Burp Suite
Web Security 6 commands

Burp Suite

Integrated platform for web application security testing. Industry standard for manual and automated web vulnerability scanning.

webproxyscannerpentesting
Official docs

Installation

# Download from PortSwigger website
# Community Edition is free
# Professional Edition requires license

Commands & usage

6 entries
  • Proxy > Intercept

    Intercept and modify HTTP requests

  • Target > Site Map

    Map application structure

  • Scanner

    Automated vulnerability scanning

  • Repeater

    Manually modify and resend requests

  • Intruder

    Automated customized attacks

  • Decoder

    Encode/decode data formats

Use cases

Web app pentestingAPI testingAuthentication testingInjection testingSession management testing