Skip to main content

No project description provided

Project description

THC4M3 — Thick Client Helper for Burp

Build Release workflow License

Status: MVP (pre-release). Tested on macOS with Burp Suite Pro/Community and Java 17. THC4M3 is a minimal Burp extension that helps you test thick-client apps without drowning in noise: label/annotate only the traffic you care about, and generate a quick PAC file.


✨ What it does

  • Events table that logs/labels interesting requests & responses
  • Allow-lists for Host (regex), Port (CSV), MIME (regex)
  • Show/annotate only matching traffic to reduce noise
  • PAC generator to route only your target domains via Burp
  • Checklist sub-tab for thick-client test setup (save/load/export)

No telemetry. Everything runs inside Burp.

image

🔧 Install

  1. Download the latest thc4m3.jar from Releases.
  2. In Burp: Extensions → Installed → Add → Java and select the JAR.
  3. Confirm the THC4M3 tab appears.

If you’re on macOS and running Burp from a mounted .dmg, copy it to /Applications first.
If HTTPS fails due to TLS interception, install Burp’s CA certificate in your OS trust store or use curl -k during smoke tests.


⚡ Quick start (MVP)

  1. In the THC4M3 tab, set:
    • Host allow (regex): e.g. .*(api|login|auth|gateway).*|localhost|127\.0\.0\.1
    • Port allow (comma): 80,443,8080,8443
    • MIME allow (regex): ^(application/json|application/xml|text/.*|application/octet-stream)$
  2. Click Apply Filters.
  3. (Optional) Click Generate PAC… and use it in your app/OS to only proxy target hosts via Burp.

Smoke tests

Send traffic through Burp on 127.0.0.1:8080

curl --proxy http://127.0.0.1:8080 -k https://postman-echo.com/get -I curl --proxy http://127.0.0.1:8080 -k https://postman-echo.com/post
-H "Content-Type: application/json" --data '{"hello":"world"}'


🧩 Checklist tab

A thin, practical list for thick-client setup (pinning, TLS suites, IPC/local endpoints, file I/O caches/logs/secrets, etc.). Use Save / Load / Export… to persist or share checklists for a project.


🛠️ Build locally

Requires Java 17 and Gradle Wrapper (included).

./gradlew clean jar

JAR: build/libs/thc4m3.jar

unzip -p build/libs/thc4m3.jar META-INF/MANIFEST.MF | grep Burp-Extender-Class

Expect: Burp-Extender-Class: com.jb.thickclient.BurpExtender


❓ Troubleshooting

Extension loads but no tab: Ensure you launched Burp from /Applications (macOS app sandbox prompts can block access when run from a DMG).

HTTPS failures: Install Burp CA into your OS keychain, or use -k only for quick tests.

No events appear: Confirm your Host/Port/MIME allow-lists match, then generate a PAC or point your app to the Burp proxy.


🧭 Roadmap

Backfill labeling from Proxy history

Export/Import of all settings

Status chip / counters

Richer checklist with WSTG mappings


See Issues and Projects for active work.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

thc4me-0.2.1.tar.gz (3.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

thc4me-0.2.1-py3-none-any.whl (3.3 kB view details)

Uploaded Python 3

File details

Details for the file thc4me-0.2.1.tar.gz.

File metadata

  • Download URL: thc4me-0.2.1.tar.gz
  • Upload date:
  • Size: 3.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.7

File hashes

Hashes for thc4me-0.2.1.tar.gz
Algorithm Hash digest
SHA256 b88a3654321353157623d7f12160989989cc7682cbea75681e738cfa1dd0a380
MD5 928a909d1124f3e20d9c3f5163bd7a0d
BLAKE2b-256 bef70eff67fd52f090c6d201e92ddcf8cf511030a2bab77f29658e91f6445fd6

See more details on using hashes here.

File details

Details for the file thc4me-0.2.1-py3-none-any.whl.

File metadata

  • Download URL: thc4me-0.2.1-py3-none-any.whl
  • Upload date:
  • Size: 3.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.7

File hashes

Hashes for thc4me-0.2.1-py3-none-any.whl
Algorithm Hash digest
SHA256 791c13a0a7e5ceaa0b5e9fb80b45aacffa0e36aeb6570855fd2f98baf7eeee41
MD5 2ece79e94e3598f4d65367a2de2563f6
BLAKE2b-256 c0da2d68aa3612427d4daea6fdd1d5d5e03ef0afa6f2c34eed4064007bef22f5

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page