Sign in

Mastering Burp Suite

@mastering-burp.agarri.fr
993 followers 1 following 181 posts

Tips and tricks for Burp Suite Pro 🛠️ Not affiliated with @portswigger.net ©️ Managed by @agarri.fr 🇫🇷 Additional free resources 🎁 hackademy.agarri.fr/freebies

PostsRepliesMedia
Mastering Burp Suite @mastering-burp.agarri.fr · 27/05/2026
Not sure it would fit you? Check the latest feedback I received
Screenshot from X: "I dont post that much, but I do when I feel like its worth it - I have to say having taken the Burp suite Pro training by @Agarri_FR I was totally blown away. I have used burp for over 20 years and have learnt so much that will immediately help me, totally recommend the course!"
100
Mastering Burp Suite @mastering-burp.agarri.fr · 28/04/2026
Great news: Burp's notes now support Markdown 🥳 🎉 It works in the usual notes (as the exchange level) but also in the About tab of collections (except for the default one named "Inbox")
Screenshot of a note using a few Markdown features (bold, headings, links...)
121
Mastering Burp Suite @mastering-burp.agarri.fr · 14/11/2025
Burp now has a command palette (similar to the one in VS Code) 🥳 portswigger.net/cms/images/4...
Burp’s command palette
132
Mastering Burp Suite @mastering-burp.agarri.fr · 10/09/2025
You never know when an obscure piece of trivia about Java regular expressions may be useful IRL 🤓 Today, I used the embedded flag "(?-s)" to disable the DOTALL mode and be able to work one a single line 🔬 The goal was to append a string to the User-Agent header, and it now works perfectly 🎉
A Burp Suite session handling rule with the "Match and replace" action. The regexp requires the embedded flag "(?-s)" in order to only impact the "User-Agent" header
151
Mastering Burp Suite @mastering-burp.agarri.fr · 05/06/2025
The Scalpel extension is magic 🪄 Especially if you're a big fan of executing both python3 and vim within Burp Suite 🛠️ blog.lexfo.fr/scalpel.html
Screenshot of the Scalpel script editor using the local `vim` binary
174
Mastering Burp Suite @mastering-burp.agarri.fr · 02/06/2025
A meme based on the "Change my mind" template (not the Steven Crowder's one, but one from the Calvin & Hobbes comics)

The text says "Chaining two instances of Burp Suite is such an underrated technique"
311
Mastering Burp Suite @mastering-burp.agarri.fr · 08/04/2025
I strongly recommend to use "Audit speed = Thorough" when scanning. Here's one of the reasons...
The event "Skipping brute force of JWT token as maximum time exceeded" appears in Burp Suite event logger.

Cuase: WT tokens use a signature to validate their contents. In some cases, Burp Scanner will attempt to brute-force this signature in order to compromise the token. This error has been caused by Burp Scanner running out of time during the brute-forcing process.

Remedy: To increase the amount of time that Burp Scanner spends brute-forcing JWT token signatures, from the Audit Optimization menu, set Audit speed to Thorough.
022
Mastering Burp Suite @mastering-burp.agarri.fr · 02/04/2025
TIL the default value for "Failed domain name resolution" is set to 60 seconds. Useful to know when reaching your target web app temporarily fails
Screenshot of the "Network > Connections" section of Burp Suite seetings. The default value for "Failed domain name resolution" is set to 60 seconds
010
Mastering Burp Suite @mastering-burp.agarri.fr · 24/03/2025
A meme picture displaying the members of a gang. The caption says :
Fuck Turbo Intruder
All my homies use
Send group (parallel)
0103
Mastering Burp Suite @mastering-burp.agarri.fr · 19/02/2025
Somebody asked me which version of Python was available in Hackvertor. So I created a custom tag displaying this piece on information And the answer is... Jython 2.7.3b1 🐍☕ PS: look at the alt-text if you're looking for the code
The following Python code is executed inside Hackvertor:

