The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Burp REST API - capturing traffic

Andrej | Last updated: Sep 26, 2018 11:04AM UTC

Hi, in my experience, launching an active scan on valid dataset from Proxy is the best approach. We have regular releases, triggering test packs for changed functionality which can be routed through Burp Suite. So far, we always opened manually new Proxy listener, captured traffic, closed it, and ran active scan. Would it be possible, to enhance the REST APIs to be able to start listening on certain port (ideally with indication of transparent proxy); then indicate to Burp that it is finished (to close the listening port); so that we can launch the pre-defined active scan on intercepted data afterwards? With session management, excludes and everything else pre-prepared. I think it would be a very good addition, and most likely it's in your pipeline, but as far as I know that isn't a publicly accessible information so I can't vote for it in other way, as this:)

PortSwigger Agent | Last updated: Sep 26, 2018 01:22PM UTC