Sign in

Mastering Burp Suite

@mastering-burp.agarri.fr
992 followers 1 following 181 posts

Tips and tricks for Burp Suite Pro 🛠️ Not affiliated with @portswigger.net ©️ Managed by @agarri.fr 🇫🇷 Additional free resources 🎁 hackademy.agarri.fr/freebies

PostsRepliesMedia
Mastering Burp Suite @mastering-burp.agarri.fr · 27/05/2026
Early-bird pricing ends soon, hurry up if you want to take advantage of it romhack.io/training/202...
romhack.io
Burp Suite Pro, 100% hands-on - RomHack Security Conference
000
Mastering Burp Suite @mastering-burp.agarri.fr · 27/05/2026
Not sure it would fit you? Check the latest feedback I received
Screenshot from X: "I dont post that much, but I do when I feel like its worth it - I have to say having taken the Burp suite Pro training by @Agarri_FR I was totally blown away. I have used burp for over 20 years and have learnt so much that will immediately help me, totally recommend the course!"
100
Mastering Burp Suite @mastering-burp.agarri.fr · 27/05/2026
As you may know, I've been giving Burp Suite Pro trainings for the last 10 years And this year, I'll give a single public on-site Burp Suite Pro training session, and it will be in RomHack 🇮🇹 (registration link in replies)
101
Mastering Burp Suite @mastering-burp.agarri.fr · 20/05/2026
For each in-scope item of the sitemap, it will take its URL and write it to `/tmp/log` No idea why there's duplicate entries in the log file though 🤷‍♂️
000
Mastering Burp Suite @mastering-burp.agarri.fr · 20/05/2026
HttpRequest r = node.requestResponse().request(); if (r.isInScope()) { FileOutputStream f = new FileOutputStream("/tmp/log", true); f.write((r.url() + "\r\n").getBytes()); f.close(); return true; } return false;
110
Mastering Burp Suite @mastering-burp.agarri.fr · 20/05/2026
Somebody asked me how to extract URLs from the Site Map without using the clipboard. So I wrote the following bambda ⤵️
100
Mastering Burp Suite @mastering-burp.agarri.fr · 05/05/2026
In case you want to nominate an extension (or several) for the 2026 Burp Suite Extension Awards... docs.google.com/forms/d/e/1F...
docs.google.com
2026 Burp Suite Extension Awards
Nominate a Burp Suite extension you love Which Burp Suite extension has made your work easier, faster, or just a bit more enjoyable? Nominate it for the 2026 Burp Suite Extension Awards and tell us w...
030
Reposted by Mastering Burp Suite
Mastering Burp Suite @mastering-burp.agarri.fr · 28/04/2026
Great news: Burp's notes now support Markdown 🥳 🎉 It works in the usual notes (as the exchange level) but also in the About tab of collections (except for the default one named "Inbox")
Screenshot of a note using a few Markdown features (bold, headings, links...)
121
Mastering Burp Suite @mastering-burp.agarri.fr · 28/04/2026
Only in EA 2026.4 for now 👀 portswigger.net/burp/release...
portswigger.net
Professional / Community 2026.4
This release introduces a combined installer for Burp Suite Professional and Community Edition, greater extension control over HTTP traffic, Markdown support in Notes, and collection-level notes in Or
000
Mastering Burp Suite @mastering-burp.agarri.fr · 28/04/2026
Great news: Burp's notes now support Markdown 🥳 🎉 It works in the usual notes (as the exchange level) but also in the About tab of collections (except for the default one named "Inbox")
Screenshot of a note using a few Markdown features (bold, headings, links...)
121
Mastering Burp Suite @mastering-burp.agarri.fr · 10/04/2026
And here's a short video demonstrating its usage xcancel.com/garethheyes/...
xcancel.com
000
Mastering Burp Suite @mastering-burp.agarri.fr · 10/04/2026
Just discovered the "Find tag" functionnality of Hackvertor and I already find it very useful 🔥 It can be triggered from Burp's command palette or with the Ctrl-Alt-F keyboard shortcut 🐇
222
Mastering Burp Suite @mastering-burp.agarri.fr · 01/04/2026
Last week, Syzik took my course and patched JWT ReAuth as the same time 🤯 Here's his fork github.com/Syzik/jwt-re... This version supports multiple profiles, per profile scopes, and the ability to fetch access tokens from refresh ones 🛠️
github.com
GitHub - Syzik/jwt-reauth
Contribute to Syzik/jwt-reauth development by creating an account on GitHub.
