PortSwigger Introduces Burp AT Agentic AI for Human-Led Web Pentesting
Key Takeaways PortSwigger has launched Burp AT, integrating agentic AI capabilities into Burp Suite Professional. The new feature allows human penetration testers to delegate specific investigative...
Key Takeaways
- PortSwigger has launched Burp AT, integrating agentic AI capabilities into Burp Suite Professional.
- The new feature allows human penetration testers to delegate specific investigative tasks to AI agents while maintaining full control and oversight.
- Burp AT leverages Burp Suite’s existing tooling and project data, enforcing boundaries through the tool rather than the AI model itself.
- Early beta testing showed significant efficiency gains, with one tester uncovering a critical vulnerability in minified JavaScript that would have been impossible to find manually within the engagement timeframe.
- The public beta phase is designed to gather feedback and build trust, with future plans for team and enterprise-level autonomous testing options.
PortSwigger has unveiled Burp AT, a significant new addition to its flagship Burp Suite Professional, introducing agentic artificial intelligence directly into web application penetration testing workflows. This public beta release marks a pivotal moment in how security professionals might approach complex web security assessments.
Table Of Content
The core innovation behind Burp AT lies in its ability to empower penetration testers to delegate specific, intricate investigative tasks to AI agents. Crucially, this delegation occurs while human testers retain absolute authority over the testing scope, make critical judgments, and draw final conclusions. This hybrid approach aims to redefine the professional standards for web application security testing.
This development directly addresses a persistent question within the cybersecurity community: the role of AI in vulnerability discovery. While advanced AI models have demonstrated their capacity to identify and exploit vulnerabilities, the challenge has been integrating such capabilities into professional testing environments where accountability, reliability, and human oversight are paramount.
PortSwigger’s solution fuses Burp Suite’s robust, two-decade-old toolset with context-rich project data and specialized penetration testing skills, developed collaboratively with PortSwigger Research. This integration ensures that AI augments, rather than replaces, the human element.
PortSwigger Launches Burp AT
Burp AT is built upon four fundamental principles designed to ensure agentic testing is practical and trustworthy in real-world engagements.
Core Pillars of Burp AT
- Leveraging Existing Tooling: Instead of operating in a vacuum, Burp AT agents utilize Burp Suite’s established tools and draw upon existing project data, including captured traffic, target structure, and previously identified findings.
- Specialized Pentesting Skills: Agents are equipped with a growing library of purpose-built pentesting skills. These structured methodologies prevent reliance on a general AI model’s knowledge, with new techniques continuously integrated as PortSwigger’s researchers develop them.
- Human Control Over Autonomy: Testers maintain granular control over agent autonomy. They can dictate which actions agents execute independently, which require explicit human approval, and which remain entirely off-limits.
- Enforced Boundaries: Critically, all operational boundaries and restrictions are enforced by Burp Suite’s underlying tooling layer, not by the AI model itself. This architecture ensures that every agent action is logged, and agents cannot bypass restrictions, even if they propose alternative actions.
This architectural philosophy underpins PortSwigger’s vision for Burp AT: agents propose actions, Burp enforces the limits, and the human tester makes the final decision.
During its closed beta phase, Burp AT demonstrated tangible benefits. One pentester successfully utilized the tool to analyze 66,000 lines of minified JavaScript during a four-day engagement—a task deemed impossible to complete manually within such a tight timeframe. The agent effectively reconstructed endpoints and workflows from the obfuscated code, highlighting suspicious, unauthenticated areas for further investigation. This process led to the discovery of a critical vulnerability that would likely have remained undetected for at least another year. The tester reported that the experience profoundly enhanced both testing efficiency and skill development.
Since all agent activity is routed through Burp Suite, testers can maintain reproducible evidence, including detailed requests and responses. This eliminates the need to solely rely on an AI’s self-reported summaries of its actions, bolstering auditability and trust.
This initial release represents what PortSwigger describes as the first stage of a comprehensive roadmap. Currently, Burp AT is designed to function within a human-led workflow, acting as an augmentation for individual testers rather than a replacement for their critical oversight.
PortSwigger has indicated that future iterations will introduce additional operating modes tailored for teams and enterprises. These may include more autonomous testing capabilities guided by standing policies, featuring shared visibility and comprehensive audit trails, while the human-led testing option will remain permanently available.
Commenting on the launch, PortSwigger Founder and CEO Dafydd Stuttard emphasized that trust must be earned, not assumed. He highlighted that while Burp Suite has established its credibility over two decades of real-world application, Burp AT is a new offering that must undergo a similar proving process. This commitment to transparency is why the company opted for a public beta release, inviting testers to rigorously evaluate the tool and contribute to its ongoing development.
Burp AT is immediately available to all Burp Suite Professional users, providing a practical entry point for security professionals eager to integrate agentic AI into their existing testing methodologies without relinquishing control over sensitive engagements.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.