Burp Suite, the leading toolkit for web application security testing

Burp Suite Documentation

Burp Suite is an integrated platform for performing security testing of web applications. It is designed to support the methodology of a hands-on tester, and gives you complete control over the actions that it performs, and deep analysis of the results. Burp contains several tools that work together to carry out virtually any task you will encounter in your testing. It can automate all kinds of tasks in customizable ways, and lets you combine manual and automated techniques to make your testing faster, more reliable and more fun.

Note: Like any security testing software, Burp Suite contains functionality that can damage target systems. Testing for security flaws inherently involves interacting with targets in non-standard ways that can cause problems in some vulnerable targets. You should take due care when using Burp, read all documentation before use, back up target systems before testing, and not use Burp against any systems for which you are not authorized by the system owner, or for which the risk of damage is not accepted by you and the system owner.

Use the links below for help about Burp Suite:

  • Getting started - Start here if you are new to Burp or want to cover the key basics.
  • Burp projects - This describes how to use Burp projects and configuration files to manage your work.
  • Using Burp Suite - This contains a detailed overview of Burp's user-driven testing workflow, and how the tools work together.
  • Burp tools - This contains detailed documentation about each of Burp's individual tools.
  • Suite functions - This describes all of the shared Suite-wide functions that support the testing process.
  • Options - This describes the Suite-wide options that affect the behavior of all tools.
  • Extensibility - This explains Burp's extensibility framework, and how you can extend Burp's functionality with your own code.
  • Troubleshooting - This contains tips for dealing with some common problems.
  • Full documentation contents - A structured site map of all the documentation.

Support Center

Get help and join the community discussions at the Burp Suite Support Center.

Visit the Support Center ›

Monday, January 16, 2017


This release adds various enhancements and fixes:

  • There is a new command-line option to launch Burp with a specified user configuration file.
  • A bug that was recently introduced that prevented license activation in headless mode has been fixed.
  • The Content Discovery function now correctly handles applications that have wildcard behavior for file extensions (e.g. those that return a specific response for admin.xxx regardless of the file extension). This eliminates the only known false positives reported by the new Content Discovery engine.

See all release notes ›

Copyright © 2016 PortSwigger Ltd. All rights reserved.