and AI Integration
Caido's workflows are node-based automation sequences. While many complex tasks currently require a JavaScript node for SDK-level interaction, future updates promise more dedicated nodes. The talk highlights a Caido Workflow Developer GPT and Cursor integration, trained on Caido's documentation, capable of generating JavaScript code for workflows, significantly lowering the barrier to entry for automation.
The Shift plugin integrates AI directly into the Caido UI, accessible via Shift+Space. It works by providing the AI with context keys (request, response, selected text, project name) and a user prompt. The AI can then perform various actions:
- Request Transformation: Convert URL-encoded requests to JSON, capitalize JSON keys, or even generate a full request body from a JavaScript snippet, enabling testing of hidden or unshipped client-side features.
- Match and Replace Rule Generation: Create complex regex-based match and replace rules from natural language, such as automatically flipping feature flags (e.g., changing
falsetotruein a nested JSON structure like the Google Jewels example). - Intelligent Tab Renaming: Automatically rename replay tabs based on specific criteria (e.g., GraphQL operation names instead of the generic
/graphqlpath, or Google RPC IDs instead ofbatch execute).
Google RPC ID Mapping Case Study
This case study exemplifies the synergy between passive workflows, environments, and match-and-replace for overcoming complex obfuscation:
- Problem: Google's
batch executeendpoint uses opaque RPC IDs (e.g.,L5A) to identify functions, making traffic unreadable. Human-friendly names exist in associated JavaScript files. - Solution - Passive Workflow:
- A passive workflow is configured to run on
on intercept responsefor every request. - A JavaScript node within this workflow uses a regular expression to extract both the RPC ID and its corresponding human-friendly name from the JS files.
- This pairing is then stored as a key-value entry in a dedicated environment variable (e.g.,
Google RPC IDs), effectively building a dynamic database of RPC ID mappings.
- Solution - Match and Replace with Workflow:
- A match and replace rule is set up to match any request containing
batch executein its first line (using regex). - Instead of a simple string replacement, this rule triggers a custom RPC ID substitutor workflow.
- This workflow iterates through the
Google RPC IDsenvironment variable. If it finds an RPC ID in the currentbatch executerequest that matches an entry in the environment variable, it appends the human-friendly name as an extra query parameter to the request's path.
- Result: The HTTP history, previously showing only
batch executewith cryptic RPC IDs, now displays human-readable paths (e.g.,update user settings), significantly reducing friction and enhancing comprehension, leading to the discovery of a $20k numeric IDOR.
Drop Plugin: End-to-End Encrypted Collaboration
The Drop plugin facilitates secure collaboration by allowing users to share any Caido object (requests, filters, scope) between instances. Its architecture emphasizes security:
- PGP Encryption: All shared data is end-to-end encrypted using PGP.
- Share Codes: Users exchange share codes containing their PGP public key and Base64-encoded name.
- Minimal Database: The central server only stores five fields:
ID,from_public_key,to_public_key,encrypted_data, andcreated_at. No sensitive data is stored in plaintext. - Signed Messages: Messages are cryptographically signed to verify authenticity.
- Self-Hosting: Users can spin up their own Docker instance of the Drop server and even use their own key server for maximum control.
Shift Agents: Micro-Agent Framework for Autonomous Testing
Shift Agents, a pre-release feature, introduces a micro agent framework into Caido. This allows hackers to define specific testing methodologies and have AI agents autonomously execute them within replay tabs.
- Agent Configuration: Users select an AI model (via Open Router for diverse options), provide a specific prompt defining the agent's goal (e.g., "check for IDOR"), and choose a knowledge base (pre-defined for XSS, SSRF, Path Traversal, SQLi, or custom-built).
- Autonomous Execution: The agent generates a procedure and a list of "to-do items," then proceeds to send requests in the replay tab, modifying payloads based on its methodology.
- Human-in-the-Loop: The results are visible in replay, allowing the hacker to review the AI's actions, jump to specific attempts, and verify findings. The agent can also automatically populate findings.
- Use Cases: Automating WAF bypass fuzzing, open redirect fuzzing, and methodology-driven checks for common vulnerability types.
These technical innovations collectively empower Caido users to move beyond manual, repetitive tasks, enabling them to focus on higher-level analysis and creative attack development.
