appsec.fyi

Burp Suite — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

Burp Suite: A Practical Guide

Curated and synthesized by . Last updated 2026-10-01. Synthesized from 178 of 178 curated resources. Browse all 178 Burp Suite resources →

Problem Framing

Application security testing, by its nature, is an iterative and often time-consuming process. While Burp Suite's core functionality provides a robust foundation for intercepting, analyzing, and manipulating web traffic, its effectiveness can be significantly amplified through specialized tools and techniques. For seasoned practitioners, the goal is to move beyond generic scanning and delve into nuanced vulnerabilities, complex attack chains, and efficient reconnaissance. This often involves augmenting Burp's built-in capabilities with custom scripts, third-party extensions, and optimized workflows to maximize both depth of analysis and speed of execution. The challenge lies in identifying, integrating, and effectively leveraging these augmentations to uncover security weaknesses that might otherwise be missed.

Core Mechanics

Burp Suite's extensibility is its cornerstone. At its heart, the platform operates as an HTTP proxy, meticulously capturing and allowing manipulation of traffic between a client and server [1]. This fundamental capability is extended through various mechanisms:

These core mechanics provide the framework upon which advanced testing strategies are built.

Notable Techniques and Extensions

The Burp Suite ecosystem is rich with extensions and techniques that cater to specific testing needs. For experienced professionals, understanding how to leverage these can dramatically improve efficiency and discovery.

High-Speed Attacks and Fuzzing

For scenarios demanding an immense volume of requests, Turbo Intruder stands out. Built from the ground up for speed, it can achieve tens of thousands of requests per second, outperforming standard Burp Intruder [18]. It's configurable via Python scripts and handles complex tasks like signed requests and multi-step sequences. The introduction of HTTP/3 support further amplifies its performance, enabling speeds of up to 100,000 RPS and beyond [19].

Session Management and Authorization Testing

Managing multiple user sessions during authorization testing can be tedious. Session Switcher simplifies this by allowing users to save and switch between named sessions (cookies and headers) with a few clicks directly from the request editor [20]. This is crucial for efficiently testing horizontal and vertical privilege escalation, and IDORs. Extensions like Autorize [21][22] and AuthMatrix [23][24] also focus on automating authorization testing by repeating requests with different user sessions or defining privilege matrices. AutoRepeater automates the duplication, modification, and resending of requests for streamlined authorization testing [25].

API Security Testing

With the rise of APIs, specialized tools are essential. SulphurAPI aims to automate OWASP API Top 10 detection, including checks for mass assignment, authentication, and authorization, with OpenAPI parsing capabilities [26]. BurpAPISecuritySuite consolidates numerous API testing functionalities into a single extension, offering reconnaissance, intelligent fuzzing, and AI integration for REST, GraphQL, and SOAP APIs [27]. GraphQL Raider specifically targets GraphQL security [28][29]. JS Miner and JS Link Finder help in analyzing JavaScript for API endpoints and hidden logic [29].

Advanced Reconnaissance and Discovery

Identifying hidden parameters and endpoints is critical. Param Miner enumerates hidden and undocumented parameters using heuristics and intelligent guessing, making it invaluable for finding web cache poisoning vulnerabilities [29][30]. Extensions like Endpoint Finder and JSReconduit aid in discovering API endpoints by analyzing JavaScript code [28][31].

AI-Powered Augmentation

Burp Suite is increasingly integrating AI capabilities. Extensions can now leverage AI for tasks such as analyzing requests, generating prompts, explaining code, and even assisting in vulnerability discovery [14][15][16][32][17]. This includes features like AI-powered custom actions in Repeater [33] and tools that use LLMs for security analysis [34][35]. Extensions like BurpGPT leverage OpenAI models for traffic analysis [36], while others integrate with providers like DeepSeek [37] or provide AI-driven payload generation [7].

