
burpsuite-mcp-server
3 years
Works with Finder
1
Github Watches
0
Github Forks
0
Github Stars
Burpsuite MCP Server
A Model Context Protocol (MCP) server that provides an interface for interacting with Burpsuite Professional's scanning and proxy functionality.
Overview
This MCP server allows AI assistants to interact with Burpsuite Professional for web security testing and vulnerability scanning. It provides tools for:
- Starting vulnerability scans on target URLs
- Checking scan status and retrieving results
- Accessing HTTP/HTTPS traffic captured by Burp Proxy
- Viewing site structure discovered during scanning
Features
Tools
The server exposes the following tools:
-
start_scan: Start a new vulnerability scan on a target URL
- Parameters:
-
target
: Target URL to scan (e.g., https://example.com) -
scan_type
: Type of scan to perform (passive, active, or full)
-
- Parameters:
-
get_scan_status: Check the status of a running scan
- Parameters:
-
scan_id
: ID of the scan to check
-
- Parameters:
-
get_scan_issues: Get vulnerability issues found in a scan
- Parameters:
-
scan_id
: ID of the scan -
severity
: Filter issues by severity (high, medium, low, info, or all)
-
- Parameters:
-
get_proxy_history: Get HTTP/HTTPS traffic captured by Burp Proxy
- Parameters:
-
host
: Filter by host (optional) -
method
: Filter by HTTP method (optional) -
status_code
: Filter by HTTP status code (optional) -
limit
: Maximum number of items to return (default: 10)
-
- Parameters:
-
get_site_map: Get the site structure discovered during scanning and browsing
- Parameters:
-
host
: Filter by host (optional) -
with_parameters
: Only show URLs with parameters (optional) -
limit
: Maximum number of items to return (default: 20)
-
- Parameters:
Resources
The server provides the following resources:
-
Scan Results:
burpsuite://scan/{scanId}
-
Issue Details:
burpsuite://scan/{scanId}/issue/{issueId}
-
Proxy History:
burpsuite://proxy/history
-
Proxy History Item:
burpsuite://proxy/history/{itemId}
-
Site Map:
burpsuite://sitemap
Installation
-
Build the server:
cd /path/to/burpsuite-server npm install npm run build
-
Add the server to your MCP settings configuration file:
{ "mcpServers": { "burpsuite": { "command": "node", "args": ["/path/to/burpsuite-server/build/index.js"], "env": {}, "disabled": false, "autoApprove": [] } } }
Future Enhancements
This server currently provides mock functionality. To connect it to a real Burpsuite Professional instance:
- Configure Burpsuite Professional to expose its REST API
- Update the server implementation to connect to the Burpsuite REST API
- Add authentication mechanisms for secure API communication
Example Usage
Here are some examples of how to use the Burpsuite MCP server with an AI assistant:
Starting a Scan
Use the Burpsuite MCP server to scan example.com for vulnerabilities.
Viewing Proxy History
Show me the HTTP traffic captured by Burp Proxy for domain example.com.
Analyzing Vulnerabilities
What high severity vulnerabilities were found in the latest scan?
相关推荐
Converts Figma frames into front-end code for various mobile frameworks.
I find academic articles and books for research and literature reviews.
Confidential guide on numerology and astrology, based of GG33 Public information
Embark on a thrilling diplomatic quest across a galaxy on the brink of war. Navigate complex politics and alien cultures to forge peace and avert catastrophe in this immersive interstellar adventure.
Advanced software engineer GPT that excels through nailing the basics.
Delivers concise Python code and interprets non-English comments
💬 MaxKB is a ready-to-use AI chatbot that integrates Retrieval-Augmented Generation (RAG) pipelines, supports robust workflows, and provides advanced MCP tool-use capabilities.
Micropython I2C-based manipulation of the MCP series GPIO expander, derived from Adafruit_MCP230xx
The all-in-one Desktop & Docker AI application with built-in RAG, AI agents, No-code agent builder, MCP compatibility, and more.
MCP server to provide Figma layout information to AI coding agents like Cursor
Reviews

user_tqYjeNfl
Burpsuite-mcp-server by Cyreslab-AI is a fantastic tool for managing multiple Burp Suite instances. It's incredibly useful for coordinating and automating security testing tasks, especially in complex environments. The ease of use and integration capabilities make it a must-have for security professionals. Highly recommended for anyone looking to streamline their penetration testing processes!