Demo / Proof of Concept
▶ Watch: "Life-changing" navigation highlighter for HTTP history (4:15)
The talk features numerous demonstrations and real-world examples illustrating Caido's capabilities:
- Navigation Highlighter: A visual example of HTTP history with "red lines" indicating top-level navigations, allowing quick identification of page loads versus sub-resource requests.
- Jump to Row: A quick demonstration of clicking the "jump to row" button to instantly navigate to a selected request within a crowded HTTP history.
- HTTPQL Queries: Examples presented on slides showcase the syntax for tracing cookie origins, filtering by API version (
/v[1-3]/), identifying potential CSRF vulnerabilities, and finding put-based CSPT sinks. - Time-Based Filters: A screenshot of a custom filter
rec.created_at is greater than a specific timestampis shown, followed by the introduction of "from today" and "1 hour ago" presets for immediate time-based filtering. - Notes++ Plugin: A visual walkthrough of the Notes++ interface, highlighting full Markdown support and the ability to "attach current context" from a replay tab, creating a live link to the request within the notes.
- Replay Placeholders: A demonstration of selecting an
Authorization: Bearertoken, clicking "add placeholder," and configuring it to insert a random UUID at send time, dynamically changing the token for each request. - Auto Session Refresher Workflow: The JavaScript code for this workflow is displayed, showing how it extracts a
PHPSSIDcookie, performs a host check, and updates a global environment variable, then how this environment variable is selected as a placeholder type in replay. - Google RPC ID Mapping: A "before and after" comparison is shown: initially, the HTTP history displays
batch executerequests with cryptic RPC IDs. After implementing the passive workflow, environment variable updates, and match-and-replace rule, the history now shows human-readable paths (e.g.,update user preferences) appended as query parameters. - Drop Plugin: A visual sequence demonstrates clicking the "share" button on a request, selecting a friend (e.g., "XSS Doctor"), and the recipient receiving a "claim" button to instantly import the shared object into their Caido instance.
- Shift AI Integration:
- A video demonstrates using
Shift+Spaceto prompt Shift to convert anx-www-form-urlencodedrequest to JSON and then to capitalize all JSON keys, all performed instantaneously. - Another key demonstration shows pasting an obfuscated JavaScript snippet (
j.data data = some variable; j.name = some other variable; ... fetch request) into Shift, which then instantly constructs the corresponding HTTP request body in the replay environment. - The Google Jewels case study shows the prompt given to Shift to generate a match and replace rule to change
falsetotruefor specific feature flags within a deeply nested JSON structure, with the resulting regex and action confirmation displayed. - A demonstration of AI renaming replay tabs, with prompts like "use operation name if GraphQL" or "use Google RPC call name" to make tab titles more informative.
- Shift Agents: A live lab demonstration shows an agent being prompted to "check for IDOR." The agent then displays its "thinking" process, generates a "procedure" (e.g., send baseline, create plan), and lists "to-do items" (e.g., test specific parameters). The video shows the agent actively sending requests in replay, and finally populating a finding on the left-hand panel when an IDOR is identified.
These demonstrations collectively underscore Caido's practical utility, showing not just what the features do, but how they are applied in real-world hacking scenarios to save time and reveal vulnerabilities.
Defensive Implications
▶ Watch: New "Jump to Row" button for efficient history navigation (5:30)
The advanced capabilities showcased in Caido, particularly its focus on efficiency and automation, present several critical implications for defenders:
- Obfuscation is Not a Security Boundary: The Google RPC ID mapping case study explicitly demonstrates that complex obfuscation, such as using opaque identifiers for API endpoints, is easily overcome by determined attackers leveraging custom workflows and pattern matching. Defenders should not rely on obfuscation as a primary security control and must ensure that underlying APIs are robustly secured regardless of their obscurity.
- Thorough Session Management is Paramount: The ease with which Caido can automate session refreshes via workflows highlights the need for strong, context-aware session management. Session tokens should not be easily "yoinked" and substituted. Implementations should bind sessions to specific user agents, IP addresses, or other contextual factors to prevent simple cookie replacement attacks.
