Burp Suite

WEB HTTP PROXY REQUEST ANALYSIS

NOTES

Burp is the workbench I want between the browser or client and the application. The biggest value is visibility: seeing exactly what the application sends, replaying requests in a controlled way, and organizing evidence as the test develops.

WORKFLOW

EVIDENCE

Save the smallest request and response pair that demonstrates the issue, redact unnecessary secrets, and record enough context that another tester can reproduce the observation in the same authorized environment.

DOCS

PortSwigger Burp Suite documentation ↗

← Back to Resources