Support Center

Burp Community

See what our users are saying about Burp Suite:

How do I?

New Post View All

Feature Requests

New Post View All

Burp Extensions

New Post View All

Bug Reports

New Post View All

Burp Suite Documentation

Take a look at our Documentation section for full details about every Burp Suite tool, function and configuration option.

Full Documentation Contents Burp Projects
Suite Functions Burp Tools
Options Using Burp Suite

Burp Extender

Burp Extender lets you extend the functionality of Burp Suite in numerous ways.

Extensions can be written in Java, Python or Ruby.

API documentation Writing your first Burp Suite extension
Sample extensions View community discussions about Extensibility

Feature Requests

Post a feature request

  • Enforce sending of TLS client certificate

    When configuring a TLS client certificate in Burp, it is only used when the server requests it in the TLS handshake. However, it would be very helpful if there would be a checkbox, which enforces usage of the TLS client certificate for certain hostnames. There are servers that don't request one in the TLS handshake, but require one to be sent by the client.

    1 Agent Answer    0 Community Answer
    Dec 03, 2018 11:47AM UTC
  • Security standards

    Do the vunarabilities identified are classified to any security standards (OWASP/CWE)? Also whether the latest scanner covers all the OWASP 2017 top 10 vunarabilities ?

    1 Agent Answer    0 Community Answer
    Nov 23, 2018 11:48AM UTC
  • Is there anyway to automatic resend request with 5xx Status in Intruder module.

    Is there anyway to automatic resend request with 5xx Status & "no response" in Intruder module. I always have to manual resend 100k or more request with 5xx Status or "no response" after 10m request. Which is very exhausting, is there any way to automatic that?

    2 Agent Answers    4 Community Answers
    Nov 02, 2018 05:29PM UTC
  • Per-Extension IRequestResponse Comment

    Adding a comment to a IRequestResponse object can be useful for a number of things. However, not all extensions consider that this is a shared field and may overwrite values set by other extensions. A solution to this may be to store comments per-extension.

    1 Agent Answer    0 Community Answer
    Nov 02, 2018 09:50AM UTC
  • Add duplicate token detection to Sequencer

    I was recently working on a badly broken app that had home rolled session tokens (never a good thing). The token entropy was so bad that there were even duplicates in the sequence. Now, whilst this is the kind of thing that's relatively easy to find by simply sorting/searching for dups in a text editor, it would be a really useful thing to have burnt into the sequencer and mentioned on the...

    1 Agent Answer    0 Community Answer
    Nov 01, 2018 10:25AM UTC
  • Allow custom color highlighting

    I like the color highlighting of requests in the proxy http history, but the hard-coded colors are mostly too bright/vibrant. It would be nice to be able to use a custom color so I can use softer colors.

    1 Agent Answer    0 Community Answer
    Oct 31, 2018 08:53PM UTC
  • No Raw in Response when using Repeater

    I copied my proxy intercept and pasted it in Repeater tab’s Raw. Then click GO (filled host&port), nothing is appeared in Response window. How can i do for see the response raw? (I’m doing webgoat missing function level access control by exercise, and changed proxy-options-proxy listeners interface’s port number from 8080 to 8081 cause it’s unable to click running. My internet proxy option ...

    1 Agent Answer    0 Community Answer
    Oct 27, 2018 06:04PM UTC
  • Dark theme

    Hi! Hackers love to hack by night. And our eyes are so fragile... To be short: I can't wait testing 2beta10 and its new dark theme :-D Looking forward!!

    1 Agent Answer    0 Community Answer
    Oct 26, 2018 11:15AM UTC
  • Search among extensions

    Hi! the BApp Store currently includes nearly 200 extensions. When having a specific need, I systematically go the Web version ( and Ctrl+F the page. That requires Internet access, breaks my testing workflow and doesn't work if the searched criteria only appears in the extended desc. I solved that with a local copy of the BApp Store that I can easily grep. ...

    1 Agent Answer    0 Community Answer
    Oct 26, 2018 11:12AM UTC
  • Side-by-side View

    Hi! Currently, displaying a request+response pair side-by-side is only possible in Repeater ("Repeater -> View -> Left/right split" from the menu bar) or via extensions like Flow or Logger++. I use this layout a lot and I'd like to have it in other areas of Burp Suite, like Target / Site Map, Proxy / History, Intruder results, ...

    1 Agent Answer    2 Community Answers
    Oct 26, 2018 11:03AM UTC