Burp Scanner is a web vulnerability scanning tool built into Burp Suite Professional. You can use Burp Scanner to automatically map the attack surface and identify vulnerabilities in both web ...
Burp includes a number of built-in scan configurations that enable you to modify how Burp Scanner crawls and audits web applications. This page explains the settings changed in each built-in ...
Burp Suite DAST is designed for automated scanning at any scale and enables integration with your software development processes. Like any security testing software, Burp Suite contains functionality ...
Burp Suite brings AI to your security testing in two complementary ways: Burp AT, which brings agentic AI to human-led pentesting, and Burp AI, which assists you within the Burp tools you already use.
This documentation describes the functionality of all editions of Burp Suite and related components. Use the links below to get started: ...
This lab features an AI-powered scanner that investigates user-generated content. The scanner has been given the login credentials for carlos so it can explore ...
This lab is vulnerable to indirect prompt injection. The application features an AI-powered scanner that can be manipulated into exploiting a routing-based SSRF ...
The BApp Store contains community-created extensions that you can install directly from Extensions > BApp Store in Burp with a single click. We review all extensions submitted to the BApp Store, but ...
To determine the way in which payloads are assigned to payload positions, you can specify an attack type. Attack types enable you to configure whether: Payloads are taken from a single set, or ...
Burp Scanner is capable of detecting a wide range of vulnerabilities, which are flagged by the scanner as issues. This table lists all vulnerabilities that can be identified by Burp Scanner. It is ...
Burp Suite is a comprehensive suite of tools for web application security testing. This interactive tutorial is designed to get you started with the core features of Burp Suite as quickly as possible.
This lab contains a vulnerability that enables you to read arbitrary files from the server. To solve the lab, retrieve the contents of /etc/passwd within 10 minutes. Due to the tight time limit, we ...