Open-source project
asaotomo/Hx0-HawkEye avatar
asaotomo/Hx0-HawkEye

Hx0 HawkEye: Browser-Side Capture, Intercept and Replay Without a System Proxy

一个轻量级浏览器抓包与安全分析扩展,在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。(A lightweight browser extension for traffic capture and security analysis, enabling capture, interception, modification, replay, rule-based detection, and AI-assisted analysis—all from the browser sidebar.)

85 stars7 forksUnknownLicense varies

At a glance

What is it?
Hx0 HawkEye is a Chrome and Firefox extension that puts HTTP and WebSocket capture, interception, replay, fuzzing and optional AI analysis in the browser sidebar. It trades the system proxy for the page's own session, and gates most of its depth behind a paid tier.
Who is it for?
Adopt Hx0 HawkEye if your work lives in a logged-in SPA session and you want capture, interception and replay without touching system proxy settings or installing a CA certificate. Do not adopt it if you need headless automation, CI integration, or a tool whose full feature set is available under an open licence, because the community build omits replay-in-page, fuzzing, AI and the batch workbenches.
Can I use it commercially?
Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
Is it still maintained?
Yes. The repository last received commits 10 days ago.
What is it written in?
GitHub does not report a main language for this repository.

Answers come from the project's GitHub data, last synced on September 27, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The Problem Hx0 HawkEye Targets: Session Drift Between the Tab and the Proxy

The README describes a familiar split. Proxy tools such as Burp Suite have a high capability ceiling, but they require changing the system proxy and trusting a root certificate, and they can lose the browser tab's Cookie and login state. Lightweight extensions next to the address bar tend to lack persistent history, structured detail views and a closed workflow. Hx0 HawkEye is aimed at that gap. The stated design goal is to collapse capture (HTTP and WebSocket), filtering, detail inspection, interception and modification, replay, micro-fuzzing, sensitive-data and hidden-link detection, and optional AI analysis into a single sidebar workbench, without forcing a system proxy change.

The intended audience is narrow and specific: engineers doing front-end and back-end integration debugging, interface troubleshooting, and authorised security triage on SPA and XHR-heavy applications. It is not positioned as a replacement for a full proxy suite. The README's own framing is that it reduces context-switching cost for integration and first-pass audit work, and that it captures fetch and XHR in the page's main world so the traffic shares the tab's origin and login state. If your target is a native mobile app, a desktop client, or a service that never touches a browser, this extension has nothing to intercept.

How Capture Works: Main-World Hooks, IndexedDB History and a Shared Rule Set

The mechanism is a main-world hook on fetch and XHR inside the page, recording requests and responses including bodies with a size guard. Noise is reduced by domain and IP wildcards, resource type (XHR/Fetch, WebSocket, JSON, HTML, JS, binary), and custom suffixes. Enabling WebSocket recording also logs the handshake (shown as GET 101) and data frames marked WS with OUT and IN direction.

History is persisted in IndexedDB and filtered by type, host, method, status code, sensitive-data hits and free-text search, with a default scope of the current page or all packets. Interception is queue-based: HTTP requests pause, and when a rule matches, WebSocket outbound and inbound frames enter a frame-level queue where they can be edited, released or dropped from the sidebar. Capture and interception share the same target rules, which is a sensible simplification: one rule set governs both what you see and what you can stop. The detail view offers Pretty, Raw and Hex, a sandboxed Render of responses, aggregated sensitive-data highlighting, full-URL copy on title click, a two-column .txt download, and a Burp-style export. The trade-off in the main-world hook approach is that traffic generated outside the page context, by another extension for example, is not part of this pipeline.

Installing Hx0 HawkEye and Running a First Intercept

The repository does not publish a build or a package manifest. Its top-level entries are two release archives, README.md and README_EN.md: Hx0-HawkEye-Chrome-V1.0.6-Official.Release.zip and Hx0-HawkEye-Firefox-V1.0.6-Official.Release.zip. The README states the extension is a native browser extension for Chrome, Firefox and mainstream Chromium browsers, and that Chrome and Firefox differ in sidebar hosting, intranet and self-signed HTTPS helper options, and system prompts during interception, while core business features are aligned. Because the repository ships prebuilt archives rather than source, installation means loading the unpacked release for your browser, not building from a checkout.

