Introducing Burp AT: agentic AI, built on two decades of Burp Suite
Fran Hutchings |Monday, 27 July 202 2026-7-27 12:51:51 Author: portswigger.net(查看原文) 阅读量:6 收藏

Fran Hutchings | Monday, 27 July 2026 at 12:51 UTC

Burp AT brings agentic AI to human-led pentesting, with Burp Suite’s proven tools, your project context, and purpose-built skills. You decide how much work agents take on. Burp enforces the boundaries. Live now in public beta for Burp Suite Professional users.

AI can already find and exploit vulnerabilities. The question is no longer whether the technology is capable. It is what kind of AI you can trust against systems you are responsible for testing.

Today, we are launching Burp AT in public beta for Burp Suite Professional users.

Burp AT lets you put agentic AI to work inside Burp Suite. Agents pursue the tasks you hand them using Burp’s specialist tools, the context gathered in your project, and pentesting skills developed with PortSwigger Research, all while you stay in the loop for scope, judgment, and conclusions.

That means you can hand agents investigations that would otherwise compete for your limited time and attention, while you focus your expertise where it matters most. Leads can be pursued further, unfamiliar areas explored more deeply, and worthwhile work that might otherwise go untouched can become part of the test.

Pentesting takes more than a capable model

Frontier AI models can find and exploit vulnerabilities. Agents can form a hypothesis, act through tools, interpret what they learn, and decide what to try next.

But a professional pentest requires more than capable reasoning. It requires reliable specialist tools, access to relevant context, purpose-built methodology, and boundaries the model cannot bypass.

Burp AT is built around all four:

  • Burp’s tools and your project context. Agents act through the same battle-hardened tooling professional pentesters have trusted for over 20 years, and draw selectively on the traffic, target structure, issues, and discoveries already in your Burp project so they work alongside you on the test rather than starting from a blank prompt.
  • Purpose-built pentesting skills. A library of pentesting skills, developed with PortSwigger Research, gives agents structured approaches to apply, instead of improvising a methodology from general model knowledge. As researchers develop new techniques, they become skills agents can use on real tests.
  • Autonomy on your terms. You decide how much work agents take on, what proceeds, what needs approval, and what is blocked. The right level of autonomy can vary by task, target, risk, and the trust that has been earned.
  • Boundaries enforced by Burp. Scope, tool access, and approval rules live in Burp’s tooling layer, architecturally separate from the model, and every request and decision is recorded. Agents can propose actions, but they cannot execute actions Burp does not permit. Agents propose. Burp enforces. You decide.

Deliver more from every pentest

The fastest way to see the value is to hand Burp AT a lead you would usually run out of time to chase. Something as simple as:

Analyze the minified JavaScript loaded by this target, reconstruct the endpoints and workflows it references, and flag anything that looks sensitive or unauthenticated and worth investigating further.

In our closed beta, one professional pentester did exactly that against 66,000 lines of minified JavaScript they could never have read by hand inside a four-day engagement. Burp AT helped surface a critical vulnerability that would otherwise have gone untested for at least another year.

This is life changing. I cannot begin to express how much easier it started making certain portions of the testing, and how much easier it has made learning. - Pentester, Closed Beta

Because the work runs through Burp, the resulting requests, responses, and evidence are tracked, so you can reproduce the finding and stand behind it rather than relying on a model’s account of what it did.

The first phase of Burp AT

This is the first release of Burp AT, available today to Burp Suite Professional users. It brings agentic AI into a human-led pentesting workflow: agents take on more of the work inside Burp, while you retain control of scope, judgment, and conclusions.

Today, Burp AT works alongside you in the Burp workflow. Over time, the same foundation will support more operating modes for teams and enterprises, including more autonomous testing under standing policy, shared visibility, and auditability. Human-led testing remains one of those modes.

We will keep improving its tools, skills, and workflows as more people put it to work and share their feedback, and we will stay clear about what it can do today and where it is still developing.

Burp Suite has earned trust through more than two decades of use against real applications. Burp AT is new, and it has to earn that trust in the real world. That is why we are launching it as a public beta: so professional testers can put it to work, show us where it performs well and where it falls short, and help shape what it becomes. - Dafydd Stuttard, Founder and CEO, PortSwigger

The shape of pentesting is changing. Burp AT gives you a way to put agentic testing to work on your terms, built on the Burp Suite tools you already trust.

See everything Burp AT can do, and start using it in public beta today.


文章来源: https://portswigger.net/blog/introducing-burp-at
如有侵权请联系:admin#unsafe.sh