
BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and streamline web application security testing workflows.
BurpFlow is a lightweight Node.js CLI tool that routes HTTP requests through a Burp Suite proxy, enabling security testers to quickly load and analyze reconnaissance URLs inside Burp.
BurpFlow is a fast, efficient, and minimal recon automation CLI tool designed for penetration testers, bug bounty hunters, and security researchers.
It simplifies the process of sending HTTP requests through a Burp proxy, allowing you to:
⚠️ DISCLAIMER: This tool is strictly for authorized security testing and educational use only. Unauthorized usage is illegal.
npm install -g burpflow
git clone https://github.com/Cappricio-Securities/burpflow.git
npm install
node burpflow.js -h
127.0.0.1:8080)burpflow -h
burpflow -p 127.0.0.1:8080 -u https://example.com
Create a file (urls.txt):
https://example.com
https://github.com
Run:
burpflow -p 127.0.0.1:8080 -l urls.txt
burpflow -p 127.0.0.1:8080 -l urls.txt -c 8 -t 12000
██████╗ ██╗ ██╗██████╗ ██████╗ ███████╗██╗ ██████╗ ██╗ ██╗
██╔══██╗██║ ██║██╔══██╗██╔══██╗██╔════╝██║ ██╔═══██╗██║ ██║
██████╔╝██║ ██║██████╔╝██████╔╝█████╗ ██║ ██║ ██║██║ █╗ ██║
██╔══██╗██║ ██║██╔══██╗██╔═══╝ ██╔══╝ ██║ ██║ ██║██║███╗██║
██████╔╝╚██████╔╝██║ ██║██║ ██║ ███████╗╚██████╔╝╚███╔███╔╝
╚═════╝ ╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═╝ ╚══════╝ ╚═════╝ ╚══╝╚══╝
Developed by Team : Cappriciosec.com
🚀 BurpFlow - Recon to Burp Automation Tool
Started
┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓
┃ proxy : 192.168.0.103:8080 ┃
┃ Concurrency: 5 | 10000ms ┃
┗━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛
[✔] Loaded: https://www.example.com [status 200]
[✔] Loaded: https://www.stage.electronics.example.com [status 200]
[✔] Loaded: http://www.sprt8.example.co.jp [status 403]
BurpFlow complete. Check Burp Suite proxy history.
burpflow/
├── burpflow.js
├── includes/
│ ├── help.js
│ ├── utils.js
│ ├── filereader.js
│ ├── validate.js
│ ├── runner.js
├── README.md
└── package.json
ECONNREFUSED → Proxy not running or wrong portInvalid URL → Must start with http:// or https://-u or -lMIT License
KarthiTheHacker
| Flag | Description |
|---|
-p, --proxy | Proxy address (required), e.g. 127.0.0.1:8080 |
-u, --url | Single URL |
-l, --list | File containing URLs |
-c, --concurrency | Parallel requests (default: 5) |
-t, --timeout | Timeout in ms (default: 10000) |
-h, --help | Show help |