Back in April, five major capabilities designed to supercharge security testers, and optimize workflows, with AI were introduced. These are…
Turn Burp AI into your personal pentesting assistant, automating follow-up analysis of scanner-identified vulnerabilities to save time, reduce blind spots, and uncover deeper insights.
Confused by an unfamiliar cookie? Unsure what a strange header means? Just highlight it in Repeater and let Burp AI explain it from a security perspective.This feature removes the friction of switching tabs and searching docs. It’s like having a security-savvy co-pilot in your tab bar.
No more fiddling around with browser recordings. Burp AI can now generate login sequences on your behalf, reducing configuration time and ensuring better scan coverage - especially for complex authentication flows.
False positives drain time and energy. With Burp AI, we’ve started cutting down on the noise - starting with one of the hardest vulnerability classes to reliably detect through automation: Broken Access Control. Burp Scanner now uses AI to intelligently filter out irrelevant findings, boosting accuracy and freeing you up to focus on real threats.
The Montoya API and AI extensibility features open up new creative possibilities. Security pros and developers can now use AI to build novel, customized tools right inside Burp Suite.
In just a few short weeks, we’ve seen a surge of new AI-powered extensions land in the BApp Store, created by both the PortSwigger team and our growing user community.
Check out AI-enhanced extensions on the BApp store, including:
From intelligent request generators to smarter analysis tools, these extensions are a testament to how AI is inspiring creativity and new workflows in web security testing.
Want to learn more about how to create an AI extension? Take a look at PortSwigger Researcher Gareth Heyes' video on what he learned when introducing AI into extensions.
Thousands of testers have already embraced Burp AI, and their feedback has been invaluable. We’ve heard from penetration testers, bug bounty hunters, and developers all making the most of AI to move faster, dig deeper, and reduce toil.
We caught up with Cristi Vlad to discuss his early experiences with Burp AI and get his take on how AI could be transformative for penetration testing in years to come.
Read more about Cristi’s journey with Burp AI.
There’s also been some amazing community moments over the last two months...
Clint Gibler, founder of tl;dr sec, sat down with James Kettle and Dafydd Stuttard for a wide-ranging conversation on how Burp Suite - and now Burp AI - is elevating the art of pentesting. Expect deep dives, big insights, and a glimpse into the vision behind it all.
John Hammond, renowned content creator and red teamer, took Burp AI’s features for a test drive, showcasing how AI augments traditional testing workflows to help you get more out of your search for vulnerabilities.
Katie Warren, Burp AI’s Product Manager, took to the stage at API Days/HAC NYC in May to share our story: Our Journey to AI. This presentation explored how we’re weaving AI into the heart of Burp Suite while staying true to the core principles of effective security testing, and what we’ve learned along the way.
Over the coming months, expect even more AI-powered capabilities that take on the most frustrating, time-consuming parts of your workflow. We’re continuing to listen, refine, and expand Burp AI based on your needs. More precision. More automation. More innovation.
It’s quick and easy to get started with Burp AI:
Not a Burp Suite Pro user yet? Request a free trial.
Don’t forget to share your thoughts on what AI functionality you’d like to see in Burp in the dedicated #burp-ai channel in the PortSwigger Discord. Join the PortSwigger Discord to check it out.