Discovery
Gather intelligence, comprehensive application
mapping and identify initial weaknesses.
Attack
Explore clues to identify vulnerabilities,
validate and analyse findings, generate a proof of
concept.
Reporting
Evidence vulnerabilities, provide concise
reporting and advise on remediation.
"I love Burp Scanner - it's probably my number one feature. I can remove a lot of the pain - it means I can focus on manual testing.”
Application Security Pentester, AppSec team
“You can't really conduct a web app pentest as a whole without Burp Suite Professional. It would take too much time and be super tedious. For me, Burp is invaluable."
Johan Persson, QueenSec
“It's extremely useful to be able to generate a fully-functioning proof-of-concept in two clicks. If this feature didn't exist, then it would take me a long time to write one myself.”
Lucas Renc, Vendavo
PortSwigger Research
Stay ahead of the latest hacking techniques with
our world-leading research.
Web Security Academy
Hone your craft in our Web Security Academy.
PortSwigger Discord
A space dedicated to interacting with other Burp
users and AppSec professionals.