News

3 min read

Web Security, Streamlined: Meet Caido on Pwnbox

Caido is now integrated with Pwnbox. Explore seamless web testing with this lightweight, powerful proxy inside your browser.

JXoaT avatar

JXoaT,
Jun 02
2025

In modern web application security, getting started quickly can make all the difference. Having the right tools at your fingertips without setup or system bloat is crucial.

We’re excited to share something that embodies this philosophy: Caido is now natively integrated into Pwnbox, our in-browser, full-featured hacking environment powered by Parrot OS.

This collaboration between Hack The Box (HTB), Parrot Security, and Caido isn’t just convenient, it’s a powerful step forward in simplifying and modernizing the web testing workflow.

If you’ve used Pwnbox before, you already know it offers a full penetration testing distro in your browser, running on Parrot OS and tailored for HTB’s ecosystem. Integrated with all HTB platforms, Parrot enables you to dive straight into content. 

Now, with Caido onboard, Pwnbox becomes an even more capable environment for web application testing.

Why Caido?

Caido is a lightweight web security toolkit designed to be fast, intuitive, and extensible. It serves as a modern interception proxy with a clean UI and modular design, offering everything you’d expect from an advanced web testing platform.

Caido empowers testers with:

  • Real-time HTTP and WebSocket interception.

  • A visual sitemap to track application structure.

  • Request and response replay, repeat, and editing features.

  • Match and replace automation via regex.

  • A plugin system with JavaScript-based extension support.

  • Workflows for encoding, decoding, and transforming data.

It’s built for speed, simplicity, and customization. In short, Caido does a lot without friction.

Getting started in Pwnbox

Here’s how to use Caido inside Pwnbox:

  1. Launch Pwnbox from your HTB dashboard.
  2. Once your instance is running, open Caido from the Applications menu or start it via terminal.
  3. Point your browser to the indicated local URL, and you’re ready to intercept and audit.

This setup is ideal for HTB learners working in Web Challenges, Starting Point, or Pro Labs. You can test live apps with your proxy directly in the browser session, all within the flexibility of Parrot OS.

Explore with Guest Mode

Caido’s Guest Mode is a standout feature and is especially useful in HTB environments.

Without creating an account, you can launch a temporary Caido session to:

  • Perform quick tests in a throwaway session.

  • Install and run a single plugin.

  • Save no data locally after the session ends.

Whether you’re demoing the tool, teaching a workshop, or just exploring something for five minutes, Guest Mode gives you fast access to Caido’s core functionality.

Try it now

Caido is already pre-installed on your next Pwnbox session, just launch and go.

Whether you're intercepting requests in an HTB scenario or exploring a personal project, Caido provides a cleaner, faster path forward in your web testing workflow.

Try it today on any of our HTB platforms, and let us know what you think. We’re always listening, building, and hacking together.

Use Caido Now

Hack The Blog

The latest news and updates, direct from Hack The Box