- Client-Side Logic Reveals Hidden Functionality: The ability of Shift AI to reconstruct request bodies from JavaScript snippets means that any sensitive or unreleased features present in client-side JavaScript can be easily discovered and exploited. Defenders must rigorously audit client-side code for hardcoded API endpoints, hidden feature flags, or sensitive logic that could be abused even if not exposed in the UI.
- Complex Payloads are Easier to Generate: Caido's convert workflows, keyboard shortcuts, and AI integration make generating highly specific, multi-encoded, or deeply nested payloads significantly easier. This implies that input validation and encoding routines must be extremely robust to handle sophisticated attack patterns, rather than relying on the difficulty of manual payload crafting.
- Collaboration Accelerates Discovery: The Drop plugin facilitates rapid, secure sharing of findings and requests among hacking teams. This means vulnerabilities can be discovered and analyzed much faster in a collaborative environment. Organizations should assume that if one hacker finds a weak point, their collaborators will quickly leverage that information.
- AI-Powered Fuzzing and Methodology Execution: Shift Agents demonstrate a future where AI can autonomously apply attack methodologies (e.g., IDOR, WAF bypasses, open redirect fuzzing) at scale. Defenders need to anticipate that common vulnerability patterns will be tested more exhaustively and efficiently. Investing in AI-driven defensive tools or red teaming with AI-powered proxies could provide valuable insights into potential attack surfaces.
- Continuous API Monitoring: Given the ease of filtering and analyzing API traffic with HTTPQL, defenders should implement continuous monitoring and analysis of their own API endpoints to detect anomalous requests or patterns that might indicate exploitation attempts, especially those targeting legacy versions or specific parameters.
In essence, Caido empowers attackers to be more efficient and creative. Defenders must respond by adopting equally sophisticated defensive strategies, moving beyond superficial security measures and focusing on hardening core application logic, robust authentication, and comprehensive input validation.
Key Takeaways
- Efficiency is Key: Caido dramatically boosts hacker efficiency by streamlining core activities in HTTP history and replay, turning mundane tasks into seamless operations through innovative UI/UX improvements.
- Powerful Data Management: Features like HTTPQL for advanced filtering, Notes++ for context-linked organization, and Environments for dynamic data storage allow hackers to manage vast amounts of traffic and information effectively.
- Automation Reduces Friction: Workflows, Replay Placeholders, and Match and Replace rules enable powerful automation for complex scenarios, such as refreshing sessions, handling intricate encoding, and dynamically mapping obfuscated API endpoints, making hard-to-test areas accessible.
- AI Augments Hacker Capabilities: The Shift plugin and Shift Agents integrate AI directly into the hacking workflow, facilitating rapid payload generation, JavaScript analysis, intelligent rule creation, and autonomous methodology execution, acting as an intelligent co-pilot for vulnerability research.
- Collaboration is Supercharged: The Drop plugin provides a secure, end-to-end encrypted platform for instant sharing of Caido objects, significantly enhancing team collaboration and accelerating collective vulnerability discovery.
- A Growing Ecosystem: Caido fosters a vibrant plugin development ecosystem, with community-contributed tools continuously expanding its capabilities and allowing for deep customization to meet diverse hacking needs.
About the Speaker(s)
Justin Gardner, known by his handle RhinoRator, is a prominent figure in the cybersecurity community, serving as an Adviser for Caido. Beyond his role with Caido, he is the host of the "Critical Thinking" podcast, a platform where he frequently shares insights into bug bounty hunting and security research. Gardner is an experienced and full-time participant in live hacking events and a dedicated bug bounty hunter. He emphasizes his deep personal connection to Caido, stating that he used and loved the tool daily long before becoming an adviser, even "pestering the team" to join them due to its revolutionary impact on his hacking success. His practical experience and passion for the tool underpin his detailed and enthusiastic presentation.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent tool walkthrough from someone who clearly lives in Caido daily — the Google RPC ID mapping case study alone is worth something, and the HTTPQL query examples are concrete enough to be immediately actionable. But this is a vendor-adjacent feature demo, not research, and the 'defensive implications' section reads like GPT filler bolted onto a sales deck.
Heather Calloway (CISO) — PASS
A polished product demo for a bug bounty proxy tool with no governance angle, no institutional risk framing, and nothing for a security leader or defender to act on. Outside my lane entirely.