Customization and Automation with Bambdas and BChecks

For tailored analysis within Burp's existing tools, Bambdas and BChecks offer powerful scripting capabilities. Bambdas allow custom filtering and data manipulation directly in tables like HTTP history [9][10]. BChecks enable the creation of custom scanner checks, automating specific vulnerability detection logic [11][38][13]. These are particularly useful for creating specialized tests not covered by default scans.

Specific Vulnerability Hunting Tools

Beyond general-purpose extensions, specialized tools address specific vulnerability classes:

Reporting and Workflow Enhancement

Extensions like Pentest-Mapper help organize testing by integrating request logging with custom checklists [45][46][47]. Copy For streamlines generating command-line syntax for various tools from Burp requests [48]. Integrating with external platforms like Neuron can centralize findings and reporting [49].

Detection and Prevention

Burp Suite's detection capabilities are broad, encompassing passive scanning, active scanning, and the extensive functionalities of its extensions.

Passive Scanning

Burp's built-in passive scanner analyzes traffic without generating additional requests, looking for obvious security issues [50]. Extensions can augment this by adding custom passive checks, identifying more subtle misconfigurations or patterns [28][7].

Active Scanning

Burp Scanner actively probes applications for vulnerabilities by sending crafted requests. This process can be significantly enhanced by custom scan checks written in BChecks or Java extensions, allowing for highly specialized attack payloads and logic [11][13][51][52]. Extensions like Active Scan++ and Burp Bounty further extend active scanning capabilities [28][7][53][23][29][8]. The introduction of HTTP/3 support in tools like Turbo Intruder means that high-volume active scanning can now leverage this newer protocol for potentially faster reconnaissance and vulnerability discovery [19].

Exploitation and Verification

While Burp excels at identifying potential vulnerabilities, extensions can assist in their verification and exploitation. Tools like Turbo Intruder can perform complex, high-speed attacks necessary for exploiting race conditions [19][18]. AI-powered extensions can also suggest exploit vectors or assist in crafting payloads [14][16][17]. Burp Collaborator is instrumental for out-of-band application security testing (OAST), allowing for the detection of blind vulnerabilities like SSRF and blind XSS by capturing external interactions [54][38].

Preventing Exploitation

For defenders, understanding how Burp is used informs better security posture. Secure coding practices, rigorous input validation, and output encoding are fundamental. Properly configuring security headers, implementing strong access controls, and keeping software updated are crucial. The ability of extensions to automate sophisticated attacks highlights the need for robust WAFs, API gateways, and intrusion detection systems that can identify and block complex or high-volume malicious traffic patterns. The focus on HTTP/3 by some extensions [19] also means that organizations need to ensure their infrastructure is adequately secured for newer protocols.

Tooling: Extensions and Integrations

The true power of Burp Suite for advanced users lies in its extensibility. The BApp Store is the primary gateway to a vast ecosystem of tools [6][7][29][8].

Key Extension Categories:

Montoya API: The Modern Extension Framework

The Montoya API, introduced in recent Burp Suite versions, provides a more modern and robust interface for developing extensions. It offers better support for features like WebSockets, AI integration, and cleaner UI development [3][4][2]. Extensions developed using Montoya are generally more performant and easier to maintain.

Integrating with External Tools

Burp Suite can also be integrated into broader security toolchains. For instance, Nmap and Metasploit are often used in conjunction with Burp, forming a powerful pipeline from reconnaissance to exploitation [57]. Extensions and custom scripts can further bridge these tools, automating data transfer and analysis.

Recent Developments

The Burp Suite ecosystem is dynamic, with continuous innovation driven by PortSwigger and the security community.

HTTP/3 Support

A significant recent development is the integration of HTTP/3 support, particularly within Turbo Intruder [19]. This allows for attacks over the latest HTTP protocol, expanding the attack surface and enabling new types of vulnerabilities, such as race conditions specific to HTTP/3. The HTTP/3 Adapter plugin bridges this functionality to the broader Burp Suite [19].

