Chiral

HTTP Request Repeater and Interceptor for security testing

As of June 2026, Chiral has 13 users and a 5.00/5 rating from 2 reviews in the Developer Tools category.

Usersup 116.7 percent+116.7%
13
13
Ratingno change0%
5.00
2 reviews
Reviewsup 100.0 percent+100.0%
2
Version
1.2.1
Manifest V3

History

10 snapshots

Tracking since Apr 1, 2026.

16.8115.199999999999999Apr 1, 2026Jun 5, 2026
View as table
DateUsersRatingReviewsVersion
Apr 1, 202665.0011.2.1
Apr 16, 202685.0021.2.1
Apr 22, 2026115.0021.2.1
Apr 27, 2026125.0021.2.1
May 4, 2026145.0021.2.1
May 10, 2026125.0021.2.1
May 15, 2026135.0021.2.1
May 21, 2026145.0021.2.1
May 27, 2026155.0021.2.1
Jun 5, 2026165.0021.2.1
Now135.0021.2.1

Permissions & access

Permissions
debuggerstoragecookiesdownloads
Host access
None declared

Screenshots

Chiral screenshot 1Chiral screenshot 2Chiral screenshot 3Chiral screenshot 4Chiral screenshot 5

About

Chiral – Browser-Native Security Suite for Chrome DevTools

  Chiral brings Burp Suite-level manual testing capabilities directly into your Chrome DevTools. Designed for researchers who prioritize speed, precision, and an uncluttered workflow. No proxy certificates, no Java environment, and no "magic" AI bloat—just powerful, expert-grade tools that get out of your way.

  Core Workflow Features

  ● True In-Flight Interception (CDP-Powered): Attach the Chrome Debugger to pause requests and responses in mid-flight. Modify method, URL, headers, and body before forwarding, or drop entirely. Edit response status codes and bodies before they reach the page.

  ● Professional Repeater & Diff View: Edit and replay captured requests with a table-based header editor or raw mode. Use the side-by-side Diff View (up to 8 panels) to spot minute byte-level discrepancies in responses. Cross-request search with regex and body content filtering.

  ● Intruder Fuzzing Engine: Mark payload positions with §markers§ and launch attacks. Four attack types: Sniper, Battering Ram, Pitchfork, and Cluster Bomb. Built-in payload generator for bruteforce attacks. Grep Match to flag successful attempts based on response patterns.

  ● Automated Sequence Chains: Turn a discovery into a reproducible Proof of Concept. Chain requests with Postman-style variables ({{VARNAME}}) and regex-based extraction rules. Transform steps for encoding/hashing. Condition steps for validation and branching logic.

  ● Passive & Active Recon Engine: Identify tech stacks, misconfigurations, and leaked secrets using 67+ regex-driven rules. In Active Mode, Chiral automatically modifies and resends requests based on your custom rule actions, or triggers sequences.

  ● Dynamic Target Mapping: Automatically build a structured map of your target's attack surface. Path normalization (e.g., /user/123 → /user/{id}), method tracking, and parameter extraction per endpoint. Probe for common files (robots.txt, swagger.json, .git/config). Spider in passive (fetch) or active (navigate) mode with form submission support.

  Advanced Power Features

  ● WebSocket Monitoring: Real-time capture of WebSocket connections and frames with direction filtering and JSON formatting.
  ● Sandboxed Scripting: All 19+ encode/decode/hash operations (Base64, JWT, SHA-256, MD5) are user-editable JavaScript scripts running in a secure iframe.
  ● Integrated Cookie & Storage Manager: Full CRUD control over browser cookies and localStorage/sessionStorage. Edit attributes or import/export sessions.
  ● SSL Certificate Inspection: View certificate details, validity, and Subject Alternative Names directly in the response viewer.
  ● Regex-Centric Everything: From detection rules to extraction, Chiral uses a unified regex engine. No complex dropdowns—just raw pattern matching power.
  ● cURL Integration: One-click cURL export for any request, or import cURL commands directly into the Repeater or Sequences.

  The Chiral Philosophy

  No "Cheap Aesthetics": Professional tools are made for professionals. No AI-bloat or hidden "secret sauce". All rules, transforms, and sequences are open and customizable.

  No Special Cases: Built-in features use the same systems as user-defined ones. You can inspect, modify, or replace any default rule or script.

  Performance First: Passive capture runs via native DevTools APIs with zero overhead. No debugger warning until you need active interception.

  Privacy & Security

  ● Local-Only: All data, rules, and history are stored locally in chrome.storage.local. Nothing is ever sent to an external server.
  ● Transparent Permissions: Optional permissions for cookie management, requested only when needed.
  ● Manifest V3 Compliant: Fully adheres to the latest Chrome security, privacy, and performance standards.

  Ready for rapid manual testing? Add Chiral to your DevTools today.

Technical

Version
1.2.1
Manifest
V3
Size
180KiB
Min Chrome
88
Languages
1
Featured
No

Metadata

ID
fchbnbjkgilildfobdcffclbnjbgcfie
Developer ID
ua8f49f1be3a15b8485d656c268e43a4c
Developer Email
[email protected]
Created
Jan 5, 2026
Last Updated (Store)
Feb 23, 2026
Last Scraped
Jun 5, 2026
Website

Similar extensions

Alternatives to Chiral, ranked by description similarity.

Data sourced from the Chrome Web Store · last verified Jun 5, 2026.