Web security testing with Ogma
An intercepting proxy and testing toolkit for pentesters, security engineers, and bug bounty hunters. Capture traffic, investigate application behavior, and keep the evidence with your project.
Inspect captured traffic with requests and responses side by side.
View guideTraffic interception & inspection
See what an application sends and how its server responds. Inspect HTTP and WebSocket traffic, pause exchanges to make changes, and narrow your investigation to relevant hosts, paths, or content.
- Inspect request and response headers and bodies
- Search captured traffic with HTTPQL
- Explore discovered hosts and paths in Sitemap
- Apply scope, filters, and Match & Replace rules
Request replay & payload testing
Take a captured request into Replay and test how the application behaves when you change it. Compare attempts, keep related tests together, and use Automate when a test needs multiple payloads.
- Edit requests and compare responses across attempts
- Organize saved sessions into collections
- Connect, send, and inspect messages in WebSocket Replay
- Test request parameters with payload lists
API testing starts with the definition.
Import OpenAPI, Postman, GraphQL introspection, or WSDL into Replay. Review generated requests, add your credentials, and test the behavior that matters.
Reusable workflows
Turn repeated processing steps into a workflow you can run again. Transform content, process selected history entries, or run logic as traffic is captured, without repeating each step by hand.
- Convert workflows transform input into output
- Active workflows run on traffic you select
- Passive workflows process captured traffic
- Test with request and response fixtures and inspect run logs
Browser interaction & MCP
Give your AI agent access to the same traffic and testing tools you use. Connect through the integrated MCP server to inspect requests, replay tests, and interact with pages in Ogma's browser. The built-in Ask Bob assistant works with your configured AI provider.
- Navigate pages, inspect snapshots, and fill forms
- Keep browser interaction alongside captured network traffic
- Use separate browser contexts for different identities
- Collect request evidence and screenshots for your assessment
Combine manual investigation with passive analysis and targeted active checks. Record the behavior you find, link supporting traffic, and keep your notes with the assessment.
- Review passive findings from captured traffic
- Run active checks against selected targets
- Link findings to supporting requests and responses
- Export captured traffic for further review
Local projects & JavaScript plugins
Keep each assessment in its own project and extend the toolkit around the way you work. Install existing plugins or build your own with the JavaScript SDK.
- Store assessment data in local projects
- Keep project notes and saved tests together
- Install plugins from folders or ZIP packages
- Build and share custom JavaScript tools