Professional

Shadow Repeater

Shadow Repeater enhances your manual testing with AI-powered, fully automatic variation testing. Simply use Burp Repeater as you normally would, and behind the scenes Shadow Repeater will monitor your attacks, try permutations, and report any discoveries via Organizer.

Whether you're probing for path traversal, SQL injection, XSS, or other vulnerabilities, Shadow Repeater intelligently mutates your inputs and analyzes responses for anomalies, making it valuable for in-depth manual testing and fuzzing. Stay one step ahead by discovering bypasses and alternative attack vectors that might otherwise go unnoticed.

Features

  • Automated Payload Mutation - Automatically mutates user generated payloads
  • Anomaly Detection - Analyzes responses using response diffing to flag interesting items
  • Intelligent Fuzzing - Enhances manual testing by automating attack vector discovery
  • Repeater Integration - Activates automatically by default after the fifth modified Repeater request

Usage

  • Install Shadow Repeater and tick the "Use AI" checkbox.
  • Use Repeater to test endpoints.
  • Every 5th request, Shadow Repeater will send variations of your attacks and look for differences in the response.
  • If Shadow Repeater finds something interesting, it will send it to the "Organizer" tool for further inspection.

Copyright © 2025 PortSwigger Ltd.

Author

Author

Gareth Heyes, PortSwigger

Version

Version

1.0.0

Rating

Rating

Popularity

Popularity

Last updated

Last updated

20 February 2025

Estimated system impact

Estimated system impact

Overall impact: Empty

Memory
Empty
CPU
Empty
General
Empty
Scanner
Empty

You can install BApps directly within Burp, via the BApp Store feature in the Burp Extender tool. You can also download them from here, for offline installation into Burp.

You can view the source code for all BApp Store extensions on our GitHub page.

Follow @BApp_Store on Twitter to receive notifications of all BApp releases and updates.

Please note that extensions are written by third party users of Burp, and PortSwigger Web Security makes no warranty about their quality or usefulness for any particular purpose.

Go back to BappStore

Note:

Please note that extensions are written by third party users of Burp, and PortSwigger Web Security makes no warranty about their quality or usefulness for any particular purpose.