Mastering Burp Suite @mastering-burp.agarri.fr · 27/05/2026Not sure it would fit you? Check the latest feedback I received 100
Mastering Burp Suite @mastering-burp.agarri.fr · 28/04/2026Great news: Burp's notes now support Markdown 🥳 🎉 It works in the usual notes (as the exchange level) but also in the About tab of collections (except for the default one named "Inbox") 121
Mastering Burp Suite @mastering-burp.agarri.fr · 14/11/2025Burp now has a command palette (similar to the one in VS Code) 🥳 portswigger.net/cms/images/4... 132
Mastering Burp Suite @mastering-burp.agarri.fr · 10/09/2025You never know when an obscure piece of trivia about Java regular expressions may be useful IRL 🤓 Today, I used the embedded flag "(?-s)" to disable the DOTALL mode and be able to work one a single line 🔬 The goal was to append a string to the User-Agent header, and it now works perfectly 🎉 151
Mastering Burp Suite @mastering-burp.agarri.fr · 05/06/2025The Scalpel extension is magic 🪄 Especially if you're a big fan of executing both python3 and vim within Burp Suite 🛠️ blog.lexfo.fr/scalpel.html 174
Mastering Burp Suite @mastering-burp.agarri.fr · 08/04/2025I strongly recommend to use "Audit speed = Thorough" when scanning. Here's one of the reasons... 022
Mastering Burp Suite @mastering-burp.agarri.fr · 02/04/2025TIL the default value for "Failed domain name resolution" is set to 60 seconds. Useful to know when reaching your target web app temporarily fails 010
Mastering Burp Suite @mastering-burp.agarri.fr · 19/02/2025Somebody asked me which version of Python was available in Hackvertor. So I created a custom tag displaying this piece on information And the answer is... Jython 2.7.3b1 🐍☕ PS: look at the alt-text if you're looking for the code 020
Mastering Burp Suite @mastering-burp.agarri.fr · 19/02/2025I like bambdas but Java is sooooo verbose 😐 120
Mastering Burp Suite @mastering-burp.agarri.fr · 17/02/2025When spending hours in front of a screen, using alternative fonts may be a very good idea 🔍 My preferred one is JetBrains Mono, but of course YMMV (go to "User options > Display > HTTP Message Display" to change your settings) ⚙️ PS: I use the same font in VS Code 🧠 081
Mastering Burp Suite @mastering-burp.agarri.fr · 05/01/2025Hackvertor now supports tags `<@space/>` and `<@newline/>` That doesn't look like a game-changer, but it's incredibly useful when you want to avoid that these raw characters break Burp's HTTP parsing 0126
Mastering Burp Suite @mastering-burp.agarri.fr · 20/12/2024Ever wondered why you NEVER see chunked responses in Burp? 🤔 The answer is simple, default settings hide them! 🫣 Go to "Settings > Network > HTTP > Streaming responses" to make them appear 🔍 0206
Mastering Burp Suite @mastering-burp.agarri.fr · 28/11/2024We can now configure what version of messages should be displayed in Proxy History 🥳 1181
Mastering Burp Suite @mastering-burp.agarri.fr · 15/11/2024It's really easy to make Repeater tabs take a single line: simply enable the "Scrolling view" mode from the ellipsis menu 0102
Mastering Burp Suite @mastering-burp.agarri.fr · 04/11/2024Reading the documentation is a super power 🦸 061
Mastering Burp Suite @mastering-burp.agarri.fr · 18/09/2024Piper, the gift that keeps on giving!🔥 042
Mastering Burp Suite @mastering-burp.agarri.fr · 05/09/2024The new "Match & Replace" editor (available in EA 2024.8) looks pretty good 🤩 000
Mastering Burp Suite @mastering-burp.agarri.fr · 03/05/2024Portswigger released a BCheck plugin for IntelliJ 🛠️ 010
Mastering Burp Suite @mastering-burp.agarri.fr · 12/04/2024The kind of small improvements I really appreciate... 011
