Burp Suite User Forum

Create new post

Custom Attributes on issues

Anthony | Last updated: Mar 10, 2018 07:22AM UTC

Add IssueAttributes[] to the IScanIssue object that would get exported with the xml report. Name/Value pairs would suffice, however, nested objects would be awesome. This new property would have to come with all the standard methods add/remove/edit. The use case for this would be so bapp’s could, for example, assign a score to an issue that could represent things like risk, likelihood, impact, etc. This would help organizations better implement NIST 800-30 scoring or OWASP Risk rating, inside of burp. This would give flexibility to organizations to consume burps output in more interesting and creative ways.

PortSwigger Agent | Last updated: Mar 12, 2018 08:43AM UTC

Hi Anthony, Thanks for this suggestion. We think this is a good idea: it would be useful to some users, and can be implemented without excessive complexity. We've got a program of work planned in the future which will expand the capability to have custom scan issues. We'll consider your suggestion when we do this. Unfortunately our development team is quite busy at the moment, so it is likely to be some time until this work begins.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.