AppSecNews
DAST Freemium Established Verified profile

Burp Suite

by PortSwigger

Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.

Visit portswigger.net (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Burp Suite in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What it does

Burp Suite is an intercepting proxy with a testing toolkit built around it. You point a browser at Burp, it records every request and response, and you can pause, modify and replay any of them. Everything else works off that captured traffic: Repeater for hand editing single requests, Intruder for driving payload sets across chosen insertion points, Sequencer for analyzing token randomness, Decoder and Comparer, and a site map that accumulates as you browse.

The automated scanner layers on top. It crawls with a browser engine so JavaScript driven navigation is covered, then audits discovered insertion points with active checks, including out of band detection through a collaborator service that catches blind injection and server side request forgery by observing DNS and HTTP callbacks the application makes. That out of band mechanism is the part hardest to replicate elsewhere. Extensibility is the other defining feature: the extender API and a public extension library let you add checks, transform requests, handle unusual session mechanics or automate a workflow specific to a target.

Where it fits

This lives on a tester's laptop, driven by a person. The enterprise edition moves the same scanner onto servers for scheduled and pipeline driven scanning, but the core product is interactive. To get value you need someone who understands web application attacks; Burp amplifies that knowledge rather than substituting for it.

Strengths

  • Complete control over every request, which is what serious manual testing requires and what fully automated tools cannot give you.
  • Out of band interaction detection catches blind vulnerability classes that response based scanning cannot see.
  • A large extension ecosystem, plus a documented API, so odd session handling or custom checks are a scripting problem rather than a dead end.
  • PortSwigger's research output and free training material make it unusually well documented for learners.

Limitations

  • The interactive product does not scale to scanning hundreds of applications on a schedule without moving to the enterprise edition.
  • Steep learning curve. Macros and session handling rules are unforgiving, and misconfiguration produces quiet false negatives.
  • The free community edition throttles Intruder and omits the scanner, so it is a learning tool rather than a working one.
  • Results quality tracks operator skill closely, which makes outcomes hard to standardize across a team.

Who it suits

Essential for penetration testers, bug bounty hunters and application security engineers who do hands on work, and worth the license for any team with at least one person testing regularly. It is the wrong shape for an organization that wants unattended, scheduled coverage of a large estate with minimal staffing, which is a job for a scanner built for that purpose.

Used Burp Suite? Recommend it under your own name and title.

Recommend this tool