National Cyber Warfare Foundation (NCWF)

Bifrost for high-performance TLS-intercepting proxy workflows


0 user ratings
2026-09-28 19:24:59
milo
Red Team (CNA)
"Bifrost

bifrost-proxy/bifrost is a Rust-based HTTP/HTTPS/SOCKS5 proxy with TLS interception, rule-based rewriting, breakpoints, a QuickJS script sandbox, and a Web UI, built for authorized traffic inspection.








Toolbifrost-proxy/bifrost — high-performance AI-friendly HTTP/HTTPS/SOCKS5 proxy server written in Rust, inspired by Whistle
Categoryman-in-the-middle debugging proxy / traffic interception tooling
Primary UseIntercepting, inspecting, rewriting, mocking and replaying HTTP(S)/SOCKS5 traffic via rules, scripts and a built-in Web UI in http://127.0.0.1:9900/_bifrost/
Safe UseAuthorized debugging on systems you own or have written permission to test: local development, lab environments, internal API debugging, and documented penetration-test scopes where a CA certificate is deliberately trusted by the device owner.
Telemetry NoteTLS interception requires the target device to trust the Bifrost CA, which defenders can detect via unusual CA chains, the /_bifrost/ admin endpoint on port 9900, and proxy traffic converging on the operator host; the Web UI exposes remote-access and password management (bifrost admin passwd, bifrost admin revoke-all).

bifrost, hosted at bifrost-proxy/bifrost, positions itself as a high-performance, AI-friendly proxy server written in Rust and openly inspired by Whistle, the long-standing Node.js MITM debugging proxy. The README describes a tool that combines a fast proxy core with request interception, rule-driven modification, TLS decryption, scriptable extension, traffic capture, request replay, and a Web UI for management. The repository sits at roughly 141 stars, is MIT-licensed, and its topic list — proxy, postman, whistle, rust, ai-tools — signals that the authors see it as much as a developer/QA companion as a security-testing aid. For professionals who have lived inside mitmproxy, Charles, or Whistle, the pitch is familiar: a single local endpoint through which all your traffic flows, where you can see and shape it.


The engineering foundation is the most interesting part of the README. The proxy kernel is built on Tokio + Hyper, giving it async high-concurrency handling and connection reuse, which matters when you are pushing large-volume API traffic or streaming workloads through it. Protocol coverage is broad for a young project: HTTP/1.1, HTTP/2, HTTP/3, HTTPS, SOCKS5, WebSocket, SSE, and gRPC. That HTTP/3 support is notable because many consumer MITM tools still treat QUIC-based traffic as a gap; the README even shows a rule (chatgpt.com http3://) that forces HTTP/3 handling for a specific host, which is a clean demonstration of protocol-level steering per domain.


TLS interception follows the standard trusted-CA model, but with operational refinements that suggest the authors have actually deployed this against real devices. The installer generates a CA certificate and installs it into the local trust store; interception then issues per-domain certificates dynamically, and rules decide per-host whether to intercept or pass through untouched. There is even an explicit upstreamUnsafeSsl://true operator for a single upstream HTTPS rule, so you can scope unsafe-certificate tolerance narrowly instead of flipping a global switch. Crucially, the Web UI includes a device availability check (Settings -> Certificate -> Availability Check) that generates a QR code or link, verifies the device is allowed by access control, can reach the probe port, and actually trusts the Bifrost CA — with platform-specific guidance for iOS trust settings and Android CA installation. This is exactly the friction point where most MITM debugging sessions die, and automating the diagnosis is a genuinely thoughtful touch.


The rule engine is where day-to-day value lives. Rules are expressed as pattern operator://value lines, a syntax inherited conceptually from Whistle. The README shows example.com host://127.0.0.1:3000 for mapping a domain to a local server, reqHeaders://x-debug=1&x-env=ppe for injecting request headers (multiple inline values separated by &, with a per-line JSON/Values fallback when values contain literal ampersands), and dns://10.0.0.53 for overriding resolution. Beyond routing and header manipulation, the operators cover request/response rewriting, injection, artificial latency, rate limiting, mocking, and handing a transaction to a script — effectively a swiss-army configuration language for shaping traffic without writing code.


A persistent rule object called Default deserves mention: it is auto-created, always enabled, pinned to the top of the rule list, cannot be deleted, disabled, renamed, or synced remotely, but its content is editable. The README suggests placing shared DNS overrides, common headers, and TLS fallback policy there, noting that edits apply to the main listening port and all temporary ports. From an operational hygiene standpoint, having an undeletable, unsyncable global baseline is a smart design — it prevents a misconfigured sync from stripping the rules every port depends on, and it gives defenders auditing an install a stable anchor point to review first.