011
Mastering Burp Suite @mastering-burp.agarri.fr · 10/03/2026
A nice trick by @parsiya.bsky.social: how to share a Burp project with others without sharing tokens and secrets 🧠 parsiya.io/research/bur...
parsiya.io
Burp Tips and Tricks
Sharing Burp Projects without Secrets with Hackvertor You want to share a Burp project with others without sharing tokens and secrets. Install Hackvertor (you probably already have it). Create a Hac...
000
Reposted by Mastering Burp Suite
Nicolas Grégoire @agarri.fr · 04/03/2026
Come to Roma 🇮🇹 in September and attend the only in-person public training session I'll give in 2026! 👨‍🏫 And if you like camping with other hackers (as I do), stay over the weekend for the 3-day long RomHack Camp 🏕️ romhack.io/training/
romhack.io
RomHack Training
032
Mastering Burp Suite @mastering-burp.agarri.fr · 17/02/2026
Since EA 2026.2, there's a a search bar in Proxy History and it doesn't work exactly like the usual display filter. Let me explain... - the filter searches in requests, responses and notes - the search bar looks for the keyword in the table of entries itself (including custom and/or hidden columns)
000
Mastering Burp Suite @mastering-burp.agarri.fr · 26/01/2026
Out of curiosity, I counted how many configurable hotkeys exist in Burp Pro 📏 In Early Adopter version 2026.1.1, the answer is 168 🤓
media.tenor.com
a man is typing on a keyboard in a living room
Alt: A guy typing very fast on a keyboard
000
Mastering Burp Suite @mastering-burp.agarri.fr · 13/12/2025
A bunch of new features in EA 2025.12, including an E2E-encrypted way to share traffic between Pro users portswigger.net/burp/release...
portswigger.net
Professional / Community 2025.12
This release adds collections for secure message sharing, quick URL actions in command palette, OAuth2 Client Credentials support for API scanning, and improvements to Comparer and extension hotkeys,
010
Mastering Burp Suite @mastering-burp.agarri.fr · 06/12/2025
I really have to try this new MultiEncoder 🔬
010
Reposted by Mastering Burp Suite
Gareth Heyes @garethheyes.co.uk · 03/12/2025
Burp Hackvertor has a bunch of new shortcuts and functionality. Try them out in Burp. They are activated from a Burp repeater request.
052
Reposted by Mastering Burp Suite
Nicolas Grégoire @agarri.fr · 24/11/2025
The 2026 online public sessions of my "Mastering Burp Suite Pro" course have been published 📅 - March 24th to 27th, in French 🇫🇷 - April 14th to 17th, in English 🇬🇧 hackademy.agarri.fr/2026 PS: feel free to ping me if you'd like to temporarily block a seat or are looking for a 10% coupon 🎁
hackademy.agarri.fr
Agarri
Training
086
Reposted by Mastering Burp Suite
Mastering Burp Suite @mastering-burp.agarri.fr · 14/11/2025
Burp now has a command palette (similar to the one in VS Code) 🥳 portswigger.net/cms/images/4...
Burp’s command palette
132
Reposted by Mastering Burp Suite
Gareth Heyes @garethheyes.co.uk · 14/11/2025
Coming to Hackvertor soon... Big thanks to CoreyD97 for the suggestion!
031
Mastering Burp Suite @mastering-burp.agarri.fr · 14/11/2025
The corresponding changelog (EA 2025.11): portswigger.net/burp/release...
portswigger.net
Professional / Community 2025.11
This release adds a command palette for faster keyboard navigation, improved memory controls, and enhanced OAST support in custom scan checks. Take command of Burp from your keyboard with the Command
000
Mastering Burp Suite @mastering-burp.agarri.fr · 14/11/2025
Burp now has a command palette (similar to the one in VS Code) 🥳 portswigger.net/cms/images/4...
