NOTES
Burp is the workbench I want between the browser or client and the application. The biggest value is visibility: seeing exactly what the application sends, replaying requests in a controlled way, and organizing evidence as the test develops.
WORKFLOW
- Set target scope early so project history stays usable.
- Use Repeater for deliberate request-by-request investigation rather than changing many variables at once.
- Keep notes tied to concrete requests, responses, affected functions, and user roles.
- Separate interesting behavior from confirmed security impact before writing a finding.
EVIDENCE
Save the smallest request and response pair that demonstrates the issue, redact unnecessary secrets, and record enough context that another tester can reproduce the observation in the same authorized environment.