Skip to content

Releases: BlackDranzer777/legilimens

Legilimens 1.0.0-preview.1

Pre-release

Choose a tag to compare

@BlackDranzer777 BlackDranzer777 released this 29 Sep 03:52

Legilimens 1.0.0-preview.1

The first public preview of Legilimens, a man-in-the-middle inspector for WebTransport:
the QUIC / HTTP/3 traffic that Burp Suite and Wireshark can't see.

This is a research preview for developers and security testers. It is for inspecting
applications you own or have explicit permission to test.

Download

File Platform Size
Legilimens-Setup-1.0.0-preview.1.exe Windows x64 138 MB

SHA-256: 6ce6b67e74e4dbe9f50b6e5a406b828d3b6e7e92ec6336d6e3d90e0255fe94d0

Verify it in PowerShell before running:

Get-FileHash .\Legilimens-Setup-1.0.0-preview.1.exe -Algorithm SHA256

No Python, Node.js or separate browser is needed: the app bundles its backend and its own Chromium.

What's in it

  • Live capture of every WebTransport datagram and stream chunk, with filters and full-text search.
  • Secret flagging: payloads containing tokens, passwords or keys are marked SUS.
  • Conditional tamper: rewrite a JSON field in passing traffic, optionally only when another field matches.
  • Manual intercept: hold messages mid-flight, then edit, forward or drop them.
  • Repeater: resend or inject an edited text datagram into a chosen live session.
  • Stream inspection for bidirectional and unidirectional streams.
  • Capture files: export traffic to a versioned JSON file and reopen it later in a read-only offline view.
  • Runtime target switching without restarting.
  • No browser flags: clients trust the proxy through its certificate hash (serverCertificateHashes).
  • Bundled practice target on 127.0.0.1:4434 to try everything safely.
  • Local-only control: every listener binds to loopback, and the UI uses a per-launch access token.

Installing

  • The installer is not code-signed. Your browser may say the file "isn't commonly downloaded":
    choose Keep. Windows SmartScreen will warn on first run: choose More info → Run anyway.
  • It installs for the current user, and you can choose the folder. The generated certificate lives
    in %APPDATA%\Legilimens\data.
  • Ports 4433–4436 must be free. If another instance is running, the app shows a startup error.

Known limitations

  • Preview quality. Tested on a single Windows 11 machine; other configurations are unverified.
  • Empty datagrams in Chromium. Chrome and Edge fail to receive empty datagrams (and the ones
    after them), both directly and through the proxy. The cause is under investigation.
  • Repeater is text-datagram only. Binary and stream replay are not supported yet.
  • Tamper needs complete JSON in a single datagram or stream chunk; fragmented JSON passes through unchanged.
  • Pinned clients can't be intercepted. A shipped client that pins its own certificate
    can't be proxied, so you need control of the client (your own or a test build). This applies to
    every MITM tool, not just Legilimens.
  • Certificate renewal needs a backend restart, which drops active sessions and resets runtime settings.
  • Capture files may contain secrets from raw payloads; handle them with care.
  • The encapsulation attack (raw packets via Scapy/Npcap) is not available in the desktop app.

Verification

  • 107 backend tests passed (one optional soak test skipped); 70 frontend and launcher tests passed.
  • Packaged-app smoke test passed across two launches: authenticated control, renderer sandboxing,
    pinned WebTransport echo, visible capture, stale-token rejection, clean shutdown and port release.

License

MIT. Third-party software included in the app is listed in
THIRD_PARTY_NOTICES.md.

Part of the Hallows security toolkit.