How do an authenticated audit only scan using the recorded login?

Michael | Last updated: Feb 17, 2022 07:50PM UTC

I can do an authenticated crawl and audit. When I tried to audit only for a URL later, there were no options to select a recorded login. Is that not possible?

Ben, PortSwigger Agent | Last updated: Feb 18, 2022 10:27AM UTC

Hi Michael, If you are performing an audit only scan then Burp will simply use existing requests that have already been captured within Burp when it is performing the auditing. Burp is not path-aware in this mode of operation so, unlike a full crawl and audit, Burp has no concept of how a particular request has been generated so will not use recorded login sequences during an audit only scan.

