Burp Suite, by PortSwigger, is the industry-standard toolkit for web application security testing. It works as an intercepting HTTP/HTTPS proxy that sits between your browser and the target, letting you view, modify and replay every request. Testers use it to find flaws such as SQL injection, XSS, broken access control and authentication weaknesses. It comes in a free Community edition and a paid Professional edition with an automated scanner.
Last updated: 6 August 2026
Burp captures a browser session so a tester can manipulate raw requests before they reach the server. You send an interesting request to Repeater to hand-craft payloads, or to Intruder to brute-force parameters and fuzz inputs. Professional adds an automated vulnerability scanner and Collaborator for detecting out-of-band issues like blind SSRF. In practice it is where web pentesters spend most of their day: mapping the app, testing each parameter, and confirming whether an input is exploitable.
Linux · Windows · macOS
Commercial (Professional/Enterprise); free Community Edition
Proxy > InterceptPause a request in-flight to read and edit headers, cookies and body before forwarding it.
Proxy > HTTP historyReview every request the browser made, then right-click to send interesting ones to other tools.
Send to Repeater (Ctrl+R)Manually re-issue and tweak a single request repeatedly to test one parameter.
Send to Intruder (Ctrl+I)Set payload positions and automate fuzzing or credential testing across a wordlist.
Target > Site mapBuild a tree of the application's URLs and endpoints as you browse for coverage.
Decoder / InspectorURL-, Base64- or HTML-encode and decode values while crafting payloads.
Scanner (Professional)Run automated active/passive scans to flag likely vulnerabilities for manual confirmation.
Only intercept and test applications you own or are explicitly authorised (in writing, within a defined scope) to assess. Actively scanning or attacking a third-party web app without permission is unauthorised access under the IT Act 2000. Bug-bounty testing is only lawful within the published program scope and rules.
The automated scanner produces false positives and misses business-logic flaws, so a human must verify every finding. Community edition throttles Intruder heavily, has no scanner, and cannot save projects. Burp tests the application layer only; it will not find OS or network vulnerabilities.
| Tool | Pick it when |
|---|---|
| OWASP ZAP | You want a fully free, open-source proxy and scanner with no paid tier. |
| Caido | You want a lighter, modern Rust-based proxy as an alternative workflow to Burp. |
| mitmproxy | You prefer a scriptable, command-line intercepting proxy for automation. |
| Fiddler | You mainly need HTTP debugging on Windows rather than security testing depth. |
| Postman | You are testing and documenting APIs rather than attacking a web app. |
Ethical Hacking Course (6 months) — web application security module
We are not affiliated with, endorsed by, or a reseller for the vendors of any tool on this site.
Free counselling call. We will tell you honestly whether a full course is worth it for what you actually want to do.
Call +91 75175 72000