AI-Powered Extensibility

The integration of AI into Burp Suite is a major trend [14][15][16][17][34]. The Montoya API provides a structured way for extensions to leverage AI models, enabling more sophisticated analysis, vulnerability detection, and automated reporting. This is transforming how tasks are performed, allowing for more efficient identification of complex issues [33][17][35].

Enhanced Scripting Capabilities (Bambdas and BChecks)

The ongoing refinement and expansion of Bambdas and BChecks continue to empower users with in-app scripting for custom automation and specialized scanning [9][10][11][38][13]. These features provide a lower barrier to entry for creating custom security tests compared to full extension development.

Improved Table Navigation and Performance

Recent releases have focused on quality-of-life improvements, such as faster table navigation with command palettes [58] and performance optimizations in extensions like Turbo Intruder [19]. These seemingly minor updates contribute to a more efficient and less frustrating user experience during extensive testing.

Where to Go Deeper

For practitioners looking to master Burp Suite and its extensibility, several resources are invaluable:

Sources cited in this guide

  1. Burp Suite Professional Testing Handbook — appsec.guide
  2. Burp Suite Extensions - Overview and Introduction with Kotlin — scip.ch
  3. Power Up Pen Tests: Create Burp Suite Extensions with Montoya API — bishopfox.com
  4. A Guide to Build Burp Suite Extensions Using Montoya API and Java — medium.com
  5. Bambdas - PortSwigger Documentation — portswigger.net
  6. Installing Extensions from BApp Store | PortSwigger — portswigger.net
  7. BApp Store | PortSwigger — portswigger.net
  8. https://github.com/snoopysecurity/awesome-burp-extensions — github.com
  9. Filtering the HTTP history with scripts (Bambdas) — portswigger.net
  10. Writing Burp Bambda Filters Like a Boss — danaepp.com
  11. Improve your API Security Testing with Burp BCheck Scripts — danaepp.com
  12. BChecks/vulnerability-classes/injection at main · PortSwigger/BChecks · GitHub — github.com
  13. PortSwigger/BChecks: BChecks collection for Burp Suite Professional — github.com
  14. The Future of Security Testing: AI-Powered Extensibility in Burp — portswigger.net
  15. Developing AI features in Burp extensions — portswigger.net
  16. Burp AI - PortSwigger Documentation — portswigger.net
  17. Burp Suite Goes AI: Revolutionizing Web Pentesting — gracker.ai
  18. Turbo Intruder: Embracing the Billion-Request Attack — portswigger.net
  19. HTTP/3 in Burp Suite - it’s time to find a bigger wordlist — portswigger.net
  20. Introducing Session Switcher. Swap Burp Sessions with One Click! — blog.doyensec.com
  21. Top 10 Pentesting Tools and Extensions in Burp Suite | PortSwigger — portswigger.net
  22. https://portswigger.net/blog/some-of-the-best-burp-extensions-as-chosen-by-you — portswigger.net
  23. Burp Suite - Top Extensions | KSEC ARK Pentesting Knowledge Base — ivoidwarranties.tech
  24. Authorization Testing: AuthMatrix - Part 1 | White Oak Security — whiteoaksecurity.com
  25. nccgroup/AutoRepeater: Automated HTTP Request Repeating With Burp Suite — github.com
  26. SulphurAPI: Burp Suite extension for automating OWASP API Top 10 detection — github.com
  27. Teycir/BurpAPISecuritySuite: Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and automated reconnaissance. Supports REST/GraphQL/SOAP APIs with Nuclei, Turbo Intruder, and external tool integration. OWASP API Top 10 coverage. — github.com
  28. Awesome Burp Extensions 2025 — github.com
