Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
BurpIA — Extensión de Burp Suite que incorpora detección pasiva de vulnerabilidades mediante inteligencia artificial. | Kitploit
Tools/GitHubGitHub/dragonjar/burpia
Defensive ToolsWeb Vulnerability ScannersVulnerability AnalysisDynamic Code Analysis (DAST)Web Application ExploitationAPI Security TestingWeb SecurityPenetration TestingUtilities & FrameworksAI Security
18361 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHub
dragonjar/burpia

BurpIA

Extensión de Burp Suite que incorpora detección pasiva de vulnerabilidades mediante inteligencia artificial.

View Repository
Share

BurpIA

BurpIA Logo

License: MIT Version Burp Suite Author Español

BurpIA turns Burp Suite into an AI-assisted web security testing environment. It analyzes real HTTP traffic with LLMs (12+ providers or local models), validates findings with autonomous CLI agents over Burp MCP, and keeps every result traceable — works on Burp Suite Community and Professional.

🎯 What BurpIA Does

This extension turns passive HTTP traffic into actionable security findings. It can:

  • Analyze traffic with LLMs: automatic passive scanning or manual analysis via context menu, using real evidence (request + response).
  • Analyze request flows: contextual analysis of 2–4 related requests as a single flow, ideal for state and logic vulnerabilities.
  • Validate with CLI agents: send findings or flows to autonomous agents (Factory Droid, Claude Code, Antigravity, Open Code, Grok, Codex) integrated with Burp Suite MCP for deep manual validation.
  • Triage at speed: send findings directly to Burp Repeater from the centralized results table, or save them to the Burp project Issues.
  • Manage findings intelligently: severity/confidence prioritization, text and severity filters, CSV/JSON export.
  • Stay in control: request deduplication (SHA-256, TTL 15 min, LRU 10k), configurable concurrency (1–10), static-resource filtering, bilingual UI (Spanish/English), native Dark/Light theme.

Important: AI findings are hints, not verdicts. Always validate before reporting — false positives are possible.

📦 Installation

  1. Download BurpIA-1.7.0.jar from the releases page.
  2. In Burp Suite: Extensions tab → Add → select the JAR file.
  3. Configure your provider in the BurpIA tab: LLM Provider, API Key (if applicable), Model, Language.
  4. Use Test Connection to validate the endpoint before capturing traffic.

⚙️ Prerequisites

RequirementDetail
Burp SuiteCommunity or Professional
Operating systemmacOS, Linux, or Windows
Java17+ (bundled JRE in native Burp installers works)
LLM accessAPI key for a cloud provider, local Ollama, or LM Studio
CLI agent (optional)One of: droid, claude, agy, opencode, grok, codex
UI languageSpanish or English (switchable in settings)

🚀 Quick Start (3 minutes)

  1. Load the extension (see Installation).
  2. Select your LLM Provider and enter the API Key.
  3. Click Test Connection to validate endpoint and model.
  4. Browse through Burp Proxy — findings appear in the BurpIA tab as traffic is analyzed.
  5. Right-click any request → Analyze request with BurpIA (or 🤖 Analyze with {Agent} for agent validation).

🔄 How It Works

Passive flow

  1. BurpIA intercepts an HTTP exchange.
  2. It checks the Scope, applies filters, and deduplicates.
  3. The task is queued in the analysis manager.
  4. The prompt is built by injecting request and response.
  5. The AI response is parsed and findings are normalized.
  6. The results table, statistics, and (if enabled) Burp Issues are updated.

Manual flow

  1. Select one or more requests (2–4 for flow analysis) in any Burp tab.
  2. Right-click:
    • 1 request: Analyze request with BurpIA or 🤖 Analyze with {Agent}.
    • 2–4 requests: 🔍 Analyze this flow or 🤖 Analyze this flow with {Agent}.
  3. The finding appears in the table to be edited, exported, or sent to Repeater.

🔌 Supported LLM Providers

ProviderNotes
OllamaLocal models: Qwen 3.8, Llama 4, Gemma 4, DeepSeek v4, Phi-4, etc.
Ollama CloudCloud models at ollama.com — requires API key
OpenAIGPT-5.6 (+ Luna/Sol/Terra/Cyber variants)
ClaudeAnthropic: Fable 5.1, Opus 5, Sonnet 5
GeminiGoogle: 3.8 Flash (GA), 3.7/3.6 Flash, 2.5 Pro
Moonshot (Kimi)K3, K2.7 and earlier
Z.ai / MinimaxGLM 5.3 and MiniMax H3
DeepSeekv4-pro, v4-flash — OpenAI-compatible API
xAI Grokgrok-4.6, grok-4.5 — OpenAI-compatible API
Sakana Fugufugu, fugu-ultra
LM StudioLocal server, OpenAI-compatible
CustomUp to 3 profiles for any OpenAI-compatible API

🤖 CLI Agents

Autonomous validation agents integrated with Burp Suite MCP:

AgentBinaryGuide
Factory DroiddroidEN · ES
Claude CodeclaudeEN · ES
Antigravity CLIagyEN · ES
Open CodeopencodeEN · ES
Grok CLIgrokEN · ES
Codex CLIcodexEN · ES

🧠 Custom Prompt Tokens

  • {REQUEST} / {RESPONSE}: normalized HTTP request/response.
  • {REQUEST_1}…{REQUEST_N} / {RESPONSE_1}…{RESPONSE_N}: Nth element of a flow.
  • {OUTPUT_LANGUAGE}: expected output language for finding descriptions.

If you omit these tokens, BurpIA automatically appends a security block (fallback) to keep minimum context and enforce the configured language.

🚀 Usage Example

Custom prompt targeting an authentication flow (2 requests analyzed as one):

You are a web security auditor. Focus ONLY on authentication and session logic.

Request 1 (login):
{REQUEST_1}
Response 1:
{RESPONSE_1}

Request 2 (password change):
{REQUEST_2}
Response 2:
{RESPONSE_2}

Report findings in {OUTPUT_LANGUAGE} with severity, confidence, and remediation.

Typical finding produced by BurpIA (rendered in the results table):

Title:    Password change endpoint accepts old password indefinitely
Severity: High · Confidence: Certain
Endpoint: POST /api/v2/account/password  (200 OK)
Evidence: The password-change flow succeeded using the pre-login session
          token, indicating missing re-authentication and no rotation of
          existing sessions.
Remedy:   Require current-password verification and invalidate all active
          sessions after a successful change.

From the table you can send it to Burp Repeater for manual validation, export it (CSV/JSON), or dispatch it to a CLI agent for deeper validation via Burp MCP.

📸 Screenshots

Download Tool