Burp Suite Professional
world's #1 web penetration testing toolkit.
Automate and save time
Smart automation works in concert with expert-designed manual tools, to save you time. Optimize your workflow, and do more of what you do best.
Scan the modern web
Burp Scanner can navigate and scan JavaScript-heavy single-page applications (SPAs), can scan APIs, and enables prerecording of complex authentication sequences.
Minimize false positive
Ultra reliable out-of-band application security testing (OAST) can find many otherwise invisible issues - including blind asynchronous vulnerabilities.
Find vulnerabilities others can't
Push the boundaries of web security testing - by being first to benefit from the work of PortSwigger Research. Frequent releases keep you ahead of the curve.
Be more productive
A toolkit designed and used by professional testers. Utilize features like the ability to record everything you did on an engagement - and a powerful search function - to improve efficiency and reliability.
Share your findings more easily
Simplify your documentation and remediation process, and produce reports that end users will appreciate. Good security testing doesn't end at discovery.
Adapt your toolkit to suit your needs
Share in a wealth of knowledge, extend Burp Scanner with BChecks, and access hundreds of pre-written BApp extensions, as a member of Burp Suite Professional's huge user community.
Customize the way you work
Whether you want to create custom scan configurations, or you'd rather just work in dark mode, we've got you covered. Burp Suite Professional is made to be customized.











