Burp’s command palette
132
Reposted by Mastering Burp Suite
James Kettle @jameskettle.com · 11/11/2025
I've just upgraded Turbo Intruder with a shiny new algorithm called HTTP Anomaly Rank, which automatically finds the most unusual responses in your attack! Here's a quick demo, full details in the writeup below: youtu.be/z92GobdN40Y
youtu.be
HTTP Anomaly Rank - a new Turbo Intruder feature
YouTube video by PortSwigger
2144
Mastering Burp Suite @mastering-burp.agarri.fr · 07/11/2025
Maybe that the next step will be the possibility to also enable extension-provided checks individually 🙏
110
Mastering Burp Suite @mastering-burp.agarri.fr · 07/11/2025
1) BChecks can be enabled individually 2) The configuration screen reflects settings loaded from the library
110
Mastering Burp Suite @mastering-burp.agarri.fr · 07/11/2025
Portswigger changed the way the Scanner configuration looks like (at least in Early Adopter releases) and I really like the new layout 👏
120
Reposted by Mastering Burp Suite
Pieter Hiele @honoki.net · 20/10/2025
If you're looking for a quick tool to copy regex matches from requests AND responses, have a look at github.com/honoki/burp-...
github.com
GitHub - honoki/burp-copy-regex-matches: Burp Suite plugin to copy regex matches from selected requests and/or responses to the clipboard.
Burp Suite plugin to copy regex matches from selected requests and/or responses to the clipboard. - honoki/burp-copy-regex-matches
011
Reposted by Mastering Burp Suite
Pieter Hiele @honoki.net · 20/10/2025
I wrote a small utility to copy unique domains, URLs, paths, filenames or directories from a selection on the Target Map in Burp Suite. The directories is especially useful in combination with something like ffuf, e.g. for /path/to/folder/file.txt will return the list /path /path/to /path/to/folder
github.com
GitHub - honoki/burp-copy-unique-domains
Contribute to honoki/burp-copy-unique-domains development by creating an account on GitHub.
141
Mastering Burp Suite @mastering-burp.agarri.fr · 25/10/2025
Great news! When creating a scan configuration, all non-default settings are now saved 💾 The ugly UX where only opened panes were saved is gone (since at least EA 2025.9.1) 🗑️
020
Mastering Burp Suite @mastering-burp.agarri.fr · 20/10/2025
A few days ago, @tib3rius.bsky.social published a video where he uses Burp AI features to hack on a vibe-coded web app 🪄 www.youtube.com/watch?v=lHby...
youtube.com
Hacking a Vibe Coded App with Burp AI!
YouTube video by Tib3rius
041
Reposted by Mastering Burp Suite
Robin @digi.ninja · 08/10/2025
New video, Decrypting TLS traffic in Wireshark. How to extract TLS keys from Burp, ZAP, and curl and then import them into Wireshark to see the raw traffic. youtu.be/bSt6E48mGuc
095
Reposted by Mastering Burp Suite
Mastering Burp Suite @mastering-burp.agarri.fr · 23/06/2025
If you're confused by the amount of resources stored in the JAR, here's a hint 🔎 Check out "resources/Scanner/jwt_secrets.txt". It contains over 100k passwords used by the passive scanner to decrypt JWT tokens 🗝️ And it works: that's how @evilpacket.net scored a $1500 bug affecting Cursor 💰
132
Mastering Burp Suite @mastering-burp.agarri.fr · 01/10/2025
In case you missed it, AWS updated its policy about pentesting, and "Amazon API Gateway" (used by the extension "IP Rotate") isn't allowed anymore aws.amazon.com/fr/security/...
aws.amazon.com
Penetration Testing
Request a penetration test for your AWS cloud infrastructure here.
122
Reposted by Mastering Burp Suite
Gareth Heyes @garethheyes.co.uk · 25/09/2025
Hackvertor v2.1.25 has been released and fixes the content-length problem!
041
Reposted by Mastering Burp Suite
Gareth Heyes @garethheyes.co.uk · 25/09/2025
Hackvertor v2.1.24 has a major bug where it doesn't update the content-length. Sorry about that. I've fixed it in v2.1.25. I'll try and get it updated on the BApp store ASAP. Gutted I missed this, sorry I'll try to do better in future.
