HTTP Repeater
XHack AI includes a built-in HTTP repeater: a Burp-style replay bench where you capture, edit, and resend requests to test for IDOR, auth bypass, and parameter injection without any command line.
A Hands-On HTTP Repeater Built Right In
Sometimes automated testing gets you close, and then you want to take the wheel yourself. XHack AI includes a built-in HTTP repeater, a replay bench in the spirit of the tools seasoned testers already love, so you can capture a request, tweak it, and fire it again as many times as you like. It lives inside the same graphical desktop app as everything else, so there is no command line and nothing to wire together. If you can edit text in a box, you can use it.
Capture or Import Any Request
Getting a request onto the bench is effortless. You can capture requests as XHack AI browses a target, or import a raw HTTP request you already have. Once it is loaded, the full request is yours to work with: every header, every parameter, and the entire body are laid out and ready to change.
Edit Every Part, See It Clearly
The request editor gives you complete control with syntax highlighting that makes each part of the request easy to read. Change a header, swap a parameter value, rewrite the body, then send it and watch the response come back. This tight edit-and-replay loop is exactly what you need to probe for IDOR, auth bypass, and parameter injection, where the whole game is changing one small thing and seeing how the server reacts.
A Clear Three-Pane Workspace
XHack AI organizes everything into a clean three-pane view. On one side, a site tree shows the hosts and requests you have collected. In the middle, the request editor holds the request you are working on. On the other side, the response pane shows exactly what came back. It is a familiar, comfortable layout that keeps your context in front of you so you can move quickly and stay oriented.
Hand Any Request to the AI
Here is where XHack AI goes beyond a traditional repeater. Any request on your bench can be sent straight to the AI for analysis. For example, you might right-click a captured request, choose "Send to AI," and simply say:
"Change the user_id and check if I can read another account."
XHack AI reasons about the request, makes the change, replays it, and tells you what it found, blending manual precision with an assistant that does the fiddly work for you. When you would rather keep a request for later or share it, you can export it as a .req file with a click.
Safe by Default
Powerful tools should not surprise you. XHack AI keeps cross-host replay turned off by default, so requests stay scoped to hosts you have already seen and interacted with. That guardrail means you can experiment freely inside your intended target without accidentally reaching somewhere you did not mean to touch. You stay in control, and the tool keeps you inside the lines.
What You'll Get
XHack AI's HTTP repeater gives you a friendly, powerful replay bench for manual web and API security testing. Capture or import a request, edit any part with syntax highlighting in a clear three-pane view, and resend it to hunt down IDOR, auth bypass, and injection flaws. Send anything to the AI for a second opinion, export requests when you need them, and rely on safe-by-default scoping the whole way through.
Try it on your own stack
Run this against a target you own and judge it on what it finds, not on a description.
Try XHack AIQuestions about this?
You get a researcher on the call, not a sales engineer reading the same page back to you.
Contact supportMore in XHack AI
Capabilities that sit alongside this one.