import sys
output = '\n\n'.join(['', sys.version, sys.executable, str(sys.version_info)])
020
Mastering Burp Suite @mastering-burp.agarri.fr · 19/02/2025
I like bambdas but Java is sooooo verbose 😐
A meme where a personn says No to "Writing clean Java code" but Yes to "Not checking for NULL in Bambdas"
120
Mastering Burp Suite @mastering-burp.agarri.fr · 17/02/2025
When spending hours in front of a screen, using alternative fonts may be a very good idea 🔍 My preferred one is JetBrains Mono, but of course YMMV (go to "User options > Display > HTTP Message Display" to change your settings) ⚙️ PS: I use the same font in VS Code 🧠
The samed message editor in Burp Suite, configured with four different fonts: JetBrains Mono, Source Code Pro, Linux Biolinum Keyboard and LM Slanted Mono
081
Mastering Burp Suite @mastering-burp.agarri.fr · 05/01/2025
Hackvertor now supports tags `<@space/>` and `<@newline/>` That doesn't look like a game-changer, but it's incredibly useful when you want to avoid that these raw characters break Burp's HTTP parsing
A XML document where raw space characters are replaced with Hackvertor's `<@space/>` tags
0126
Mastering Burp Suite @mastering-burp.agarri.fr · 20/12/2024
Ever wondered why you NEVER see chunked responses in Burp? 🤔 The answer is simple, default settings hide them! 🫣 Go to "Settings > Network > HTTP > Streaming responses" to make them appear 🔍
Screenshot of Burp's HTTP settings, where streaming URLs must be definedChunked response as seen in Repeater, with chunk metadata (their size) not stripped
0206
Mastering Burp Suite @mastering-burp.agarri.fr · 28/11/2024
We can now configure what version of messages should be displayed in Proxy History 🥳
The configuration options in "Settings > Tools > Proxy Default Proxy history message display". We can act separately on Websocket messages, HTTP requests and HTTP responses
1181
Mastering Burp Suite @mastering-burp.agarri.fr · 15/11/2024
It's really easy to make Repeater tabs take a single line: simply enable the "Scrolling view" mode from the ellipsis menu
This screenshot shows how to use the ellipsis menu in Burp Suite's Repeater in order to switch the tab mode to "Scrolling view"
0102
Mastering Burp Suite @mastering-burp.agarri.fr · 04/11/2024
Reading the documentation is a super power 🦸
061
Mastering Burp Suite @mastering-burp.agarri.fr · 18/09/2024
Piper, the gift that keeps on giving!🔥
The response contains a PDF file and it's hard to make sense of its contentUsing the Piper extension, textual content is extracted from the PDF and displayed in a separate viewer
042
Mastering Burp Suite @mastering-burp.agarri.fr · 05/09/2024
The new "Match & Replace" editor (available in EA 2024.8) looks pretty good 🤩
Screenshot of the new "Match & Replace" editor, which allows the rule to be tested against a specific request (or response)
000
Mastering Burp Suite @mastering-burp.agarri.fr · 09/06/2024
172
Mastering Burp Suite @mastering-burp.agarri.fr · 27/05/2024
Great or awful? 🤔
Burp Suite interface, but using the Comic Sans font
000
Mastering Burp Suite @mastering-burp.agarri.fr · 03/05/2024
Portswigger released a BCheck plugin for IntelliJ 🛠️
010
Mastering Burp Suite @mastering-burp.agarri.fr · 12/04/2024
The kind of small improvements I really appreciate...
The title of the Collaborator tab now displays how many unread interactions exist
011
Mastering Burp Suite @mastering-burp.agarri.fr · 10/04/2024
Since EA 2024.3.1, it's possible to add custom columns to all the tables visible in Burp Suite In the following screenshot, I simply extract the value of the "Server" header
010
Mastering Burp Suite @mastering-burp.agarri.fr · 10/04/2024
Combining Piper and LinkFinder (thanks Antoine Roly for the screenshot)
010
Mastering Burp Suite @mastering-burp.agarri.fr · 04/03/2024
Since EA 2024.2.1, it's possible to sort tables using 3 distinct criteria 🤩 Here, the data is sorted by Mime Type then Status code then Length (you need to click on the columns in the opposite order) 📊
