BurpMCP
If you are the rightful owner of BurpMCP and would like to certify it and/or have it hosted online, please leave a comment on the right or send an email to henry@mcphub.com.
BurpMCP is a Burp Suite extension that integrates with Model Context Protocol clients to enhance application security testing using AI.
BurpMCP is a powerful extension for Burp Suite designed to enhance the capabilities of application security testers, vulnerability researchers, and bug bounty hunters by integrating modern AI technologies. It leverages large language models (LLMs) to provide intelligent assistance in navigating complex attack surfaces and identifying vulnerabilities in HTTP-based applications. By connecting Burp Suite with MCP clients like Claude Desktop and Cursor, BurpMCP allows users to prompt AI for autonomous testing while maintaining full control and visibility over the model's actions. This extension is particularly useful for manual application security testing, offering features such as saving requests, sending new requests, and generating Collaborator payloads for out-of-band testing. BurpMCP operates an MCP Server that interfaces directly with the Burp Suite extension API, providing a seamless integration for enhanced security testing.
Features
- Save Requests: Allows saving requests in the extension for MCP clients to retrieve using the Get-Saved-Request Tool.
- Request Logs: Send new HTTP/1.1 and HTTP/2 requests and view them in the Request Logs tab.
- Resend Requests: Resend saved requests with regex string replacements for faster tweaking, similar to Repeater for LLMs.
- Collaborator Payloads: Generate Collaborator payloads and retrieve interactions for LLM-led out-of-band testing.
- Server Logs: View all MCP messages in the Server logs tab for easy debugging.