DAST

Issue management rules

  • Last updated: October 9, 2026

  • Read time: 3 Minutes

An issue management rule applies your decision about one issue to every matching issue on a site, so you make the decision once rather than after every scan.

A rule can set an issue's status to False positive or Accepted risk, or change its severity. It updates the matching issues that already exist and the matching issues that later scans find.

Creating an issue management rule

You create a rule when you change the status or severity of an issue and choose a wider scope than the issue itself.

To create a rule:

  1. Go to the All issues tab on the Home page, or the Issues tab on a site or folder.
  2. Select an issue to open it.
  3. Select False positive or Accepted risk from the Status drop-down, or select a severity from the Severity drop-down.
  4. Under Apply to, select This issue type at this URL or This issue type anywhere on this site.
  5. Click Change issue status or Change issue severity.

If you select This issue only, Burp Suite DAST changes the one issue and creates no rule. Rules are not available for the Verified risk and Fixed (unconfirmed) statuses.

What a rule applies to

A rule applies to one site and one issue type. Its scope sets how much of that site it covers:

  • This issue type at this URL - The rule applies to issues of the same type at the same origin and path. This includes issues with a different insertion point.
  • This issue type anywhere on this site - The rule applies to issues of the same type on any path of the site, including paths that the scanner finds in later scans.

URL matching is exact and case-sensitive. A rule does not affect other issue types or other sites. A URL rule also does not affect other URLs.

When you create a rule, Burp Suite DAST updates every matching issue on the site straight away. A rule does not change issues that the scanner has confirmed as fixed. The rule then applies to matching issues in each later scan, so you do not triage them again.

A site can have one status rule and one severity rule for each issue type and URL. If you create a second rule of the same kind for the same target, it replaces the first. A rule for an issue type anywhere on a site also replaces the URL rules for that issue type on the site. If a URL rule and a site-wide rule both match an issue, the URL rule applies.

Issues that a rule marks as False positive or Accepted risk get the same treatment as issues that you mark directly. For more information, see Setting an issue status.

When a rule sets a severity, later scans cannot override it.

The timeline of each issue that a rule changes shows Issue management rule as the author of the change. The note that you add when you create a rule stays on the issue that you changed. Burp Suite DAST does not copy it to the other issues that the rule updates.

Viewing and deleting rules

To review the rules on your instance, click the symbol in the top-right corner of the window, then click Issue management rules. For each rule, the page shows:

  • The site.
  • The issue type.
  • The matching URL. A rule for an issue type anywhere on a site shows Any URL.
  • The rule type: Mark as false positive, Mark as accepted risk, or Change severity to, followed by the severity that the rule sets.

Deleting a rule stops it applying to issues in later scans. Issues that the rule has already changed keep their status or severity, so change them yourself if you want to reverse the decision.

To delete a rule, click the delete button for that rule on the Issue management rules page.

Note

You need the Modify settings permission to view the Issue management rules page. You need the Edit issues permission on the site that a rule applies to before you can delete the rule. Burp Suite DAST records the creation, replacement, and deletion of rules in the user activity log.