Burp sits between your browser and the web app, letting you see and modify every request. It's the #1 tool of web testers and bug bounty hunters.
Follow the steps β click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Install Burp's CA certificate or HTTPS sites will scream.
See exactly what the app sends. Edit anything, forward, watch the result.
Repeater is where 90% of manual testing happens.
CE throttles speed; the workflow is what matters. Try ffuf for speed.
Passive crawl as you browse = your attack surface inventory.
| Proxy | intercept & history |
| Repeater | manual replay lab |
| Intruder | payload fuzzing |
| Decoder | encode/decode quickly |
| Comparer | diff two responses |
| Extensions | BApp store toys: Autorize⦠|
Scope the target (Target β Scope) so you only attack what you're allowed.
Match & replace rules auto-ride sessions: swap logged-out cookies for admin ones, watch access control break.
PortSwigger Academy labs assume Burp workflows β do them in order.
Hotkeys win: Ctrl+R repeater, Ctrl+I interceptor, Ctrl+Shift+T new tab.
Use Burp Suite only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox β plenty of legal targets, zero risk.