Burp Suite is a comprehensive web application security testing toolkit by PortSwigger. It integrates an intercepting proxy, scanner, and manual testing tools to find and validate vulnerabilities. Widely used by security teams and developers for dynamic application security testing and penetration testing workflows.
Use this profile to understand the building block briefly, place it in the model, and open related building blocks.
Usable application software: supports people in a task.
Concrete cog in the system that works inside larger relationships.
Burp Suite is an integrated toolkit for web application security testing. It combines an intercepting proxy, a scanner, and manual testing tools so vulnerabilities in HTTP-based applications can be observed, modified, and validated.
Burp Suite grew out of Dafydd Stuttard’s need to automate his own web security testing. According to the product history, he developed the tool between 2003 and 2006 and created PortSwigger to carry it forward. What began as a personal testing problem became an integrated platform for intercepting, replaying, and checking web traffic.
Think of Burp Suite as a test control room between the browser and the target application. The proxy captures traffic and makes requests editable. The site map organizes the attack surface, Repeater resends individual messages in a controlled way, Intruder generates variants for fuzzing and load-style tests, Scanner looks for known patterns, and extensions add specialist functions.
The proxy sits between client and target system and makes traffic visible and editable.
A clearly defined scope decides which hosts, paths, and tests are allowed and useful.
Individual HTTP messages can be resent and changed in a controlled way to compare responses.
The scanner detects recurring patterns and known vulnerability classes, but does not replace validation.
The BApp Store and APIs allow add-ons for extra checks, workflows, and integrations.
Burp Suite is useful before releases, in penetration testing, for bug bounty work, and when checking authentication, session handling, access control, and input validation. It speeds up routine findings, but trustworthy results still require skilled manual review and a clear test scope. Intrusive tests can change data, invalidate tokens, or trigger rate limits, so authorization and test accounts matter.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.