011
Mastering Burp Suite @mastering-burp.agarri.fr · 18/09/2025
This one-liner shows the details of the most recent EA release of Burp Suite Pro 🔬 curl -s portswigger.net/burp/release... | jq -r '[.ResultSet.Results[] | select(.releaseChannels[0] == "Early Adopter")][:2] | .[] | "=== Version EA v\(.version), \(.releaseDate) ===", "\(.content)"' | html2text
020
Reposted by Mastering Burp Suite
d4d @zakfedotkin.bsky.social · 17/09/2025
Dive into WebSocket Turbo Intruder 2.0 - fuzz at scale, automate complex multi-step attacks, and exploit faster. The blog post is live! Read it here: portswigger.net/research/web...
portswigger.net
WebSocket Turbo Intruder: Unearthing the WebSocket Goldmine
Many testers and tools give up the moment a protocol upgrade to WebSocket occurs, or only perform shallow analysis. This is a huge blind spot, leaving many bugs like Broken Access Controls, Race condi
0136
Mastering Burp Suite @mastering-burp.agarri.fr · 12/09/2025
TIL Peter Weiner is on Linkedin 👀 www.linkedin.com/in/peter-wei... Did I send him an invitation? OF COURSE!! Has he accepted it? Not yet, but fingers crossed.
linkedin.com
020
Mastering Burp Suite @mastering-burp.agarri.fr · 10/09/2025
Here's the official doc from Oracle, you'll need in order to fully understand the regexp I posted above docs.oracle.com/javase/8/doc...
media.tenor.com
a poster that says knowledge is power with a statue of a viking
Alt: A cartoon where a dog carrying a pile of books says "knowledge is power"
030
Mastering Burp Suite @mastering-burp.agarri.fr · 10/09/2025
You never know when an obscure piece of trivia about Java regular expressions may be useful IRL 🤓 Today, I used the embedded flag "(?-s)" to disable the DOTALL mode and be able to work one a single line 🔬 The goal was to append a string to the User-Agent header, and it now works perfectly 🎉
A Burp Suite session handling rule with the "Match and replace" action. The regexp requires the embedded flag "(?-s)" in order to only impact the "User-Agent" header
151
Reposted by Mastering Burp Suite
Compass Security @compass-security.com · 09/09/2025
We use @jameskettle.com Burp extension Collaborator Everywhere daily. Now our upgrades are in v2: customizable payloads, storage, visibility. Perfect for OOB bugs like SSRF. Find out more here: blog.compass-security.com/2025/09/coll... #AppSec #BurpSuite #Pentesting
086
Reposted by Mastering Burp Suite
Mastering Burp Suite @mastering-burp.agarri.fr · 09/09/2025
It feels good to open Burp Suite after some month-long holidays All the bugs I reported have been patched, including the one where Repeater for Websocket wasn't showing the correspoding "response" in the bottom-right corner
media.tenor.com
a cartoon character from south park is sitting at a desk and says wow neato
Alt: A cartoon character from south park is sitting at a desk and says "wow! neato!"
041
Mastering Burp Suite @mastering-burp.agarri.fr · 09/09/2025
It feels good to open Burp Suite after some month-long holidays All the bugs I reported have been patched, including the one where Repeater for Websocket wasn't showing the correspoding "response" in the bottom-right corner
media.tenor.com
a cartoon character from south park is sitting at a desk and says wow neato
Alt: A cartoon character from south park is sitting at a desk and says "wow! neato!"
041
Reposted by Mastering Burp Suite
Mastering Burp Suite @mastering-burp.agarri.fr · 16/08/2025
A deep dive into Burp AI, by @parsiya.bsky.social 💎 parsiya.net/blog/2025-08...
parsiya.net
How Burp AI Works
This is a quick peek inside Burp AI. I'll show how to proxy its requests, what actually happens when you trigger a feature. This knowledge allows us to redirect Burp AI to your own AI instance. As far...
061
Reposted by Mastering Burp Suite
James Kettle @jameskettle.com · 20/08/2025
I just published a Repeater feature to make it easier to explore request smuggling. It repeats your request until the status code changes. It's called "Retry until success" and you can install it via the Extensibility helper bapp.
1145
Reposted by Mastering Burp Suite
Mastering Burp Suite @mastering-burp.agarri.fr · 18/08/2025
Burp Suite v1.0 was released exactly 20 years ago 🎂 portswigger.net/blog/burp-th...
portswigger.net
Burp through the ages
Here is a brief tour of the major releases of Burp from over the years. I can't believe it's been over 10 years already! Burp v1.0 Released June 2003 First incarnation of Intruder tool Includes burp s
0113