Wadjet szerző: n36l3c7
A case-bound investigation console for security analysts: capture traffic, decode and enrich artifacts, detonate links in throwaway containers, and export case reports, locally, with no passive telemetry.
Kiegészítő metaadatai
A kiegészítő névjegye
Wadjet is a case-bound investigation console for security analysts. Everything you do is organized under an investigation case and stored locally in your browser profile — there is no account, no cloud, and no passive telemetry.
What it does:
• Case timeline — capture notes and findings under one case; open, close, and switch cases.
• Traffic capture — opt-in, observe-only recording of HTTP(S) request metadata bound to the active case. Sensitive headers (Authorization, Cookie, tokens) are redacted at capture time.
• Decoders & encoders — Base64, URL, hex, unicode, JWT, plus defang/refang for IOCs, in an editable conversion chain you can reorder or trim step by step.
• Enrichment — on-demand reputation lookups across VirusTotal, AlienVault OTX, and AbuseIPDB, each queried only when you configure its API key. Results are shown per provider, never merged into a single score.
• Throwaway detonation — open a suspicious link in a fresh, isolated container (isolated cookies/storage) that is discarded when the tab closes. This isolates state only; it is not a network or exploit sandbox.
• DevTools panel — deterministic, individually explained security-header checks (CSP, HSTS, X-Content-Type-Options, and more) and TLS/certificate details for the inspected page.
• Export — produce a Markdown report, a HAR of captured requests, a CSV of IOCs, or a full JSON dump of the case.
• Optional native host — an optional local helper (installed separately) can archive a case to SQLite and run allowlisted local tools (whois, exiftool, yara). The extension is fully functional without it.
Privacy & permissions:
Wadjet is local-first. The only outbound network path is on-demand enrichment, and only to the provider whose API key you configured. Broad site access and provider hosts are optional and requested only when you turn on a feature that needs them. Nothing is ever sent to the developer.
Firefox desktop only (current ESR and stable). Open source under MPL-2.0.
What it does:
• Case timeline — capture notes and findings under one case; open, close, and switch cases.
• Traffic capture — opt-in, observe-only recording of HTTP(S) request metadata bound to the active case. Sensitive headers (Authorization, Cookie, tokens) are redacted at capture time.
• Decoders & encoders — Base64, URL, hex, unicode, JWT, plus defang/refang for IOCs, in an editable conversion chain you can reorder or trim step by step.
• Enrichment — on-demand reputation lookups across VirusTotal, AlienVault OTX, and AbuseIPDB, each queried only when you configure its API key. Results are shown per provider, never merged into a single score.
• Throwaway detonation — open a suspicious link in a fresh, isolated container (isolated cookies/storage) that is discarded when the tab closes. This isolates state only; it is not a network or exploit sandbox.
• DevTools panel — deterministic, individually explained security-header checks (CSP, HSTS, X-Content-Type-Options, and more) and TLS/certificate details for the inspected page.
• Export — produce a Markdown report, a HAR of captured requests, a CSV of IOCs, or a full JSON dump of the case.
• Optional native host — an optional local helper (installed separately) can archive a case to SQLite and run allowlisted local tools (whois, exiftool, yara). The extension is fully functional without it.
Privacy & permissions:
Wadjet is local-first. The only outbound network path is on-demand enrichment, and only to the provider whose API key you configured. Broad site access and provider hosts are optional and requested only when you turn on a feature that needs them. Nothing is ever sent to the developer.
Firefox desktop only (current ESR and stable). Open source under MPL-2.0.
Értékelés 0 szerkesztő által: 0
Engedélyek és adatok
Szükséges engedélyek:
- Üzenetváltás Firefoxon kívüli programokkal
- Fejlesztőeszközök kinyitása, hogy elérje a nyitott lapokon lévő adatokat
- Fájlok letöltése, valamint a letöltési előzmények olvasása és módosítása
Adatgyűjtés:
- A fejlesztő szerint ez a kiegészítő nem igényel adatgyűjtést.
A fejlesztő szerint nem kötelező adatgyűjtés:
- Weboldalon végzett tevékenységek
További információk
- Kiegészítő hivatkozásai
- Verzió
- 1.3.0
- Méret
- 47,71 kB
- Legutóbb frissítve
- 4 napja (2026. júl. 23.)
- Kapcsolódó kategóriák
- Verziótörténet
- Gyűjteményhez adás