Scriptability is handled through a sandbox based on QuickJS, the lightweight embeddable JavaScript engine, with three hook types: reqScript, resScript, and decode. Running user scripts in a QuickJS sandbox rather than the host runtime is a meaningful security boundary — a malformed or hostile rule script cannot trivially reach the filesystem or spawn processes the way a Node.js-based tool would. The trade-off, as always with sandboxes, is API surface; heavy payload manipulation will be slower than native code, but for header surgery, body rewriting, and decoding tasks, the model fits well.


Breakpoints extend the interception model from scripted to interactive. Rules pointing at breakpoint://request or breakpoint://response pause the matching HTTP transaction inside the Web UI, where the operator can edit headers and body before releasing it — the same workflow popularized by Charles and Whistle, but integrated into the browser-based console. For authorized testing this is the classic mechanism for understanding how a client reacts to a modified server response, or for debugging a flaky integration by surgically altering one field mid-flight rather than mocking the whole endpoint.


The CLI deserves separate attention because it is unusually complete. bifrost status and bifrost stop handle lifecycle; bifrost admin remote enable, bifrost admin passwd, and bifrost admin revoke-all manage remote Web UI access with authentication and session revocation — a rare and welcome acknowledgment that a proxy admin console is itself attack surface. Traffic archaeology is first-class: bifrost traffic search "keyword" --method POST --host api.openai.com --path /v1/responses filters by method, host, path, status and protocol, with search scopes like --req-header, --res-body, --url, plus --req-json/--res-json supporting JSONPath-style root $, dot paths, array indexes and [*] wildcards, with hard errors on malformed paths instead of silent empty results. Output defaults to NDJSON for machine consumption, with --format json-pretty for humans, and --latest 5m time windows — this is tooling designed to be piped, not just stared at.


The AI-friendliness is not just a topic tag. bifrost install-skill -y installs the project's agent skills so an AI assistant can drive the proxy, and the README documents an ASR Daily Agent pipeline that fans a daily report out into multiple independent research questions dispatched to ChatGPT sessions, configurable through a JSON manifest (max_questions, chatgpt_interface_mode, chatgpt_model, chatgpt_project_url). The design document lives in design/asr-daily-agent-pipeline.md. The framing is that a proxy is a natural orchestration layer for agent workflows — it can observe, throttle, and modify the API traffic that agents themselves generate, which is an emerging use case that traditional MITM tools never contemplated.


Installation is straightforward and, per the rules of engagement here, we will cite only the essentials. The npm path is npm i -g @bifrost-proxy/bifrost, or the shell installer (install-binary.sh on macOS/Linux/Git Bash, install-binary.ps1 on Windows) fetches the CLI, optionally a Tauri-based desktop app (--no-desktop or BIFROST_INSTALL_AUTO_DESKTOP=0 skips it), installs and trusts the CA, and starts the service. A BIFROST_GITHUB_MIRROR variable lets restricted networks pick a faster mirror. Post-install, bifrost status confirms the service and the console is at http://127.0.0.1:9900/_bifrost/. Developers contributing to the repo run bash scripts/setup-git-hooks.sh, which wires .githooks with formatting checks and cargo clippy --workspace --all-targets --all-features -- -D warnings — a strict lint posture that hints at code quality discipline.


Resource-conscious design shows up in the operations details. The Performance page and /_bifrost/api/system/memory surface body and WebSocket file-writer occupancy plus warnings when the process approaches the file-handle limit — exactly the failure modes a long-running capture proxy hits in practice. The README also documents a desktop app route (Bifrost.app via .dmg, .msi for Windows, with correct aarch64/x86_64 target guidance) for users who prefer GUI packet inspection over CLI, and the desktop app can install the CLI retroactively from Settings -> Desktop Proxy Core.


Within an authorized workflow, bifrost slots in as a modern Rust alternative to Whistle with better concurrency, an actual script sandbox, and agent integration. The legitimate contexts are concrete: debugging mobile or desktop apps you develop against their APIs, mocking backends during integration testing, replaying captured requests to reproduce defects, and inspecting traffic during scoped penetration tests where the device owner deliberately trusts the CA. What defenders should remember is the inverse: a suddenly trusted unknown CA, decrypted-looking HTTPS on a segment where it should be opaque, or a listening admin console on 9900 are all high-signal indicators that interception tooling is in play — authorized or otherwise.



Official project repository for bifrost-proxy/bifrost.

Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.






Source: OffensiveSec
Source Link: https://www.offsecblog.com/2026/09/bifrost-for-high-performance-tls.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.