Support Center

Burp Community

See what our users are saying about Burp Suite:

How do I?

New Post View All

Feature Requests

New Post View All

Burp Extensions

New Post View All

Bug Reports

New Post View All

Burp Suite Documentation

Take a look at our Documentation section for full details about every Burp Suite tool, function and configuration option.

Full Documentation Contents Burp Projects
Suite Functions Burp Tools
Options Using Burp Suite

Burp Extender

Burp Extender lets you extend the functionality of Burp Suite in numerous ways.

Extensions can be written in Java, Python or Ruby.

API documentation Writing your first Burp Suite extension
Sample extensions View community discussions about Extensibility

Feature Requests

Post a feature request

  • Intruder - Payload Processing: Macro - Add prefix/suffix

    On some circustances there is the need to process a dynamic value like anti-csrf token and append this to a parameter. I'm not sure this could be helpful to others, anyway should be a great feature.

    2 Agent Answers    0 Community Answer
    Oct 09, 2018 10:09AM UTC
  • additional decoder compression options

    It would be really useful if decoder had options to deal with deflate and brotli as well as gzip ...

    1 Agent Answer    1 Community Answer
    Oct 02, 2018 12:52PM UTC
  • Shortcut for Action "Do intercept - Response to this request"

    Hello, I use the option "Do intercept - Response to this request" all the time in the Proxy Intercept - tool. Would it be possible to add a shortcut - or even better - add it to the buttons at the top (next to "Forward, Drop, Intercept is on, Action")? That would help me a lot, and save me a ton of time! Or, is there a way I can do this myself by editing the UI so...

    1 Agent Answer    0 Community Answer
    Sep 28, 2018 10:42AM UTC
  • Burp scanner paused for unknown reasons

    In Burp 2.0.07beta, the crawl&scan can sometimes pauses. The message in the Dashboard reads: "Paused do to error: X consecutive audit items have failed." where X is a number (by default the first time it occurs 10). I'm testing a regular Wordpress website that doesn't use cookies at all and has no login mechanism. When the error message in the log is shown, I would li...

    5 Agent Answers    6 Community Answers
    Sep 27, 2018 11:55AM UTC
  • Shared configuration between Pro and Enterprise

    Hi, The Configuration Library is awesome in Beta2, and I can see same pre-defined templates in Enterprise Edition. Would it be possible to cross-promote settings easily? Like show Burp Pro the address to Burp EE, so that it could always take the fresh config, or even change it? In my opinion, people will want to manually improve configuration locally in Burp Pro, which will then be needed to expo...

    1 Agent Answer    0 Community Answer
    Sep 26, 2018 01:37PM UTC
  • Burp REST API - capturing traffic

    Hi, in my experience, launching an active scan on valid dataset from Proxy is the best approach. We have regular releases, triggering test packs for changed functionality which can be routed through Burp Suite. So far, we always opened manually new Proxy listener, captured traffic, closed it, and ran active scan. Would it be possible, to enhance the REST APIs to be able to start listening on c...

    1 Agent Answer    0 Community Answer
    Sep 26, 2018 11:04AM UTC
  • Burp Enterprise - blackout periods

    Hi, would it be possible to add a feature in Scheduling GUI for blackout periods? For example, every day, twice a day, during certain hours there are locks on environments for regression testing, during which the environment should not be used. Or, if the scan is of production, and they need to test it only during work hours when there is someone on-call, we want to be able to tweak it as such. ...

    1 Agent Answer    0 Community Answer
    Sep 26, 2018 10:54AM UTC
  • Automating burp scans

    Hello, We are interested in automating scans using Burp Suite. I came across this post/thread discussing the same where it was suggested that this capability would be available in future and currently instead had to use Carbonator - Wanted to check if there have been any development on this feature since...

    1 Agent Answer    0 Community Answer
    Sep 24, 2018 10:27PM UTC
  • Highlight data that has been automatically changed by burp

    It would be helpful to visually mark data that has been automatically changed in a request/response by Burp. Occasionally, I'll stumble when some request data has been changed by a session handling rule or req/resp matcher without me noticing it. It would be nice if the data in question is highlighted or colored in the editor window to denote the change.

    1 Agent Answer    0 Community Answer
    Sep 24, 2018 04:12PM UTC
  • Enterprise Edition proxy for scan agents

    Hi, If I understand it correctly, currently, when I add proxy in Burp EE, it's mainly used for sharing feedback with portswigger (correct me if I'm wrong). However, because of various issues with Burp 2 at the moment (running into noscript directive and always being redirected elsewhere; and problems with using current user-agent), the scan of a very big site is finished within a few r...

    1 Agent Answer    0 Community Answer
    Sep 24, 2018 12:16PM UTC