Burp Suite User Forum

Create new post

Setting up Burp Professional for Automated Scans via APIs

Praveen | Last updated: Feb 08, 2021 03:42AM UTC

Hello, I have a few questions on how Burp can be setup to automate API Penetration Testing and call it as a service 1. Does Burp Suite Professional have APIs for Scan,Report, etc. that can be called as a web-service, if so please provide the link 2. Or only Enterprise Edition has APIs that can be availed for this purpose 3. Also, is there any documentation to host this kind of automated service in Kubernetes Cluster for scaling and faster scan times ?

Ben, PortSwigger Agent | Last updated: Feb 08, 2021 10:34AM UTC

Hi Praveen, Burp Professional has a REST API that contains a subset of the functionality that can be used when interacting with Burp using the GUI. The REST API is self documenting and, if you navigate to the User options -> Misc -> REST API within Burp, you will be able to find details of how to access this. In terms of automation, we have specifically created Burp Enterprise for this purpose and Burp Professional has been designed to be run as a desktop application by a single user.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.