Mastering Burp Suite @mastering-burp.agarri.fr · 10/04/2024Since EA 2024.3.1, it's possible to add custom columns to all the tables visible in Burp Suite In the following screenshot, I simply extract the value of the "Server" header 010
Mastering Burp Suite @mastering-burp.agarri.fr · 10/04/2024Combining Piper and LinkFinder (thanks Antoine Roly for the screenshot) 010
Mastering Burp Suite @mastering-burp.agarri.fr · 04/03/2024Since EA 2024.2.1, it's possible to sort tables using 3 distinct criteria 🤩 Here, the data is sorted by Mime Type then Status code then Length (you need to click on the columns in the opposite order) 📊 000
Mastering Burp Suite @mastering-burp.agarri.fr · 07/02/2024In case you want to modify the layout of the menu listing extensions' actions, the extension "Menu level" does exactly that... 🛠️ There's 4 possible layouts, and the attached screenshot shows the third one 100
Mastering Burp Suite @mastering-burp.agarri.fr · 01/02/2024I was recently told that the Hackvertor extension by @garethheyes.co.uk can display the most commonly used tags in a separate menu 🤯 That's sooooo useful!! Note: this isn't enabled by default, you've to enable the option "Allow Hackvertor to count tag usage" 011
Mastering Burp Suite @mastering-burp.agarri.fr · 23/11/2023Another example of #Bambda , by @burpsuite.bsky.social 🛠️ 030
Mastering Burp Suite @mastering-burp.agarri.fr · 14/11/2023Working on an internal pentest where *only* external requests must go through the corporate proxy? 🤔 In "Upstream proxy servers", exclude the internal hosts by defining them with an empty "Proxy host" field 😈 Note: rules are processed from top to bottom, as usual 030
Mastering Burp Suite @mastering-burp.agarri.fr · 13/11/2023Second option: use the global search, limit it to "Target" and "Request headers", then search for ".js HTTP/" Now, select all results (with Control-A), right-click and execute "Copy selected URLs" 000
Mastering Burp Suite @mastering-burp.agarri.fr · 09/11/2023FYI a new BCheck grammar is available in Burp Suite Pro Stable 2023.3.4 010
Mastering Burp Suite @mastering-burp.agarri.fr · 24/10/2023For the Halloween season, you may want to use the Sharpener extension to dress up your Burp... 🧛♂️🎃 000
Mastering Burp Suite @mastering-burp.agarri.fr · 18/10/2023In order to look for specific strings in **responses** stored in the Proxy History, use the global search located in "Engagement tools" (Pro version only) 🛠️ 021
Mastering Burp Suite @mastering-burp.agarri.fr · 05/10/2023If you do have APIs in scope, maybe take 5 minutes to answer this @portswigger.bsky.social survey... 010
Mastering Burp Suite @mastering-burp.agarri.fr · 10/09/2023When spending hours in front of a screen, using alternative fonts may be a very good idea. My preferred one for Burp Suite is JetBrains Mono, but of course YMMV. (Go to "User interface > Inspector and message editor > HTTP message display" to change your settings) 000
Mastering Burp Suite @mastering-burp.agarri.fr · 08/09/2023Since EA 2023.10, an easy way to fingerprint Burp disappeared 😈 Thanks @burpsuite.bsky.social for supporting Brotli! 000
Mastering Burp Suite @mastering-burp.agarri.fr · 07/09/2023Here's @burpsuite.bsky.social + jsluice, using the Piper extension 🛠️ Thanks Antoine for the screenshot! 000
Mastering Burp Suite @mastering-burp.agarri.fr · 05/09/2023Periodical reminder: it's possible to navigate sub-tabs (like Repeater entries) from the keyboard. You simply have to configure the actions "Go to previous tab" and "Go to next tab". 000
Mastering Burp Suite @mastering-burp.agarri.fr · 30/08/2023As Burp Suite is developed in Java, regexes may use embedded flag expressions like "(?m)" 🤯 Here's a detailled description of all the possibilities (including embedded flags, character classes, quantifiers, groups, ...) 030