Burp Suite User Forum

Create new post

Burpsuite Scan using command line

KieuThanh | Last updated: Aug 22, 2023 04:22AM UTC

Hi, I would like to bring up BURP using command line (without any GUI) for automation. I want to fill in options such as --domain, --proxy (authentication required), --concurrency,... where should I handle it? Thanks for the support.

Dominyque, PortSwigger Agent | Last updated: Aug 22, 2023 09:34AM UTC

Hi Burp Suite Professional does not have a great amount of functionality available for the command line as it is designed to be used through the GUI. These are the commands we have available: https://portswigger.net/burp/documentation/desktop/troubleshooting/launch-from-command-line. Additionally, it should be noted that Burp Suite Professional is not designed to be used for large-scale automation.

KieuThanh | Last updated: Aug 23, 2023 02:13AM UTC

i want to integrate burp into my app. so can i scan target with api? and the api is only provided by burp suite enterprise

KieuThanh | Last updated: Aug 23, 2023 02:16AM UTC

i want to ask more is option --config-file and --user-config-file it's burpsuite config file, it's not config file for target scan right

Dominyque, PortSwigger Agent | Last updated: Aug 23, 2023 07:50AM UTC

Hi You might be interested in one of our Extensions on the BApp Store. It might give you more of the functionality you are looking for to run Burp headlessly: https://portswigger.net/bappstore/d54b11f7af3c4dfeb6b81fb5db72e381. Yes, you are right in the --config-file specifics the project configuration file. Additionally, you can check out our REST API. It should be noted that this is a legacy feature and is also quite limited in what you can do with it: https://portswigger.net/burp/documentation/desktop/settings/suite/rest-api.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.