  29. Top 20 Useful Burp Suite Extensions for Web Application Pentesting — cybersecwriteups.com
  30. PortSwigger/param-miner — github.com
  31. MantisSTS/JSReconduit: Passive JavaScript reconnaissance for penetration testers — bridging Burp Suite traffic into structured, AST-based analysis in VSCode. — github.com
  32. Burp Suite AI Extension for Pentester — medium.com
  33. Burp Suite Professional 2025.5 Release — portswigger.net
  34. The Future of Pentesting: Burp Suite + Cursor AI — medium.com
  35. SILENTCHAIN AI - AI-Powered Security Testing — silentchain.ai
  36. aress31/burpgpt — github.com
  37. GitHub - IckoGZ/burp-deepseek: A quick and dirty (and a little shitty) burp extension that uses cheap deepseek api to send request and response and maybe found something interesting. — github.com
  38. Example Collaborator-based check — portswigger.net
  39. GitHub - nccgroup/BurpSuiteHTTPSmuggler: A Burp Suite extension to help pen — github.com
  40. d0ge/sign-saboteur: SignSaboteur is a Burp Suite extension for editing, sig — github.com
  41. Introducing DOM Invader: DOM XSS just got a whole lot easier to find — portswigger.net
  42. Burp Suite for Pentester: Software Vulnerability Scanner & Retire.js — hackingarticles.in
  43. AES-Killer v3.0 - Burp Plugin To Decrypt AES Encrypted Traffic Of Mobile Apps On The Fly — kitploit.com
  44. GitHub - 0x999-x/jsluicepp: jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice — github.com
  45. Pentest-Mapper: Burp Extension for Pentesters & Bug Bounty — github.com
  46. Pentest Mapper: Burp Extension for Application Pentesting — github.com
  47. Pentest Mapper — PortSwigger BApp Store — portswigger.net
  48. Burp Suite Extension: Copy For — Black Hills InfoSec — blackhillsinfosec.com
  49. Burp Suite Integration for Neuron — news.pentest.ws
  50. Smart Automation with Burp Suite - YesWeHack — yeswehack.com
  51. My First Burp Suite Extension — itsecguy.com
  52. My First Burp Suite Extension — itsecguy.com
  53. Burp Bounty - Scan Check Builder Extension — github.com
  54. Proving API exploitability with Burp Collaborator — danaepp.com
  55. burpa: Burp Automator — github.com
  56. BurpSuite Extensions: Some Favorites - VDA Labs — vdalabs.com
  57. Toolchain: Nmap, Burp Suite, and Metasploit - A Practical Workflow Guide — tryhackme.com
  58. Burp Suite Professional 2026.1 Release — portswigger.net
  59. https://www.infosecurity-magazine.com/news/portswigger-launches-web-security/ — infosecurity-magazine.com
  60. PortSwigger Launches Web Security Academy — infosecurity-magazine.com
  61. Great getting started resources for new users of Burp Suite Professional | — portswigger.net
  62. Automating Burp Suite -4 | Understanding And Customising Custom Header From — infosecwriteups.com
  63. Bambdas Collection for Burp Suite Professional and Community — github.com
  64. 254Labs/awesome-bambdas: A collection of Burp Suite Lambda Filters ~ Bambda — github.com
  65. GitHub - federicodotta/Burp-Suite-Extender-Montoya-Course: This repository — github.com
  66. Burp Extension Dev Part 1: Setup & Basics - TCM Security — tcm-sec.com
  67. synfron/ReshaperForBurp — github.com
  68. https://github.com/lucsemassa/burp_bug_finder — github.com
  69. xnl-h4ck3r/GAP-Burp-Extension — github.com
  70. PortSwigger Web Security Blog: Writing your first Burp Suite extension — blog.portswigger.net
  71. Burp Share Requests - PortSwigger — portswigger.net
  72. Sticky Burp, Reusable and Replaceable Environment Variables — portswigger.net
  73. GitHub - vsec7/BurpSuite-Xkeys: A Burp Suite Extension to extract interesting strings (key, secret, token, or etc.) from a webpage. — github.com
