0Pricing
Cyber Security Academy · Lesson

Scanner and Extensions

Automate testing.

Automating with Scanner

Burp's Scanner automatically tests an application for common vulnerabilities, freeing you to focus on the harder, manual logic flaws.

It is available in Burp Suite Professional and Enterprise editions, not Community.

Crawl and Audit

A Burp scan has two phases: crawl discovers the application's pages and inputs, and audit tests each discovered input for vulnerabilities.

You can run crawl only, audit only, or both.

Scan phases:
  1. Crawl  -> map URLs, forms, params
  2. Audit  -> test inputs for issues

All lessons in this course

  1. Proxy and Interception
  2. Repeater and Intruder
  3. Scanner and Extensions
  4. Practical Workflows
← Back to Cyber Security Academy