000
Mastering Burp Suite @mastering-burp.agarri.fr · 07/02/2024
In case you want to modify the layout of the menu listing extensions' actions, the extension "Menu level" does exactly that... 🛠️ There's 4 possible layouts, and the attached screenshot shows the third one
Using layout 3 in Burp's extension "Menu level"
100
Mastering Burp Suite @mastering-burp.agarri.fr · 01/02/2024
I was recently told that the Hackvertor extension by @garethheyes.co.uk can display the most commonly used tags in a separate menu 🤯 That's sooooo useful!! Note: this isn't enabled by default, you've to enable the option "Allow Hackvertor to count tag usage"
Screenshot showing the "Popular tags" menu of Hackvertor
011
Mastering Burp Suite @mastering-burp.agarri.fr · 30/01/2024
Nice finding! 🎯
010
Mastering Burp Suite @mastering-burp.agarri.fr · 23/11/2023
Another example of #Bambda , by @burpsuite.bsky.social 🛠️
030
Mastering Burp Suite @mastering-burp.agarri.fr · 14/11/2023
Working on an internal pentest where *only* external requests must go through the corporate proxy? 🤔 In "Upstream proxy servers", exclude the internal hosts by defining them with an empty "Proxy host" field 😈 Note: rules are processed from top to bottom, as usual
The "Upstream proxy server" configuration screen
030
Mastering Burp Suite @mastering-burp.agarri.fr · 13/11/2023
Second option: use the global search, limit it to "Target" and "Request headers", then search for ".js HTTP/" Now, select all results (with Control-A), right-click and execute "Copy selected URLs"
Using the global search feature in order to identify Javascript files
000
Mastering Burp Suite @mastering-burp.agarri.fr · 09/11/2023
FYI a new BCheck grammar is available in Burp Suite Pro Stable 2023.3.4
Changelog of version 2023.3.4 describing the new BCheck grammar
010
Mastering Burp Suite @mastering-burp.agarri.fr · 24/10/2023
For the Halloween season, you may want to use the Sharpener extension to dress up your Burp... 🧛‍♂️🎃
000
Mastering Burp Suite @mastering-burp.agarri.fr · 18/10/2023
In order to look for specific strings in **responses** stored in the Proxy History, use the global search located in "Engagement tools" (Pro version only) 🛠️
The global search interface, where the filter is set to search only into responses stored in the Proxy History
021
Mastering Burp Suite @mastering-burp.agarri.fr · 05/10/2023
If you do have APIs in scope, maybe take 5 minutes to answer this @portswigger.bsky.social survey...
010
Mastering Burp Suite @mastering-burp.agarri.fr · 10/09/2023
When spending hours in front of a screen, using alternative fonts may be a very good idea. My preferred one for Burp Suite is JetBrains Mono, but of course YMMV. (Go to "User interface > Inspector and message editor > HTTP message display" to change your settings)
Testing four different fonts
000
Mastering Burp Suite @mastering-burp.agarri.fr · 08/09/2023
Since EA 2023.10, an easy way to fingerprint Burp disappeared 😈 Thanks @burpsuite.bsky.social for supporting Brotli!
Changelog for version EA 2023.10
000
Mastering Burp Suite @mastering-burp.agarri.fr · 07/09/2023
Here's @burpsuite.bsky.social + jsluice, using the Piper extension 🛠️ Thanks Antoine for the screenshot!
000
Mastering Burp Suite @mastering-burp.agarri.fr · 05/09/2023
Yes, I'm proud of myself...
010
Mastering Burp Suite @mastering-burp.agarri.fr · 05/09/2023
Periodical reminder: it's possible to navigate sub-tabs (like Repeater entries) from the keyboard. You simply have to configure the actions "Go to previous tab" and "Go to next tab".
000
Mastering Burp Suite @mastering-burp.agarri.fr · 30/08/2023
As Burp Suite is developed in Java, regexes may use embedded flag expressions like "(?m)" 🤯 Here's a detailled description of all the possibilities (including embedded flags, character classes, quantifiers, groups, ...)
Searching Burp Proxy History using the regex "(?m)User-Agent: burl", which includes an embedded flag
030