The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

How do I exclude any issues that are marked as false positive in a consecutive scan?

ramya | Last updated: Jun 04, 2019 04:25AM UTC

We run Active scan regularly against full application. Since in every scan, there is a chance that the same false positives will be reported, we want to eliminate the activity of identifying the repeated false positives in every scan. Is there a way that the first time scan is run, we analyse the report to identify the false positives (FPs) - mark them as FPs and when the subsequent scan is run, we focus more on the newly reported issue analysis? And in the latest analysis, if we found any more FPs, add them to the FP repository and move forward? I read from https://support.portswigger.net/customer/portal/questions/17430540-enterprise-version , that there is an option to include or exclude any issues that are marked as false positive. Can you help by letting us the steps?

PortSwigger Agent | Last updated: Jun 04, 2019 09:02AM UTC