The 'Tool Integration' category contains Burp Suite extensions designed to bridge Burp with external vulnerability management, collaboration, and reconnaissance platforms. Use these extensions to automate the flow of findings, import external data into the Burp sitemap, or collaborate with other security professionals.
Key integration types include:
Vulnerability Management & Reporting
- ElasticSearch: Use
Report To Elastic Search to pass issues to stdout or an ElasticSearch database, or ElasticBurp to store requests/responses in an ElasticSearch index. - Qualys: Use
Qualys WAS to push findings to the Qualys Cloud Platform. - CodeDx: Use
Code Dx to upload scan reports directly to the CodeDx management system. - ThreadFix: Use
Threadfix to interface with ThreadFix. - Nucleus: Use
Nucleus Burp Extension to push scans to the Nucleus platform. - Dradis: Use
Drasis Framework to integrate with Dradis. - Faraday: Use
Faraday to integrate with the Faraday Integrated Penetration-Test Environment. - Issue Poster: Use
Issue Poster to post scanner issue details to external web services.
Data Import & Parsing
- Nmap: Use
NMAP Parser to parse Nmap output files and add web ports to the target scope. - Nessus: Use
Nessus Loader to parse Nessus XML files and add discovered web servers to the sitemap. - Pcap: Use
Pcap Importer to import Pcap/Pcap-NG files into the Target sitemap for passive scanning. - ZAP/wstalker: Use
Import To Sitemap to import wstalker CSV or ZAP export files into the Burp Sitemap. - Teamserver: Use
Burptrast to pull endpoint information from Teamserver into the sitemap.
Collaboration & Workflow
- Git: Use
Git Bridge to store Burp data and collaborate via git repositories. - Chat: Use
Burp Chat to enable collaborative usage via XMPP/Jabber. - Faction: Use
Faction Burp Suite Extension to integrate into the Faction assessment collaboration framework.
Specialized Security Tooling
- Frida: Use
Brida to bridge Burp Suite and Frida, allowing manipulation of application methods while tampering with traffic. - Semgrep: Use
Semgrepper to include Semgrep results in the passive scanner checks. - Nuclei: Use
Nuclei Template Generator Burp Plugin to assist with nuclei template generation. - Bug Bounty: Use
YesWeBurp to access YesWeHack bug bounty programs directly within Burp.