Mastering Burp Suite's Avatar

Mastering Burp Suite

@mastering-burp.agarri.fr

Tips and tricks for Burp Suite Pro ๐Ÿ› ๏ธ Not affiliated with @portswigger.net ยฉ๏ธ Managed by @agarri.fr ๐Ÿ‡ซ๐Ÿ‡ท Additional free resources ๐ŸŽ http://hackademy.agarri.fr/freebies

976
Followers
1
Following
168
Posts
30.08.2023
Joined
Posts Following

Latest posts by Mastering Burp Suite @mastering-burp.agarri.fr

RomHack Training

Come to Roma ๐Ÿ‡ฎ๐Ÿ‡น ๏ฟผin September and attend the only in-person public training session I'll give in 2026! ๐Ÿ‘จโ€๐Ÿซ

And if you like camping with other hackers (as I do), stay over the weekend for the 3-day long RomHack Camp ๏ฟผ๐Ÿ•๏ธ

romhack.io/training/

04.03.2026 14:05 ๐Ÿ‘ 3 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Since EA 2026.2, there's a a search bar in Proxy History and it doesn't work exactly like the usual display filter. Let me explain...

- the filter searches in requests, responses and notes
- the search bar looks for the keyword in the table of entries itself (including custom and/or hidden columns)

17.02.2026 18:45 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
a man is typing on a keyboard in a living room Alt: A guy typing very fast on a keyboard

Out of curiosity, I counted how many configurable hotkeys exist in Burp Pro ๐Ÿ“

In Early Adopter version 2026.1.1, the answer is 168 ๐Ÿค“

26.01.2026 09:05 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Professional / Community 2025.12 This release adds collections for secure message sharing, quick URL actions in command palette, OAuth2 Client Credentials support for API scanning, and improvements to Comparer and extension hotkeys,

A bunch of new features in EA 2025.12, including an E2E-encrypted way to share traffic between Pro users portswigger.net/burp/release...

13.12.2025 13:36 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

I really have to try this new MultiEncoder ๐Ÿ”ฌ

06.12.2025 12:18 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Burp Hackvertor has a bunch of new shortcuts and functionality. Try them out in Burp. They are activated from a Burp repeater request.

03.12.2025 12:29 ๐Ÿ‘ 5 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Agarri Training

The 2026 online public sessions of my "Mastering Burp Suite Pro" course have been published ๐Ÿ“…

- March 24th to 27th, in French ๐Ÿ‡ซ๐Ÿ‡ท
- April 14th to 17th, in English ๐Ÿ‡ฌ๐Ÿ‡ง

hackademy.agarri.fr/2026

PS: feel free to ping me if you'd like to temporarily block a seat or are looking for a 10% coupon ๐ŸŽ

24.11.2025 10:14 ๐Ÿ‘ 8 ๐Ÿ” 7 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Burpโ€™s command palette

Burpโ€™s command palette

Burp now has a command palette (similar to the one in VS Code) ๐Ÿฅณ

portswigger.net/cms/images/4...

14.11.2025 13:07 ๐Ÿ‘ 3 ๐Ÿ” 2 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Video thumbnail

Coming to Hackvertor soon...
Big thanks to CoreyD97 for the suggestion!

14.11.2025 22:45 ๐Ÿ‘ 3 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Professional / Community 2025.11 This release adds a command palette for faster keyboard navigation, improved memory controls, and enhanced OAST support in custom scan checks. Take command of Burp from your keyboard with the Command

The corresponding changelog (EA 2025.11): portswigger.net/burp/release...

14.11.2025 13:08 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Burpโ€™s command palette

Burpโ€™s command palette

Burp now has a command palette (similar to the one in VS Code) ๐Ÿฅณ

portswigger.net/cms/images/4...

14.11.2025 13:07 ๐Ÿ‘ 3 ๐Ÿ” 2 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
HTTP Anomaly Rank - a new Turbo Intruder feature
HTTP Anomaly Rank - a new Turbo Intruder feature YouTube video by PortSwigger

I've just upgraded Turbo Intruder with a shiny new algorithm called HTTP Anomaly Rank, which automatically finds the most unusual responses in your attack! Here's a quick demo, full details in the writeup below: youtu.be/z92GobdN40Y

11.11.2025 14:49 ๐Ÿ‘ 14 ๐Ÿ” 4 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 1

Maybe that the next step will be the possibility to also enable extension-provided checks individually ๐Ÿ™

07.11.2025 08:55 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

1) BChecks can be enabled individually
2) The configuration screen reflects settings loaded from the library

07.11.2025 08:54 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Portswigger changed the way the Scanner configuration looks like (at least in Early Adopter releases) and I really like the new layout ๐Ÿ‘

07.11.2025 08:52 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
GitHub - honoki/burp-copy-regex-matches: Burp Suite plugin to copy regex matches from selected requests and/or responses to the clipboard. Burp Suite plugin to copy regex matches from selected requests and/or responses to the clipboard. - honoki/burp-copy-regex-matches

If you're looking for a quick tool to copy regex matches from requests AND responses, have a look at github.com/honoki/burp-...

