Skip to content

#65 · Burp Suite Exports Support for REST API Scanning in DAST

We’re excited to introduce another great capability for our DAST scanner: support for Burp Suite exports as REST API schemas. This enhancement streamlines your workflow by allowing you to leverage Burp Suite traffic captures to define your API schema, ensuring more comprehensive and efficient vulnerability scans.

What are Burp Suite Exports, and why use them?

Burp Suite is a widely-used tool for security testing, and its exports provide detailed records of HTTP traffic captured during web application testing. With this update, our DAST scanner can now ingest Burp Suite exports to interpret and scan REST APIs.

How it works

  1. Capture Traffic with Burp Suite

Use Burp Suite to intercept and record API traffic during your testing session. Export the captured data in the supported format.

  1. Upload to DAST Scanner Configure your scan in a few easy steps:

  2. Go to Security Scan and click New Application.

  3. Select REST API.
  4. Configure your Network and Authentication settings (if required).
  5. Upload the Burp Suite export file to define your API schema.

3.Initiate the Scan

The scanner parses the Burp Suite export, identifying endpoints, HTTP methods, and other critical details. Start the scan to analyze your API for vulnerabilities.

We hope this new feature helps streamline your security testing workflow. And of course, we wish you not too many criticals found 😉