  74. GitHub - trufflesecurity/trufflehog-burp-suite-extension: Official TruffleHog Burp Suite Extension. Scan Burp Suite traffic for 800+ different types of secrets (API keys, passwords, SSH keys, etc) using TruffleHog. — github.com
  75. A Burpsuite Extension For JS Reconnaissance - Jsmon — blogs.jsmon.sh
  76. GitHub - hackerassociate/SSRF-Hacks-IP-Decimal: A Burp Suite extension that converts IP addresses to decimal notation, useful for SSRF bypass and WAF evasion testing. Created by Harshad Shah. — github.com
  77. burp-extensions-montoya-api-examples/customlogger/src/main/java/example/customlogger/MyTableModel.java at main · PortSwigger/burp-extensions-montoya-api-examples — github.com
  78. Hacking API discovery with a custom Burp extension — danaepp.com
  79. Burp-Montoya-Utilities/src/main/java/com/coreyd97/BurpExtenderUtilities/PopOutPanel.java at master · CoreyD97/Burp-Montoya-Utilities — github.com
  80. burp-extensions-montoya-api-examples/collaborator/src/main/java/example/collaborator/CollaboratorExample.java at main · PortSwigger/burp-extensions-montoya-api-examples · GitHub — github.com
  81. GitHub - synacktiv/HopLa: HopLa Burp Suite Extender plugin - Adds autocompletion support and useful payloads in Burp Suite — github.com
  82. videos[1] = "GAP Burp Extension" — youtube.com
  83. Swing in Python Burp Extensions - Part 1 — parsiya.net
  84. RepeaterSearch — github.com
  85. A Step-by-Step Guide to Writing Extensions for API Pentesting in BurpSuite — danaepp.com
  86. Why u should use burp to test Path Traversal Vulnerability and also get RXSS — medium.com
  87. Leveraging Burp Suite extension for finding IDOR(Insecure Direct Object Reference). — medium.com
  88. PimpMyBurp — blog.yeswehack.com
  89. How i exploit out-of-band resource load (HTTP) using burp suite extension plugin (taborator) — link.medium.com
  90. SleuthQL - Burp History Parsing Tool To Discover Potential SQL Injection Po — kitploit.com
  91. I Wasted 3 Days Intercepting a Flutter App. Here’s What Actually Works. — infosecwriteups.com
  92. I Found the Entire Admin UI of a Live PlatformJust By Tweaking Traffic in Burp Suite — infosecwriteups.com
  93. Weaponize Your Burp - Bug Bounty Hunting Automation — github.com
  94. Creating Burp Extensions: A Beginner's Guide - Black Hills InfoSec — blackhillsinfosec.com
  95. Top 10 Burp Extensions Every Pentester Should Use — datafarm-cybersecurity.medium.com
  96. 10 Burp Suite Extensions That Will Instantly Boost Your Work — medium.com
  97. Top 10 Burp Suite Extensions Every Pentester Should Use — linkedin.com
  98. 3 Powerful Burp Suite Extensions Every Pentester Should Use — medium.com
  99. Top 10 Must-Have Burp Suite Extensions for Web Application Security (2024) — medium.com
  100. Network Penetration Testing Tools Market Is Going to Boom |? Nessus ? Burp Suite ? Metasploit — openpr.com
  101. Burp Suite | Pentest Book — pentestbook.six2dez.com
  102. Web App Hacking: Finding Web App Vulnerabilities with Caido Scanner — x.com
  103. Web App Hacking: Finding Web App Vulnerabilities with Caido Scanner — x.com
  104. Burp Suite: The Basics TryHackMe Writeup — medium.com
  105. Vulnerabilities detected by Burp Scanner - PortSwigger — portswigger.net
  106. botesjuan/Burp-Suite-Certified-Practitioner-Exam-Study — github.com
  107. The Top 8 Burp Suite Extensions - Think outside the box — kalilinux.co
  108. Open Security Research: Extending Burp Proxy With Extensions — blog.opensecurityresearch.com
  109. Web App Pentesting With Burp Suite Scan Profiles | White Oak — whiteoaksecurity.com
  110. https://www.whiteoaksecurity.com/web-app-pentesting-burp-suite-scan-profile/ — whiteoaksecurity.com
