Use with security tools
Send a proxy-unaware application into Burp Suite, mitmproxy or InterceptSuite with ProxyBridge, and choose the right proxy for the traffic.
Use ProxyBridge with security tools
Many desktop and mobile-companion applications have no proxy setting at all. ProxyBridge solves that part: it redirects the TCP and UDP traffic of the processes you choose to a proxy you run. What happens to the traffic after that depends on the proxy.
This page lists common choices. ProxyBridge works with any HTTP or SOCKS5 proxy, so pick the one that matches the protocol you are testing.
Only test applications, devices and networks you own or have written permission to test.
Pick the proxy for the traffic
| If the traffic is... | Common choice | Proxy type in ProxyBridge |
|---|---|---|
| HTTP or HTTPS (web apps, REST APIs) | Burp Suite, OWASP ZAP, mitmproxy | HTTP (use the tool's proxy listener) |
| Mixed HTTP and raw TCP, scripted analysis | mitmproxy in SOCKS5 mode | SOCKS5 |
| Non-HTTP: raw TCP, TLS, DTLS, QUIC, UDP, STARTTLS | InterceptSuite (SOCKS5 listener) | SOCKS5 |
| You only want to change the route (no inspection) | Your own SOCKS5 or HTTP proxy | SOCKS5 or HTTP |
Steps for any of them
- Start your proxy and note its address and port.
- In ProxyBridge, open the proxy settings, choose the type (HTTP or SOCKS5), and enter the host and port. Add a username and password if the proxy needs them.
- Create a rule for the target application (by process name), and set the action to route through the proxy.
- Start the application. Its traffic now flows through your proxy.
- If the proxy decrypts TLS, install and trust its CA certificate on the machine running the target application.
See the configuration pages for your system for the exact screens: Windows, macOS and Linux.
Things to check
- Protocol support is the proxy's job. An HTTP proxy cannot handle raw TCP or UDP, and a SOCKS5 proxy needs UDP support for UDP traffic.
- QUIC and HTTP/3 need proxy support too. See the QUIC and HTTP/3 notes in the configuration pages.
- Certificate pinning. Applications that pin certificates will reject a decrypting proxy. Leave those hosts untouched in your proxy, or test them another way.