Burp AT brings agentic AI to human-led pentesting, with Burp’s proven tools, project context, and purpose-built skills.
Live in public beta for Burp Suite Professional users.
Frontier AI models can find and exploit vulnerabilities. Agents can form a hypothesis, act through tools, interpret what they learn, and decide what to try next.
But a professional pentest requires more than capable reasoning. It requires reliable specialist tools, access to relevant context, purpose-built methodology and boundaries the model cannot bypass.
Burp AT was built for that challenge.
Web pentesters and bug bounty hunters alike are already experimenting with general-purpose coding agents to automate and enhance parts of their workflow. But leveraging this capability professionally can mean assembling tools, developing prompts and workflows, managing context and trusting a model to enforce its own restrictions. That’s not to mention the ongoing maintenance effort, meaning you spend more time on software engineering than hacking.
Burp AT gives you a ready-to-use, specialist alternative. Agents work with Burp Suite’s tools and project context, use purpose-built pentesting skills, and operate reliably within the scope and permission boundaries you define and Burp enforces.
Burp AT is natively integrated with Burp Suite. It equips agents with the same specialist, battle-hardened web security tooling trusted by professional pentesters for over 20 years.
The model works out the strategy, but uses Burp Suite’s tools to act. This enables them to work with protocol edge cases, malformed traffic and unusual application behaviour that can derail workflows built on improvised scripts and general-purpose libraries.
Burp AT draws on a library of pentesting skills developed with PortSwigger’s world-renowned research team. This means agents can follow structured, task-specific methodology rather than inventing a pentesting workflow from general model knowledge.
As PortSwigger Research develops and refines testing techniques, those approaches can be translated into reusable skills for agents to apply during real tests. This creates a direct path from research breakthrough to repeatable testing without every user having to interpret and operationalise the research independently. As the skills library grows, so does the range and depth of work Burp AT can take on.
Highly granular control over permissions means you can flexibly adapt the level of autonomy. Begin with tighter approvals, then gradually give Burp AT more autonomy as it earns your trust. Alternatively, you can adapt the autonomy to suit the engagement.
Smart approvals can reduce approval fatigue, allowing routine actions to continue while escalating decisions that need your attention within the boundaries you have set.
Burp’s existing manual tools remain available whenever you want to take over directly.
Scope, tool access and approval rules live in Burp’s tooling layer, architecturally separate from the model.
Agents can propose actions, but they cannot execute actions the tooling layer does not permit. Whatever level of autonomy you choose, the boundaries remain enforced by Burp rather than being left to instructions the model can reinterpret or ignore.
Requests and tool activity are recorded in the Burp project along with your own actions, so you can verify this as required.
Burp AT lets agents draw selectively on the site map, relevant traffic, issues, and prior discoveries in the Burp project without flooding the context window.
By consuming the project context already accumulated during the test, agents don’t need to rediscover the application or begin each task from a blank prompt. They can continually update the project as they work, adding to that shared understanding.
The project file itself also serves as a verifiable record of all actions taken during the test by both you and your agents. This is more than an agent connected to a collection of tools. It is agentic AI working within the same shared Burp context as the human-led test.
Burp AT is live in public beta for Burp Suite Professional users.
This is the first phase of Burp AT. We will continue improving its tools, skills and workflows based on your feedback and real-world use.
See the documentation for current capabilities and guidance on using Burp AT.
Why capable AI needs controls outside the model, and how human judgment will shape the future of pentesting.
Read the post → // Risky BusinessDafydd Stuttard discusses what AI changes in web security testing, and why boundaries must be enforced outside the model.
Listen to the episode → // Black Hat USA 2026James Kettle presents PortSwigger Research’s work on agentic security research at Black Hat USA 2026.
Read the abstract →Burp AT is live in public beta for Burp Suite Professional users.