After installation, the README says a new install gets a 30-minute full professional trial, and that when the trial ends without activation the extension automatically falls back to the community edition. The first practical step is to set capture targets so the history list is usable. The README places the capture type and suffix controls on the basic settings page, and the smart proxy diverter sits directly below them; that diverter routes matching requests to Burp, Yakit or another upstream proxy by site rule while non-matching requests keep their original network path. The README does not document exact UI labels or config keys for these controls, so treat the settings page itself as the reference.

To exercise interception, the workflow in the README is: capture, filter, inspect, then intercept. The community edition includes the intercept toggle, editing, release and one-click release or drop for both HTTP and WebSocket frames when host rules match. Replay is the next step, and the community edition keeps plain replay including WebSocket frame replay, which sends an outbound frame over a connection that is still OPEN in the page rather than performing a new handshake. That constraint matters: if the page's socket has closed, frame replay has no channel to use.

Where Hx0 HawkEye Stops: Paid Tiers, Page-Bound Replay and the Missing Source

The most consequential limitation is licensing and tiering, not capability. The README lays out a community, professional and 30-minute trial split. The community edition covers capture with basic WebSocket observation, detail inspection, plain replay including WebSocket frame replay, basic encoding and decoding, and interception with modification. Everything deeper is professional only: replay inside the page, in-page fuzzing, HTTP and WebSocket micro-fuzzing with the §...§ injection marker, method switching, target domain switching, the userscript workbench, all AI features, the AI task console, the Skills knowledge base, hidden-link detection, batch workbenches, advanced encoding and decoding, and the MCP and browser-level agent added in v1.0.6. The agent mode is available only under a valid trial or professional licence.

Several constraints follow from the design rather than the licence. WebSocket frame replay and WebSocket micro-fuzzing depend on an active in-page connection, and micro-fuzzing treats the next inbound frame as the response, so a quiet or one-way socket gives you nothing to correlate. The 30-minute trial is a hard evaluation window, and the fallback to community edition is automatic, which means a team evaluating the professional features has a short window unless it activates. The repository also does not expose source in its top-level entries, so you cannot audit the fetch and XHR hooks, the IndexedDB schema, or the AI request construction from this repository. For a tool that reads request and response bodies, that is a real consideration. The README states that data is sent only to the endpoint you configure under BYOK, but the code path itself is not in the repository listing.

Hx0 HawkEye Versus Burp Suite and Yakit: Different Capture Layers

The clearest alternative is a proxy-based tool, and the README names Burp and Yakit directly. The difference is where interception happens. A proxy sits below the browser: it sees every client on the machine, works with native apps and command-line tools, and can be scripted and driven headlessly. Hx0 HawkEye sits inside the page: it sees fetch and XHR from that tab with the tab's own session, and it cannot see anything the browser does not route through its hooks.

That is not a strict downgrade, and the README does not present it as one. The proxy's cost is configuration: system proxy changes, root certificate trust, and the session drift that shows up as lost Cookies and repeated logins on SPA targets. Hx0 HawkEye's cost is scope: one browser, one session, no native clients. The smart proxy diverter is the interesting middle ground, because it lets you send only matching site rules upstream to Burp or Yakit and leave the rest on the original network path. That suggests the intended deployment is coexistence rather than replacement: use the extension for the logged-in tab you are already debugging, and hand the traffic you need heavier tooling for to the proxy you already run. The README notes the Firefox build additionally supports compatibility mode and takeover mode for the diverter.

