New feature
A brand new tool to help you organize your testing workflow, and keep track of pending actions.
New feature
Include an API definition as part of the Burp Scanner launch process. Burp Scanner will use this API definition to seed its scan - enhancing its ability to scan APIs and microservices.
New feature
Alter and customize the layout of your Burp workspace. Tailor Burp Suite's top level tools to the particularities of your workflow.
Feature enhancement
Generate and include Burp Collaborator payloads as part of a Burp Intruder attack. Any interactions detected by Burp Collaborator will then be included in the results for your Burp Intruder attack.
New feature
Add scan checks to Burp Scanner using a simplified language we've created specifically for this purpose. This will enable you to create custom scan checks more easily (without writing a BApp extension).
New feature
Burp Suite Professional and Burp Suite Community Edition will support machines running Linux on an ARM64-based processor.
Feature enhancement
We will continue to develop Burp's new Montoya API, adding improved support for WebSockets, as well as functionality around project files - enabling extensions to save data.
Feature enhancement
Improved visualization of scan activity. Better understand the coverage that your scan configuration has achieved, and how any discovered issues fit into the target's nav structure.
New feature
Burp Scanner will check for a number of security vulnerabilities relating to APIs that use the GraphQL language.
New feature
Burp Scanner will check for a number of security vulnerabilities relating to access control.
Feature enhancement
Scan single page applications (SPAs) built using React more easily. Specifically, this will improve Burp Scanner's handling of input elements that do not have an enclosing form tag.
Feature enhancement
Fine-tuning of Burp Scanner, to optimize its performance when scanning single page applications (SPAs) built using Angular, Vue.js, and other frameworks.
Done
Collaborator client now has its own top-level tab, uses a tabbed interface, and saves its interactions in project files, among other improvements.
Done
Burp Scanner now checks for a number of security vulnerabilities relating to JSON Web Tokens (JWT).
Done
Burp's Montoya API is a completely new extensibility framework, which will lead to much richer capabilities in the future.
Done
Burp Scanner now automatically audits in-scope API requests that are issued from client-side JavaScript using XHR and Fetch.
Done
More options for brute forcing and fuzzing. New payload types and placement options, richer results analysis, and incremental saving.
Done
Add-ons to Burp Suite Professional's embedded browser have enhanced manual testing for DOM-based vulnerabilities.
Done
Perform software composition analysis (SCA) of client-visible code. Report JavaScript libraries in use that contain known vulnerabilities.
Done
Enumerate API endpoints to scan APIs in target applications. API scanning utilizes OpenAPI (Swagger) definitions.
Done
Update without lifting a finger. Burp Suite Professional can now update itself automatically - without user intervention.
Done
Find cutting-edge vulnerabilities with Burp Scanner. Scan checks based on James Kettle's latest web cache poisoning research.
Done
Best-in-class coverage and scanning performance for challenging targets like AJAX-heavy single page app, with browser-driven (Chromium) scanning. Enabled by default.
Read all release notesDone
We have fundamentally changed the way that Burp Scanner navigates using its built-in browser. This improves scanning of applications that make heavy use of client-side JavaScript for navigation, and lays a strong foundation for further development of the scanner.
Done
User and project options are now accessed via a single Settings dialog. We have also added a search function.
Done
Improved memory and processing efficiency for various Burp features. Users also now get feedback on any resource-hungry BApps.
Done
Various improvements to the usability of the HTTP message inspector, based on user feedback.
Done
Burp Scanner can now report new classes of HTTP/2-specific vulnerabilities.
Done
Burp Scanner can now detect injection into a wider range of templating engines, and will employ OAST techniques to detect blind SSTI.
Done
Burp Scanner now handles navigational actions that cause DOM updates without a synchronous request to the server, allowing better handling of single-page applications.
Based on the user popularity of certain BApps (Logger++ and Flow), Burp Suite Professional has gained native, resource-efficient logging functionality.
Done
Use HTTP/2 for both inbound and outbound communication over TLS (beta feature). Also gives control of TLS protocols within Burp Proxy.
Done
Manipulate browser traffic more easily. Improved access to headers, parameters, and more - plus automatic encoding and decoding.
Done
See exactly what you're looking at - without changing tab. Tools like Burp Repeater and Burp Intruder now allow you to render responses.
Done
Further optimized performance in default settings - to enable faster scans without compromising coverage.
Done
Addition of support for popup page elements when using Burp Scanner's recorded login (authenticated scanning) feature.
Done
A number of changes to Burp Suite Professional's UI, based on user feedback - including grouped tabs, and four new preset modes for Burp Scanner.
Done
The HTTP message inspector has gained new capabilities, enabling manual exploitation of HTTP/2-specific vulnerabilities using Burp Repeater. The Burp Extender API has also been enhanced to enable HTTP/2-specific attacks.
Done
We have improved the placement and encoding of scan payloads within JSON and XML data structures.
Done
Burp Scanner now detects and interacts with more DOM elements that can cause JavaScript-triggered navigation, in addition to conventional links and forms.
Done
All Burp Suite Professional users now gain access to an optional early adopters' release track - giving early access to new and experimental features.
Done
Better scrutinize login-related functionality by recording complex login sequences in a browser. Ideal for JavaScript-heavy logins, or single sign-on.
Done
Proxy HTTPS traffic with no configuration necessary. Burp Suite's embedded Chromium browser can now take care of everything.
Done
Significant improvements to Burp Scanner - enabling enhanced performance and coverage of modern navigational patterns.
Done
Make code easier to work with. Burp Suite will prettify JSON, XML, HTML, CSS, and JavaScript within the HTTP message editor.
See more customer stories![]()
The tool is self sufficient, with many features out of the box and allows for extensibility. No need for servers or databases. It's a well calibrated "gun". It lets us either validate findings from external security reports or penetration test our software while in development. Source: TechValidate survey of PortSwigger customers
Software Engineer
Large Enterprise Financial Services Company