20.10.2025 13:26 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
GitHub - honoki/burp-copy-unique-domains Contribute to honoki/burp-copy-unique-domains development by creating an account on GitHub.

I wrote a small utility to copy unique domains, URLs, paths, filenames or directories from a selection on the Target Map in Burp Suite.

The directories is especially useful in combination with something like ffuf, e.g. for /path/to/folder/file.txt will return the list
/path
/path/to
/path/to/folder

20.10.2025 13:21 ๐Ÿ‘ 4 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Great news! When creating a scan configuration, all non-default settings are now saved ๐Ÿ’พ

The ugly UX where only opened panes were saved is gone (since at least EA 2025.9.1) ๐Ÿ—‘๏ธ

25.10.2025 12:17 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Hacking a Vibe Coded App with Burp AI!
Hacking a Vibe Coded App with Burp AI! YouTube video by Tib3rius

A few days ago, @tib3rius.bsky.social published a video where he uses Burp AI features to hack on a vibe-coded web app ๐Ÿช„

www.youtube.com/watch?v=lHby...

20.10.2025 11:08 ๐Ÿ‘ 4 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

New video, Decrypting TLS traffic in Wireshark. How to extract TLS keys from Burp, ZAP, and curl and then import them into Wireshark to see the raw traffic.

youtu.be/bSt6E48mGuc

08.10.2025 10:05 ๐Ÿ‘ 9 ๐Ÿ” 5 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

If you're confused by the amount of resources stored in the JAR, here's a hint ๐Ÿ”Ž

Check out "resources/Scanner/jwt_secrets.txt". It contains over 100k passwords used by the passive scanner to decrypt JWT tokens ๐Ÿ—๏ธ

And it works: that's how @evilpacket.net scored a $1500 bug affecting Cursor ๐Ÿ’ฐ

23.06.2025 08:35 ๐Ÿ‘ 3 ๐Ÿ” 2 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Penetration Testing Request a penetration test for your AWS cloud infrastructure here.

In case you missed it, AWS updated its policy about pentesting, and "Amazon API Gateway" (used by the extension "IP Rotate") isn't allowed anymore

aws.amazon.com/fr/security/...

01.10.2025 09:21 ๐Ÿ‘ 2 ๐Ÿ” 2 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Hackvertor v2.1.25 has been released and fixes the content-length problem!

25.09.2025 09:32 ๐Ÿ‘ 4 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Hackvertor v2.1.24 has a major bug where it doesn't update the content-length. Sorry about that. I've fixed it in v2.1.25. I'll try and get it updated on the BApp store ASAP. Gutted I missed this, sorry I'll try to do better in future.

25.09.2025 07:56 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

This one-liner shows the details of the most recent EA release of Burp Suite Pro ๐Ÿ”ฌ

curl -s portswigger.net/burp/release... | jq -r '[.ResultSet.Results[] | select(.releaseChannels[0] == "Early Adopter")][:2] | .[] | "=== Version EA v\(.version), \(.releaseDate) ===", "\(.content)"' | html2text

18.09.2025 08:45 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
WebSocket Turbo Intruder:ย Unearthing the WebSocket Goldmine Many testers and tools give up the moment a protocol upgrade to WebSocket occurs, or only perform shallow analysis. This is a huge blind spot, leaving many bugs like Broken Access Controls, Race condi

Dive into WebSocket Turbo Intruder 2.0 - fuzz at scale, automate complex multi-step attacks, and exploit faster.
The blog post is live! Read it here:
portswigger.net/research/web...

17.09.2025 12:44 ๐Ÿ‘ 13 ๐Ÿ” 6 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

TIL Peter Weiner is on Linkedin ๐Ÿ‘€
www.linkedin.com/in/peter-wei...

Did I send him an invitation? OF COURSE!!
Has he accepted it? Not yet, but fingers crossed.

12.09.2025 10:45 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
a poster that says knowledge is power with a statue of a viking Alt: A cartoon where a dog carrying a pile of books says "knowledge is power"

Here's the official doc from Oracle, you'll need in order to fully understand the regexp I posted above

docs.oracle.com/javase/8/doc...

10.09.2025 13:31 ๐Ÿ‘ 3 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
A Burp Suite session handling rule with the "Match and replace" action. The regexp requires the embedded flag "(?-s)" in order to only impact the "User-Agent" header

A Burp Suite session handling rule with the "Match and replace" action. The regexp requires the embedded flag "(?-s)" in order to only impact the "User-Agent" header

You never know when an obscure piece of trivia about Java regular expressions may be useful IRL ๐Ÿค“

Today, I used the embedded flag "(?-s)" to disable the DOTALL mode and be able to work one a single line ๐Ÿ”ฌ

The goal was to append a string to the User-Agent header, and it now works perfectly ๐ŸŽ‰

10.09.2025 13:23 ๐Ÿ‘ 5 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0