Web security testing with Ogma

An intercepting proxy and testing toolkit for pentesters, security engineers, and bug bounty hunters. Capture traffic, investigate application behavior, and keep the evidence with your project.

Ogma / HTTP History
Opening Ogma...

Inspect captured traffic with requests and responses side by side.

View guide

Traffic interception & inspection

See what an application sends and how its server responds. Inspect HTTP and WebSocket traffic, pause exchanges to make changes, and narrow your investigation to relevant hosts, paths, or content.

  • Inspect request and response headers and bodies
  • Search captured traffic with HTTPQL
  • Explore discovered hosts and paths in Sitemap
  • Apply scope, filters, and Match & Replace rules

Request replay & payload testing

Take a captured request into Replay and test how the application behaves when you change it. Compare attempts, keep related tests together, and use Automate when a test needs multiple payloads.

  • Edit requests and compare responses across attempts
  • Organize saved sessions into collections
  • Connect, send, and inspect messages in WebSocket Replay
  • Test request parameters with payload lists

API testing starts with the definition.

Import OpenAPI, Postman, GraphQL introspection, or WSDL into Replay. Review generated requests, add your credentials, and test the behavior that matters.

Reusable workflows

Turn repeated processing steps into a workflow you can run again. Transform content, process selected history entries, or run logic as traffic is captured, without repeating each step by hand.

  • Convert workflows transform input into output
  • Active workflows run on traffic you select
  • Passive workflows process captured traffic
  • Test with request and response fixtures and inspect run logs

Browser interaction & MCP

Give your AI agent access to the same traffic and testing tools you use. Connect through the integrated MCP server to inspect requests, replay tests, and interact with pages in Ogma's browser. The built-in Ask Bob assistant works with your configured AI provider.

  • Navigate pages, inspect snapshots, and fill forms
  • Keep browser interaction alongside captured network traffic
  • Use separate browser contexts for different identities
  • Collect request evidence and screenshots for your assessment

Scanning, findings & evidence

Combine manual investigation with passive analysis and targeted active checks. Record the behavior you find, link supporting traffic, and keep your notes with the assessment.

  • Review passive findings from captured traffic
  • Run active checks against selected targets
  • Link findings to supporting requests and responses
  • Export captured traffic for further review

Local projects & JavaScript plugins

Keep each assessment in its own project and extend the toolkit around the way you work. Install existing plugins or build your own with the JavaScript SDK.

  • Store assessment data in local projects
  • Keep project notes and saved tests together
  • Install plugins from folders or ZIP packages
  • Build and share custom JavaScript tools

Download for your platform.

Download Ogma