Releases: BlackDranzer777/legilimens
Releases · BlackDranzer777/legilimens
Release list
Legilimens 1.0.0-preview.1
Legilimens 1.0.0-preview.1
The first public preview of Legilimens, a man-in-the-middle inspector for WebTransport:
the QUIC / HTTP/3 traffic that Burp Suite and Wireshark can't see.
This is a research preview for developers and security testers. It is for inspecting
applications you own or have explicit permission to test.
Download
| File | Platform | Size |
|---|---|---|
Legilimens-Setup-1.0.0-preview.1.exe |
Windows x64 | 138 MB |
SHA-256: 6ce6b67e74e4dbe9f50b6e5a406b828d3b6e7e92ec6336d6e3d90e0255fe94d0
Verify it in PowerShell before running:
Get-FileHash .\Legilimens-Setup-1.0.0-preview.1.exe -Algorithm SHA256No Python, Node.js or separate browser is needed: the app bundles its backend and its own Chromium.
What's in it
- Live capture of every WebTransport datagram and stream chunk, with filters and full-text search.
- Secret flagging: payloads containing tokens, passwords or keys are marked
SUS. - Conditional tamper: rewrite a JSON field in passing traffic, optionally only when another field matches.
- Manual intercept: hold messages mid-flight, then edit, forward or drop them.
- Repeater: resend or inject an edited text datagram into a chosen live session.
- Stream inspection for bidirectional and unidirectional streams.
- Capture files: export traffic to a versioned JSON file and reopen it later in a read-only offline view.
- Runtime target switching without restarting.
- No browser flags: clients trust the proxy through its certificate hash (
serverCertificateHashes). - Bundled practice target on
127.0.0.1:4434to try everything safely. - Local-only control: every listener binds to loopback, and the UI uses a per-launch access token.
Installing
- The installer is not code-signed. Your browser may say the file "isn't commonly downloaded":
choose Keep. Windows SmartScreen will warn on first run: choose More info → Run anyway. - It installs for the current user, and you can choose the folder. The generated certificate lives
in%APPDATA%\Legilimens\data. - Ports 4433–4436 must be free. If another instance is running, the app shows a startup error.
Known limitations
- Preview quality. Tested on a single Windows 11 machine; other configurations are unverified.
- Empty datagrams in Chromium. Chrome and Edge fail to receive empty datagrams (and the ones
after them), both directly and through the proxy. The cause is under investigation. - Repeater is text-datagram only. Binary and stream replay are not supported yet.
- Tamper needs complete JSON in a single datagram or stream chunk; fragmented JSON passes through unchanged.
- Pinned clients can't be intercepted. A shipped client that pins its own certificate
can't be proxied, so you need control of the client (your own or a test build). This applies to
every MITM tool, not just Legilimens. - Certificate renewal needs a backend restart, which drops active sessions and resets runtime settings.
- Capture files may contain secrets from raw payloads; handle them with care.
- The
encapsulationattack (raw packets via Scapy/Npcap) is not available in the desktop app.
Verification
- 107 backend tests passed (one optional soak test skipped); 70 frontend and launcher tests passed.
- Packaged-app smoke test passed across two launches: authenticated control, renderer sandboxing,
pinned WebTransport echo, visible capture, stale-token rejection, clean shutdown and port release.
License
MIT. Third-party software included in the app is listed in
THIRD_PARTY_NOTICES.md.
Part of the Hallows security toolkit.