Hetty: An HTTP toolkit for security research
github.com
github.com
An intercepting proxy is a great tool for any web developer in addition to security research, and it's awesome to see an open source option.
Burp is with all it’s faults is still so much better in every aspect. If you just discard any technical feature, just the workflow from start to finish shows zap being build BY developers and burp being build FOR hackers. This alone explains why every serious security professional you will ever meet will swear to burp. This doesn’t mean that there is no usecase of course. It’s probably still relevant in the training area and it is included as an ‘automated’ dast/scanner in many cicd pipelines for cheap and preventing low-hanging fruit.
Hetty looks promising so far and competition will drive the overall quality of this niche.
The only downsides I see so far are that the project will need cgo, and thus cross compilation is a bit trickier for doing releases on GitHub. But already found a possible tool for making it easier: https://github.com/troian/golang-cross
Logging on the a back end is fine but this would be simpler I think.