
Extensión de Burp Suite que incorpora detección pasiva de vulnerabilidades mediante inteligencia artificial.
BurpIA turns Burp Suite into an AI-assisted web security testing environment. It analyzes real HTTP traffic with LLMs (12+ providers or local models), validates findings with autonomous CLI agents over Burp MCP, and keeps every result traceable — works on Burp Suite Community and Professional.
This extension turns passive HTTP traffic into actionable security findings. It can:
request + response).Important: AI findings are hints, not verdicts. Always validate before reporting — false positives are possible.
BurpIA-1.7.0.jar from the releases page.Extensions tab → Add → select the JAR file.| Requirement | Detail |
|---|---|
| Burp Suite | Community or Professional |
| Operating system | macOS, Linux, or Windows |
| Java | 17+ (bundled JRE in native Burp installers works) |
| LLM access | API key for a cloud provider, local Ollama, or LM Studio |
| CLI agent (optional) | One of: droid, claude, agy, opencode, grok, codex |
| UI language | Spanish or English (switchable in settings) |
Analyze request with BurpIA (or 🤖 Analyze with {Agent} for agent validation).request and response.Analyze request with BurpIA or 🤖 Analyze with {Agent}.🔍 Analyze this flow or 🤖 Analyze this flow with {Agent}.| Provider | Notes |
|---|---|
| Ollama | Local models: Qwen 3.8, Llama 4, Gemma 4, DeepSeek v4, Phi-4, etc. |
| Ollama Cloud | Cloud models at ollama.com — requires API key |
| OpenAI | GPT-5.6 (+ Luna/Sol/Terra/Cyber variants) |
| Claude | Anthropic: Fable 5.1, Opus 5, Sonnet 5 |
| Gemini | Google: 3.8 Flash (GA), 3.7/3.6 Flash, 2.5 Pro |
| Moonshot (Kimi) | K3, K2.7 and earlier |
| Z.ai / Minimax | GLM 5.3 and MiniMax H3 |
| DeepSeek | v4-pro, v4-flash — OpenAI-compatible API |
| xAI Grok | grok-4.6, grok-4.5 — OpenAI-compatible API |
| Sakana Fugu | fugu, fugu-ultra |
| LM Studio | Local server, OpenAI-compatible |
| Custom | Up to 3 profiles for any OpenAI-compatible API |
Autonomous validation agents integrated with Burp Suite MCP:
| Agent | Binary | Guide |
|---|---|---|
| Factory Droid | droid | EN · ES |
| Claude Code | claude | EN · ES |
| Antigravity CLI | agy | EN · ES |
| Open Code | opencode | EN · ES |
| Grok CLI | grok | EN · ES |
| Codex CLI | codex | EN · ES |
{REQUEST} / {RESPONSE}: normalized HTTP request/response.{REQUEST_1}…{REQUEST_N} / {RESPONSE_1}…{RESPONSE_N}: Nth element of a flow.{OUTPUT_LANGUAGE}: expected output language for finding descriptions.If you omit these tokens, BurpIA automatically appends a security block (fallback) to keep minimum context and enforce the configured language.
Custom prompt targeting an authentication flow (2 requests analyzed as one):
You are a web security auditor. Focus ONLY on authentication and session logic.
Request 1 (login):
{REQUEST_1}
Response 1:
{RESPONSE_1}
Request 2 (password change):
{REQUEST_2}
Response 2:
{RESPONSE_2}
Report findings in {OUTPUT_LANGUAGE} with severity, confidence, and remediation.
Typical finding produced by BurpIA (rendered in the results table):
Title: Password change endpoint accepts old password indefinitely
Severity: High · Confidence: Certain
Endpoint: POST /api/v2/account/password (200 OK)
Evidence: The password-change flow succeeded using the pre-login session
token, indicating missing re-authentication and no rotation of
existing sessions.
Remedy: Require current-password verification and invalidate all active
sessions after a successful change.
From the table you can send it to Burp Repeater for manual validation, export it (CSV/JSON), or dispatch it to a CLI agent for deeper validation via Burp MCP.