Professional

Burp AT

  • Last updated: July 23, 2026

  • Read time: 2 Minutes

Burp AT brings agentic AI to human-led pentesting. With direct access to Burp Suite's trusted tooling and skills from PortSwigger's world-renowned research team, Burp AT pursues the testing goals you set, choosing the right actions for each step and adapting as it learns about your target.

Burp AT uses the same proven Burp tools you use yourself, rather than improvising its own. These tools are deterministic - they behave predictably every time - so Burp AT produces consistent, repeatable results you can trust.

Staying in control

You have control of Burp AT's autonomy at all times. Fine-grained, per-tool permissions let you decide what it can do on its own and what it must check with you first, from approving every action to running autonomously. You set the boundaries it works within: its testing scope, and the permissions for each tool. These are enforced by Burp's tooling rather than left to the AI's discretion, so Burp AT can't give itself permission you haven't granted.

As it works, Burp AT explains each step taken and the reasoning behind it in the conversation. The requests and responses it sends are captured in the Logger, so you can follow its work and verify its findings. The result is testing you can rely on: fast, consistent, and fully accountable to you.

PortSwigger takes the privacy and security of your data seriously. Burp AT runs on infrastructure built for security, privacy, and transparency. For information on what Burp AT sends and how your data is protected, see AI trust and data handling.

More information

Looking for Burp's assistive AI features, such as Explore Issue? See AI features (Burp AI).

When to use Burp AT

You can use Burp AT at any point in a project, taking on everything from broad goals to quick, focused tasks. You might use it to map an unfamiliar target, confirm a suspected vulnerability on a specific endpoint, reproduce a known issue to capture the evidence, or test an area for a particular class of vulnerability.

These are starting points, not a fixed list of use cases. If you can describe a testing task, it's worth trying. A task is a good fit when you can state the goal in a sentence or two, the target and scope are defined, and you can verify the result yourself.

Burp AT is built to extend your testing, not replace your judgment. Treat each finding as a lead to verify before you act on it.

Note

Burp AT uses AI credits, which are deducted from your balance as it works. For more information, see AI credits.