PortSwigger Introduces Burp AT: The Future of Pentesting with Agentic AI

PortSwigger Unveils Burp AT: A Game-Changer in Pentesting



PortSwigger has made a significant stride in the cybersecurity landscape with the announcement of Burp AT, a novel addition to its renowned Burp Suite. As a public beta, this innovative product promises to revolutionize professional pentesting through the integration of agentic AI, allowing cybersecurity professionals to enhance their testing capabilities while maintaining rigorous controls.

What is Burp AT?


Burp AT represents an evolutionary step for pentesters, enabling them to leverage agentic AI to assist in their workflows. This new functionality allows the AI to perform defined investigative tasks using Burp Suite's specialized tools, drawing relevant context from current projects and applying pentesting skills tailored for real-world applications. Ultimately, while this AI can operate autonomously, it is paramount that pentesters retain control. They can decide how much responsibility the AI should take on, establishing clear boundaries for its tasks which Burp enforces diligently.

Empowering Pentesters with Advanced AI


The capabilities of Burp AT extend beyond merely executing predefined tests. With the introduction of advanced reasoning abilities, the AI can formulate hypotheses, act using the suite's tools, interpret application responses, and determine subsequent actions. However, it is critical to note that ensuring reliable execution goes hand-in-hand with maintaining the integrity of pentesting. This balance is what sets Burp AT apart, as it not only facilitates advanced automated testing but does so within a framework that preserves the evidence, ensuring that the testing process is both reliable and accountable.

According to Dafydd Stuttard, the creator of Burp Suite and CEO of PortSwigger, "Burp AT empowers models with autonomous reasoning, but it meticulously regulates the parameters within which they operate, leveraging familiar tools that have been trusted by professionals in the field. This paradigm transforms agentic testing from an impressive theory into a practical resource during actual engagements."

Seamless Integration with Burp Suite


Burp AT's architecture is fundamentally designed to work natively with Burp Suite's specialized web security tools. This integration allows the AI to operate with a level of sophistication unachievable through generic HTTP libraries or improvised codes. The built-in tools of Burp Suite ensure robust handling of malformed requests and intricate protocol nuances that are critical for security testing, empowering the AI to concentrate on deeper investigative efforts.

Moreover, agents within Burp AT can access essential information stored in the Burp project, such as traffic data, application structure, and past discoveries, allowing for a consistent and informed approach to pentesting. This knowledge-sharing mechanism ensures that each new investigation can build on previously acquired information, enhancing overall efficiency and effectiveness.

Tailored Pentesting Skills for Next-Level Efficiency


As part of its innovative offering, Burp AT integrates structured and task-specific pentesting skills developed by PortSwigger Research. This feature not only equips agents with reusable testing methodologies but also assures that users do not need to code and maintain their operational frameworks manually. Instead, these methodologies evolve with input from research, translating into practical skills that can be employed during active tests.

Pentesters can dictate the extent of agent involvement per task, granting permissions that allow for increased autonomy, or mandating approvals for critical actions. This flexibility means that pentesters can adjust the AI's degree of intervention based on performance metrics and the sensitivity of the target systems, ensuring that human oversight is consistent.

The Value of Controlled Autonomy


One of the fundamental tenets of Burp AT is the distinction of control boundaries; while agents can suggest actions, they cannot execute without Burp's explicit permissions. This separation guarantees that pentesters retain authority over testing workflows and that all agent activities are logged meticulously within Burp projects. This accountability fosters transparency, permitting pentesters to conduct thorough oversight without solely relying on AI reports.

Participation in the Public Beta


At present, Burp AT is accessible in public beta exclusively to users of Burp Suite Professional. This initial version allows cybersecurity professionals to apply agentic AI capabilities in their real-world engagements, providing invaluable feedback that will inform future expansions of the product.

For more details about Burp AT, including its features, documentation, and pricing, interested users can visit Burp Suite's official page.

PortSwigger's commitment to enhancing web security remains unwavering, as they continue to support security professionals with cutting-edge tools and training tailored to meet tomorrow's challenges in cybersecurity.

Topics Consumer Technology)

【About Using Articles】

You can freely use the title and article content by linking to the page where the article is posted.
※ Images cannot be used.

【About Links】

Links are free to use.