The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Does API Scan do anything different than just using scanner?

Robert | Last updated: Aug 01, 2024 02:03AM UTC

Before there was an API scan, I would do some manual testing on APIs and then run the API through scanner to double check my work. Now I see there is an option for API scan or Web app scan but what is the difference? Does API scan just not crawl as to only scan the specific API? or are there new checks and vulnerabilities it checks that it wouldn't under web app scan? I noticed the API scan makes you use a certain format, does that allow BURP to better locate injection points within the body of the request making it more accurate than the Web App scan? Just trying to see if I should use API Scan or just stay with the Web App scan.

Syed, PortSwigger Agent | Last updated: Aug 01, 2024 02:55PM UTC