Burp Suite User Forum

Create new post

Recommended Scan Config settings?

Dylan | Last updated: May 13, 2020 04:57PM UTC

We are currently using for Enterprise: Audit Checks - all except time-based detection methods Audit Checks - passive Crawl strategy - faster This config scans much much quicker than our previous tool (most site scans under 15 minutes). We are not seeing many High or Medium (which is good..) findings. Just wondering if there is a Recommended Scan Config or a baseline we could start with and slowing add or change settings for best results.

Uthman, PortSwigger Agent | Last updated: May 14, 2020 08:28AM UTC

Hi Dylan, There is no specific baseline configuration but I would suggest fully customizing your scan configuration alongside using the default ones. You can create a new scan configuration in the UI: <ENTERPRISE-SERVER-URL>/scanconfigurations/create. You may be missing any High/Medium vulnerabilities so it would be best if you test a few different configurations to see which one meets your testing needs and yields the best results. - https://portswigger.net/burp/documentation/enterprise/working/scans

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.