Maintenance, Release Cadence and What the Licence Does Not Tell You

The repository is not archived, and the last push was on 2026-08-26, which is recent enough that the project is being worked on. The release history shows v1.0.4 on 2026-06-07, v1.0.5 on 2026-06-13, and v1.0.6 on 2026-08-26, so the cadence is a few weeks to a couple of months between tagged releases rather than continuous delivery. v1.0.6 is a substantive release: it adds the HawkEye browser automation MCP and the browser-level agent, opens the smart proxy diverter, full-depth search, and the built-in and custom sensitive-information matching and keyword libraries to the community edition, and reworks DOM snapshotting into a single linear traversal with bounded output and early filtering of off-viewport elements. Firefox webRequest listeners are now registered and unregistered dynamically by state, and agent and MCP transports were compacted with batched notifications, observer reuse and a next_cursor for reading large results.

Upgrade cost is low in one sense: the repository ships browser-specific zip archives, so upgrading means replacing the loaded release. It is higher in another: the release notes describe behaviour changes to the Skills authorisation model in v1.0.6. Skills now require two explicit grants. The advanced settings page is a global allow list, and an agent's new session has Skills off by default, so the user must also click Skills in the current session; a Skill that is not enabled in both places will not be called. Teams that relied on the earlier behaviour will need to re-check their configuration after upgrading.

On licensing, the repository does not state a licence, and the README describes a commercial community and professional split with a time-limited trial. That combination means the practical question is not open-source licence compliance but commercial terms: what the professional tier costs, whether the trial can be extended, and how activation works. Those answers are not in the README, so they have to come from the vendor. Nothing here should be read as legal advice.

Editorial conclusion

Adopt Hx0 HawkEye if your work lives in a logged-in SPA session and you want capture, interception and replay without touching system proxy settings or installing a CA certificate. Do not adopt it if you need headless automation, CI integration, or a tool whose full feature set is available under an open licence, because the community build omits replay-in-page, fuzzing, AI and the batch workbenches. Before committing, install the release zip for your browser, confirm the 30-minute professional trial starts and then falls back to the community edition, and check whether the paid tier's AI features are acceptable to your organisation given that request and response data is sent to whichever endpoint you configure.

Frequently asked questions

What is Hx0 HawkEye software?

It is a browser extension for Chrome and Firefox that performs traffic capture, interception, modification, replay, micro-fuzzing, rule-based detection and optional AI-assisted analysis from the browser sidebar. The README describes it as capturing fetch and XHR in the page's main world so the traffic shares the current tab's origin and login state, without changing the system proxy.

Does Hx0 HawkEye require a system proxy or a root certificate?

No. The README lists zero environment dependency as a core advantage: no Burp Suite, no system proxy change, no root certificate trust and no Java environment. It also notes Chrome and Firefox differ in intranet and self-signed HTTPS helper options.

What is the difference between the Hx0 HawkEye community and professional editions?

The community edition covers capture with basic WebSocket observation, detail inspection, plain replay including WebSocket frame replay, basic encoding and decoding, and interception with modification. The professional edition adds in-page replay and fuzzing, HTTP and WebSocket micro-fuzzing, the userscript workbench, all AI features, the AI task console, Skills, hidden-link detection, batch workbenches, advanced encoding and decoding, and the MCP and browser-level agent.

Does Hx0 HawkEye send my traffic to a third party?

The README states that data is sent only to the endpoint you configure, under a bring-your-own-key model supporting OpenAI, DeepSeek, local LM Studio and a custom Base URL. AI features that would transmit request and response content are professional-tier only.

Can Hx0 HawkEye replay WebSocket frames?

Plain WebSocket frame replay is in the community edition, and it sends an outbound frame over a connection that is still OPEN in the page rather than performing a new handshake. WebSocket micro-fuzzing, which is professional only, sends frames serially and treats the next inbound frame as the response, so both depend on an active in-page connection.

Official sources

  1. Official documentation
  2. Official README
  3. Project repository
  4. Release notes
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/asaotomo-hx0-hawkeye.svg)](https://hysenlabs.com/projects/asaotomo-hx0-hawkeye)