
"It feels like I get 10X the productivity on an engagement. The difference is night and day."
Profile
Ray H. is a Security Analyst at a managed security service provider with over 2500 employees worldwide. He performs regular web, API, and mobile pentesting for clients and has been a Burp Suite user since 2019.
Like most pentesters, one of the biggest challenges Ray faces isn't figuring out what to test; it's what to leave behind. On a so-called "four-plus-one" engagement, where he has four days to test and one day to write up his report, he has to use his knowledge and intuition to make hundreds of judgement calls throughout the week.
On a recent engagement, a client-side JavaScript bundle provided just such a dilemma. "There's no way I could justify spending the time going through 66,000 lines of minified JavaScript." He explains. "It's the sort of thing where you have to write it off and hope you've got some spare time at the end of the engagement, which doesn't really happen. A traditional scanner doesn't really help in this situation either: it can tell you some exposed JavaScript is there, but it can't really analyze it in the same way a human would."
Fortunately, Ray had backup.
"I was trialing Burp AT at the time, so I said 'This is some sort of source code disclosure. Can we build on this?'" He continues. Meanwhile, he carried on with his usual process. When he checked back in later, he was shocked by what he saw. While he'd been focussing his attention elsewhere, Burp AT had found a way to leak highly sensitive reports submitted via the client's whistleblower initiative.
"Burp AT had gone through all the JavaScript and figured out what it was for and how it worked. It also told me that each whistleblower report was only locked down behind a six-digit alphanumeric code, so it was potentially possible to bruteforce the codes and pull out what are meant to be confidential reports."
The attack vector was clear, but Ray didn't want to stop at a hypothetical. He wanted to demonstrate the real-world exploitability and impact of the bug for his client. He knew what he had to do, but as Burp AT is natively integrated with the same Burp Suite tools he works with every day, he was able to hand this off to an agent as well.
"I said 'Hey Burp AT, while you're at it, run an Intruder attack to bruteforce the codes.' When I started to see the exfiltrated reports coming back, I thought 'This is going to be a very awkward conversation with the client!'"
It turned out that the vulnerability had been present for a while, and missed during previous security assessments. Not because the other pentesters didn't do their job properly, but because it would previously have been almost impossible, even irresponsible, to dedicate the extensive amount of time required to find it. Ray is convinced that without Burp AT, this pattern would've repeated itself.
"I'm 100% certain that ship would've sailed away for at least another year until the next pentester came along." He confirms. "Even worse, a malicious threat actor could've found it in the meantime and gone on to exploit it."
This serves as a cautionary tale of how many serious vulnerabilities are out there waiting to be discovered, even in apps that undergo routine pentests.
Ray is optimistic that Burp AT can help close the gap in what gets tested, massively increasing the depth and breadth pentesters can realistically cover.
"A lot of what has historically been overlooked can now be actioned. There's so much that humans aren't looking at that Burp AT will now make time for."
He likens his relationship with Burp AT to working with a pentesting partner. "I can outsource what I'd describe as grunt work to the AI." He explains. "I feel like I can confidently say 'You test this' while I do something else and then check back in every half hour or so to see what the agents have come back with."
But that's just one side of it. Like working with a colleague, he feels like pairing with Burp AT is genuinely helping sharpen his own skills.
"No matter how experienced you are, there's still stuff that you won't fully understand, and there's always going to be more to learn." He continues. "With Burp AT I can say 'Hey, this is what I've found. My spidey-senses are tingling here. What have I got? Am I chasing the right thing? How should I investigate it?' The learning opportunity is huge."
The impact on Ray's day-to-day workflow is tangible, even though Burp AT is still in its infancy.
"When I can't use it on an engagement, I genuinely feel like I have withdrawal symptoms!" He jokes. "In all seriousness, though, this is life changing. I cannot begin to express how much easier it started making certain portions of the testing, and how much simpler it's made learning."
Burp AT is currently available to Burp Suite Professional subscribers as part of a public beta. For more details, see https://portswigger.net/burp/burp-at.