Burp Suite

Professional tools for web application security testing, from scanning for vulnerabilities to exploiting them.

Developer

PortSwigger

verified_user
Visit Official Site open_in_new

description Technical Dossier

Burp Suite by PortSwigger is the de facto standard for web application security testing, used by the vast majority of professional penetration testers worldwide. It provides an integrated platform that combines automated scanning with manual testing tools, allowing security professionals to perform comprehensive assessments of modern web applications.

At its core, Burp Suite operates as an intercepting proxy that sits between the tester’s browser and the target application. All HTTP/S traffic flows through Burp, where it can be inspected, modified, and replayed. This proxy-centric architecture provides complete visibility into application behavior and enables both passive analysis and active exploitation.

The automated scanner component performs deep crawling and audit of web applications, detecting vulnerabilities including SQL injection, cross-site scripting (XSS), XML external entity (XXE) injection, server-side request forgery (SSRF), and many other issues from the OWASP Top 10 and beyond. Burp’s scan engine uses a combination of static and dynamic analysis techniques, including out-of-band detection via Burp Collaborator, to identify vulnerabilities that simpler scanners would miss.

captive_portal Intercepting Proxy

Man-in-the-middle proxy to intercept, inspect, and modify HTTP/S traffic between browser and target application.

bug_report Automated Scanning

State-of-the-art web vulnerability scanner detecting SQL injection, XSS, CSRF, and OWASP Top 10 vulnerabilities.

extension Extensibility

BApp Store with hundreds of community extensions plus Java/Python API for building custom plugins.

repeat Repeater & Intruder

Manual testing tools for replaying and fuzzing requests with customizable payloads and attack patterns.

Distribution Model

Commercial

Licensed software with professional support and enterprise features.

trending_up Popularity

Low 90 / 100 High

settings_suggest Deployment Complexity

Low 20 / 100 High

engineering Technical Difficulty

Low 45 / 100 High
Burp Suite visualization
radar

Scan Types

DAST / IAST

API Testing

REST & GRAPHQL

Extensions

BAPP STORE

License

COMMERCIAL