  111. https://gist.github.com/righettod/862728e1476c0551f1ddf38f099a1803 — gist.github.com
  112. Using Burp to Test a REST API | Burp Suite Support Center — support.portswigger.net
  113. The Top 5 Burp Suite Extensions — joecmarshall.com
  114. https://www.hackingarticles.in/burp-suite-for-pentester-hackbar/ — hackingarticles.in
  115. #burp #pentest #ai #hackerassociate #cybersecurity #infosec… | Harshad Shah — linkedin.com
  116. Best Browser Extensions for Bug Hunting and Cybersecurity — infosecwriteups.com
  117. API Testing with Insomnia and Burp Suite: An Alternative to Postman — wafflesexploits.github.io
  118. Mindmap/Burp Suite/Burp Suite Normal.png at main · Ignitetechnologies/Mindmap — github.com
  119. Top 10 Browser Extensions Every Bug Bounty Hunter Needs — medium.com
  120. Testing Handbook - Burp — docs.google.com
  121. Mastering Web Research with Burp Suite — events.goldcast.io
  122. Here's how I get the most out of Burp Suite reporting — danaepp.com
  123. JS Link Finder Burp Suite Extension Guide — taksec.medium.com
  124. Burp Suite Shorts | Automatic Session Handling — youtube.com
  125. Burp Suite Shorts | Automatic Session Handling — youtube.com
  126. How to build custom scanners for web security research automation — portswigger.net
  127. A lightweight web security auditing toolkit — caido.io
  128. burp.IBurpExtenderCallbacks java code examples — tabnine.com
  129. Proxying Burp Traffic through VPS using SOCKS Proxy — busk3r.medium.com
  130. Proxying MetaSploit through BurpSuite — security.stackexchange.com
  131. Web App Hacking with Caido.io — youtube.com
  132. DNS Analyzer - Finding DNS vulnerabilities with Burp Suite — sec-consult.com
  133. Web Application Hacking with Burp Suite — manning.com
  134. How to use Burp Suite Like a PRO? — medium.com
  135. Burp Suite Extensions Rarely Utilized but Quite Useful — medium.com
  136. Favorite tweet by @Burp_Suite — twitter.com
  137. Favorite tweet by @PortSwigger — twitter.com
  138. Favorite tweet by @Jhaddix — twitter.com
  139. Favorite tweet by @e11i0t_4lders0n — twitter.com
  140. Favorite tweet by @cedoxX — twitter.com
  141. Favorite tweet by @fardeenahmed411 — twitter.com
  142. Favorite tweet by @ptracesecurity — twitter.com
  143. BUG BOUNTY HUNTING WITH BURP SUITE — udemy.com
  144. Improvements to Burp Suite authenticated scanning — portswigger.net
  145. Authorization Testing: AuthMatrix - Part 1 | White Oak Security — whiteoaksecurity.com
  146. Web App Pentesting With Burp Suite Scan Profiles | White Oak — whiteoaksecurity.com
  147. Web App Pentesting With Burp Suite Scan Profiles — whiteoaksecurity.com
  148. Burp Suite for Pentester: Repeater — hackingarticles.in
  149. Top 11 extensions to turn your browser into an advance hacking tool — iics.medium.com
  150. RequestBin Collect inspect and debug HTTP requests and webhooks — requestbin.net
  151. Detecting and annoying Burp users — dustri.org
  152. Web App Pentesting With Burp Suite Scan Profiles | White Oak — whiteoaksecurity.com
  153. BurpSuite Extensions: Some Favorites - VDA Labs — vdalabs.com
  154. The Top 5 Burp Suite Extensions — joecmarshall.com
  155. The Top 8 Burp Suite Extensions - Think outside the box — kalilinux.co
  156. Introducing HTTP Anomaly Rank — portswigger.net
  157. Top 10 Web Hacking Techniques of 2025: Call for Nominations — portswigger.net
  158. How Burp Suite DAST Is Leveling Up Enterprise Security in 2025 — portswigger.net
📚 This guide is synthesized from the full text of resources curated in the Burp Suite library, and refreshed as new material is added.