Burp Suite

Web App Testing Workflows

🌐 Proxy & Interception

ActionPurpose
Start Burp SuiteLaunch GUI interface
Configure browser proxy (127.0.0.1:8080)Route traffic through Burp
Enable InterceptPause and inspect HTTP requests
Forward / DropSend or discard intercepted request
Save request to RepeaterSend request for manual testing

πŸ” Scanner & Crawler

ActionPurpose
Target > Site MapView discovered endpoints
Right-click > ScanLaunch active scan on target
Dashboard > IssuesReview vulnerabilities found
Spider / CrawlAutomatically discover pages and forms
Filter by severityPrioritize critical findings

πŸ§ͺ Repeater & Intruder

ActionPurpose
Send request to RepeaterManually modify and resend requests
Analyze responseCheck for changes, errors, or leaks
Send request to IntruderAutomate payload injection
Set attack positionsMark fields for fuzzing
Choose payload typeUse lists, numbers, or brute force

πŸ“ Extensions & Output

ActionPurpose
Install BApp extensionsAdd custom modules and tools
Export scan resultsSave findings to HTML or XML
Generate reportCreate summary of vulnerabilities
Use Logger++Track all requests and responses