Burp Suite User Forum

Create new post

How do I exclude any issues that are marked as false positive in a consecutive scan?

ramya | Last updated: Jun 04, 2019 04:25AM UTC

We run Active scan regularly against full application. Since in every scan, there is a chance that the same false positives will be reported, we want to eliminate the activity of identifying the repeated false positives in every scan. Is there a way that the first time scan is run, we analyse the report to identify the false positives (FPs) - mark them as FPs and when the subsequent scan is run, we focus more on the newly reported issue analysis? And in the latest analysis, if we found any more FPs, add them to the FP repository and move forward? I read from https://support.portswigger.net/customer/portal/questions/17430540-enterprise-version , that there is an option to include or exclude any issues that are marked as false positive. Can you help by letting us the steps?

PortSwigger Agent | Last updated: Jun 04, 2019 09:02AM UTC

This is possible using Burp Enterprise - although not with Burp Pro. There's a quick guide to this in the release notes: - http://releases.portswigger.net/2019/04/enterprise-edition-1015beta.html We'll be producing more through documentation in due course.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.