The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Configuring default false positive settings - Burp Professional

Shaunik | Last updated: Jan 06, 2023 02:18PM UTC

Hi, I'm using Burp Professional for application scanning (Crawl and Audit). I need to perform this activity on same application at regular frequency (monthly, quarterly, etc.). Once the scan is completed, Burp Professional has a provision to mark any finding as "False positive" by using Set Severity option. Is there a way Burp Professional remembers that based on URL and Issue Type (may be more parameters) and similar issues are not reported in successive scans using same project file? I checked recently updated documentation of Enterprise edition - Configuring default false positive settings - which looks like for the same purpose I'm looking for. [https://portswigger.net/burp/documentation/enterprise/working-with-scans/config-false-positives] Please confirm my understanding. Is similar feature offered by Burp Professional as well ? Thanks

Hannah, PortSwigger Agent | Last updated: Jan 09, 2023 09:34AM UTC