Web application · Commercial (Professional/Enterprise); free Community Edition

Burp Suite

Burp Suite, by PortSwigger, is the industry-standard toolkit for web application security testing. It works as an intercepting HTTP/HTTPS proxy that sits between your browser and the target, letting you view, modify and replay every request. Testers use it to find flaws such as SQL injection, XSS, broken access control and authentication weaknesses. It comes in a free Community edition and a paid Professional edition with an automated scanner.

Last updated: 6 August 2026

What Burp Suite is actually used for

Burp captures a browser session so a tester can manipulate raw requests before they reach the server. You send an interesting request to Repeater to hand-craft payloads, or to Intruder to brute-force parameters and fuzz inputs. Professional adds an automated vulnerability scanner and Collaborator for detecting out-of-band issues like blind SSRF. In practice it is where web pentesters spend most of their day: mapping the app, testing each parameter, and confirming whether an input is exploitable.

Platforms

Linux · Windows · macOS

Licence

Commercial (Professional/Enterprise); free Community Edition

Commands worth knowing

Proxy > Intercept

Pause a request in-flight to read and edit headers, cookies and body before forwarding it.

Proxy > HTTP history

Review every request the browser made, then right-click to send interesting ones to other tools.

Send to Repeater (Ctrl+R)

Manually re-issue and tweak a single request repeatedly to test one parameter.

Send to Intruder (Ctrl+I)

Set payload positions and automate fuzzing or credential testing across a wordlist.

Target > Site map

Build a tree of the application's URLs and endpoints as you browse for coverage.

Decoder / Inspector

URL-, Base64- or HTML-encode and decode values while crafting payloads.

Scanner (Professional)

Run automated active/passive scans to flag likely vulnerabilities for manual confirmation.

The legal line

Only intercept and test applications you own or are explicitly authorised (in writing, within a defined scope) to assess. Actively scanning or attacking a third-party web app without permission is unauthorised access under the IT Act 2000. Bug-bounty testing is only lawful within the published program scope and rules.

What Burp Suite is bad at

The automated scanner produces false positives and misses business-logic flaws, so a human must verify every finding. Community edition throttles Intruder heavily, has no scanner, and cannot save projects. Burp tests the application layer only; it will not find OS or network vulnerabilities.

Alternatives, and when to pick them

ToolPick it when
OWASP ZAPYou want a fully free, open-source proxy and scanner with no paid tier.
CaidoYou want a lighter, modern Rust-based proxy as an alternative workflow to Burp.
mitmproxyYou prefer a scriptable, command-line intercepting proxy for automation.
FiddlerYou mainly need HTTP debugging on Windows rather than security testing depth.
PostmanYou are testing and documenting APIs rather than attacking a web app.

Where we teach it

Ethical Hacking Course (6 months) — web application security module

We are not affiliated with, endorsed by, or a reseller for the vendors of any tool on this site.

Burp Suite — FAQs

Is Burp Suite Community edition enough to learn web pentesting?

Yes for learning. Community gives you the full proxy, Repeater and a rate-limited Intruder, which cover the core manual skills. You mainly lose the automated scanner, Collaborator and saved projects, which matter more on paid engagements.

What is the difference between Burp Community and Professional?

Professional removes the Intruder throttle and adds an automated vulnerability scanner, Burp Collaborator for out-of-band testing, the full BApp store and saved project files. Community is free but manual-only.

Can Burp Suite hack any website?

No. Burp is a testing toolkit, not a one-click exploit. It helps a skilled tester find and confirm flaws, and using it against sites you are not authorised to test is illegal.

Burp Suite Professional ki keemat kitni hai?

PortSwigger ise per-user yearly subscription (lagbhag USD 499) par bechta hai. Seekhne ke liye free Community edition kaafi hai; paid version tab lein jab aap professional engagements karein.

Learn Burp Suite properly, in a legal lab

Free counselling call. We will tell you honestly whether a full course is worth it for what you actually want to do.

Call +91 75175 72000