All releases

Professional / Community 2026.7.1

SHA256: {SHA FROM OPTION GOES HERE} MD5: {MD5 FROM OPTION GOES HERE}

This release introduces Burp AT, an agentic AI-driven capability for Burp Suite Professional that pursues the testing goals you set using Burp's own tools.

Introducing Burp AT

Burp AT enables you to embrace agentic AI without giving up control over your work. With direct access to Burp Suite's trusted tooling and skills from PortSwigger's world-renowned research team, it pursues the testing goals you set, choosing the right actions for each step and adapting as it learns about your target.

Burp AT uses Burp's proven tooling rather than improvising its own. These tools are deterministic - they behave predictably every time - so it produces consistent, repeatable results, and saves the time and tokens it would otherwise spend figuring out how to test.

To access it, click Burp AT in the top-right corner of Burp.

Signing in

The first time you open Burp AT, you're prompted to sign in to your PortSwigger account. Signing in verifies your account and helps us to securely route your requests to PortSwigger's AI service.

Make sure you sign in with the PortSwigger account that your Burp Suite Professional license is registered to.

Working in tasks

When using Burp AT, your work is organized into tasks. A task is a conversation focused on one area of testing, which can split into parallel sub-tasks if needed. You can run more than one task at a time, send follow-up prompts to dig into a result or point it at something new, and stop a task at any point. As it works, its activity appears in the Burp tools you already use: traffic in the Logger, scans on the Dashboard, and confirmed vulnerabilities in the Issues panel and site map.

You can also give Burp AT more to work from by attaching context from Burp, such as a Proxy history item, a site map node, or an issue.

Controlling autonomy

You have control of Burp AT's autonomy level at all times, from checking with you before every action to running autonomously. Each task runs in one of three autonomy modes that determine how much it can do without asking you first:

  • Manual mode uses permissions you set for each tool.
  • Smart mode approves routine tool use on its own, and stops to ask you about anything it judges to be potentially risky.
  • Autonomous mode runs without asking for approval, apart from a few high-impact tools that always require it.

Skills from PortSwigger Research

Burp AT can draw on skills, which are focused testing techniques written by PortSwigger's Research team that extend what it knows how to do. It invokes skills automatically when it decides they're relevant to the situation. Skills are published and updated automatically, so you don't need to update Burp to take advantage of new techniques. Skills are enabled by default, but you can disable them if you need to.

Reviewing findings

Vulnerabilities that Burp AT finds are recorded as issues in Burp, and work the same way as those raised during your manual testing. Each issue includes the requests and responses used to find it, so you can reproduce it, confirm it's exploitable, and report it with confidence.

AI credits

Burp AT uses AI credits, which are deducted from your account balance as it works. For information on how AI credits work, see AI credits.

If you're on a Burp AI subscription, your usage of Burp AT is covered by your subscription's fair usage allowance.

More information

For more information on using Burp AT, see our documentation.

Share your feedback

We'd really value your feedback on Burp AT. To share your thoughts on what's working, what isn't, and what you'd want to see next, click the Feedback link in the Burp AT message box.

Burp's Chromium browser is now Burp Browser

Burp's embedded browser previously presented as "Chromium" on your system. It's now branded as Burp Browser, to make it more identifiable. If you've previously added the browser to an allow list, for example in your endpoint security, antivirus, or firewall configuration, you may need to update the entry to reflect the new name.