Burp AT

Burp, redefined.

Burp AT brings agentic AI to human-led pentesting, with Burp’s proven tools, project context, and purpose-built skills.

Live in public beta for Burp Suite Professional users.

Burp AT TASKS SSRF check · /api/stock 34 requests · 8 tool calls Auth bypass · /admin 36 requests · 14 tool calls IDOR sweep · /api/v2 60 requests · 22 tool calls Race condition · promo code analysis 88 requests · 19 tool calls Check whether there is a race condition in the promo code functionality BURP AT I'll activate the race condition skill and search for relevant tools to get started. SKILL limit-overrun-race-condition Use when a resource has any form of limit in order to overrun that limit via a race condition with the single-packet attack. BURP AT The skill is loaded. I need to find the request that applies a promo code. Let me check the site map and proxy history for that functionality. Request Send to ▾ 1 POST /checkout/apply-coupon HTTP/2 2 Host: ginandjuice.shop 3 Cookie: session=gGVZKNT7wxOVITzYnmAVzDeasTphU1Bt 4 Content-Type: application/x-www-form-urlencoded 5 Content-Length: 52 6 Origin: https://ginandjuice.shop
Why now

Pentesting takes more than a capable model

Frontier AI models can find and exploit vulnerabilities. Agents can form a hypothesis, act through tools, interpret what they learn, and decide what to try next.

But a professional pentest requires more than capable reasoning. It requires reliable specialist tools, access to relevant context, purpose-built methodology and boundaries the model cannot bypass.

Burp AT was built for that challenge.

What it does

Agentic AI that thinks like a pentester, with the tools of a pentester.

Web pentesters and bug bounty hunters alike are already experimenting with general-purpose coding agents to automate and enhance parts of their workflow. But leveraging this capability professionally can mean assembling tools, developing prompts and workflows, managing context and trusting a model to enforce its own restrictions. That’s not to mention the ongoing maintenance effort, meaning you spend more time on software engineering than hacking.

Burp AT gives you a ready-to-use, specialist alternative. Agents work with Burp Suite’s tools and project context, use purpose-built pentesting skills, and operate reliably within the scope and permission boundaries you define and Burp enforces.

// The Burp tools you trust

Burp Suite’s specialist tools, in the hands of your agents.

Burp AT is natively integrated with Burp Suite. It equips agents with the same specialist, battle-hardened web security tooling trusted by professional pentesters for over 20 years.

The model works out the strategy, but uses Burp Suite’s tools to act. This enables them to work with protocol edge cases, malformed traffic and unusual application behaviour that can derail workflows built on improvised scripts and general-purpose libraries.

BURP SCANNER · CRAWL BURP AT Good — I have the tooling I need. Let me start recon in parallel: fingerprint the server, kick off a crawl, and check existing proxy history. 3 tools ran Escalated by Smart mode · Crawl SCANNER Allow Burp AT to Crawl? ⌃ Collapse details INPUTS Start URLs https://ginandjuice.shop/ Task name ginandjuice.shop · Initial Crawl
// Purpose-built pentesting skills

Purpose-built skills, developed with PortSwigger Research.

Burp AT draws on a library of pentesting skills developed with PortSwigger’s world-renowned research team. This means agents can follow structured, task-specific methodology rather than inventing a pentesting workflow from general model knowledge.

As PortSwigger Research develops and refines testing techniques, those approaches can be translated into reusable skills for agents to apply during real tests. This creates a direct path from research breakthrough to repeatable testing without every user having to interpret and operationalise the research independently. As the skills library grows, so does the range and depth of work Burp AT can take on.

SKILLS BANK · PORTSWIGGER RESEARCH We're testing ginandjuice.shop end-to-end. BURP AT I'll kick off recon and activate the content discovery skill. SKILL content-discovery Use this to identify hidden directories, files, endpoints, and functionality on a web application. PortSwigger Research · Burp AT skills bank active BURP AT Good — tooling's ready. Starting recon in parallel. 3 tools ran
// Autonomy on your terms

Hand off the repetition. Keep the judgment.

Highly granular control over permissions means you can flexibly adapt the level of autonomy. Begin with tighter approvals, then gradually give Burp AT more autonomy as it earns your trust. Alternatively, you can adapt the autonomy to suit the engagement.

Smart approvals can reduce approval fatigue, allowing routine actions to continue while escalating decisions that need your attention within the boundaries you have set.

Burp’s existing manual tools remain available whenever you want to take over directly.

AGENT · MODE SELECTOR BURP AT Let me get the second page of the sitemap to complete the picture. used List Sitemap Show details Found 150 entries across ginandjuice.shop's sitemap. Spinning up four subagents to analyze each section… Show details Manual Follows your tool configuration — asking or acting on each tool as you've set it. Only uses enabled tools. Smart Acts independently — pausing to ask before anything it deems risky. Only uses enabled tools. Autonomous Acts independently. Only uses enabled tools. Ask anything Mode: Smart Feedback
// Boundaries enforced by Burp

You set the boundaries. Burp enforces them.

Scope, tool access and approval rules live in Burp’s tooling layer, architecturally separate from the model.

Agents can propose actions, but they cannot execute actions the tooling layer does not permit. Whatever level of autonomy you choose, the boundaries remain enforced by Burp rather than being left to instructions the model can reinterpret or ignore.

Requests and tool activity are recorded in the Burp project along with your own actions, so you can verify this as required.

Burp AT BURP AT Based on what we know so far, where should I prioritize testing first? Tool settings Esc ✕ Configure which tools ask for approval, and which act automatically. COLLABORATOR 3 Create Collaborator payloads Generates fresh payload URLs to embed in test traffic. Ask Act Poll for interactions Checks whether Collaborator payloads have triggered callbacks. Ask Act CONFIGURATION 3 Edit scan config Changes settings on an existing saved scan configuration. Ask Act ↺ Reset to Burp's default Done
Burp project context

Your Burp project is its working context.

Burp AT lets agents draw selectively on the site map, relevant traffic, issues, and prior discoveries in the Burp project without flooding the context window.

By consuming the project context already accumulated during the test, agents don’t need to rediscover the application or begin each task from a blank prompt. They can continually update the project as they work, adding to that shared understanding.

The project file itself also serves as a verifiable record of all actions taken during the test by both you and your agents. This is more than an agent connected to a collection of tools. It is agentic AI working within the same shared Burp context as the human-led test.

BURP PROJECT CONTEXT BURP AT Let me pull the current engagement state in parallel. used List Sitemap Show details used List Scan Issues Show details used List Proxy History Show details BURP AT I have the sitemap (150 entries), 0 issues reported, and no proxy history yet. Cross-referencing before I decide where to start — checkout looks like the highest-value gap to close first.
Public beta

What's included in the public beta.

Burp AT is live in public beta for Burp Suite Professional users.

  • Burp Suite's specialist web security tools.
  • Access to relevant Burp project context.
  • Purpose-built pentesting skills developed with PortSwigger Research.
  • Flexible approvals for actions that can proceed, require review, or are blocked.
  • Scope and tool-access policies enforced by Burp, not the model.
  • Agent requests and tool activity recorded in the Burp project.

This is the first phase of Burp AT. We will continue improving its tools, skills and workflows based on your feedback and real-world use.

See the documentation for current capabilities and guidance on using Burp AT.

Get started

Investigate more of the target. Keep control of the test.

Burp AT is live in public beta for Burp Suite Professional users.