Burp Suite Goes AI: Revolutionizing Web Pentesting
PortSwigger has built an agentic AI assistant, Burp AI, directly into Burp Suite Professional's Repeater tool, so testers can triage findings, validate exploits, and draft parts of a report without leaving the tool they already run all day. The same release ships AI-enhanced scanning for Broken Access Control and an AI-powered upgrade to the community extension Hackvertor. PortSwigger positions Burp AI as an assistant that augments a tester's judgment, not a tool that replaces it (PortSwigger, retrieved 2026-09-18).
This post covers what Burp AI actually does today, what independent numbers exist on its impact, and why cybersecurity marketers and product teams should treat AI-native updates to security tooling as both a competitive signal and a fast-moving content opportunity.
Key Takeaways
- Burp AI lives inside Repeater and is built to augment, not replace, a human tester (PortSwigger, retrieved 2026-09-18).
- It automates the repetitive middle of testing: reducing scanning noise, helping validate findings, and drafting report language.
- An Orange Cyberdefense case study reported 2-5x faster completion of early-stage investigation and validation work using the tool (PortSwigger, retrieved 2026-09-18).
- The AI-enhanced vulnerability scanning ships narrow at launch, starting with Broken Access Control, not a blanket claim of finding every vulnerability class.
- PortSwigger states pentest data stays inside its own AI platform and is not stored by the AI provider or used for model training, which matters when the data involves a client's live vulnerabilities.
- Extension developers get AI hooks through the Montoya API, and Hackvertor's natural-language custom tags are the first public showcase built on it.
What Is Burp AI?
Burp AI is PortSwigger's agentic AI feature set built into Burp Suite Professional's Repeater tool, the workspace most testers use to manually manipulate and resend HTTP requests. Instead of a separate AI product bolted on the side, it works inside the request/response flow a tester already relies on.
What it does inside Repeater
- Reduces scanning noise so a tester spends less time separating real findings from false positives.
- Assists with validating a finding before it goes into a report, which is normally one of the slower manual steps.
- Helps draft report language once a vulnerability is confirmed.
- Runs AI-enhanced scanning for Broken Access Control, the first vulnerability class PortSwigger has extended with this capability.
Why the Orange Cyberdefense number matters
The 2-5x speed figure PortSwigger cites from Orange Cyberdefense's use of the tool applies specifically to early-stage investigation and validation, not to a full pentest engagement end to end (PortSwigger, retrieved 2026-09-18). Treat it as a directional signal on where the tool saves time, not a claim that entire engagements run 2-5x faster.
What Changed With This Release
- Montoya API hooks for extensions. PortSwigger's extension API now exposes AI functionality, so third-party extension developers can build their own AI-powered tools on top of Burp Suite rather than waiting for PortSwigger to ship every feature natively.
- Hackvertor's AI upgrade. As the first public showcase built on those hooks, researcher Gareth Heyes added AI features to the popular Hackvertor extension: creating custom tags from natural-language prompts, generating the underlying code in JavaScript, Python, Java, and Groovy, and generating encoding/decoding tag pairs based on patterns observed in a request.
- Data handling disclosure. PortSwigger states explicitly that AI-processed data stays inside its own platform, isn't stored by the underlying AI provider, and isn't used to train external models — and that the AI features can be fully disabled in settings (PortSwigger, retrieved 2026-09-18).
Why This Matters to Cybersecurity Marketers
A pentesting tool millions of security professionals already use just shipped a visible AI feature set, and that is exactly the kind of vendor-tool news worth turning into content fast, before the outlets covering it move on.
AI is showing up across the entire security stack, not just marketing tools. If you're only tracking AI adoption inside your own martech, you're missing half the story your buyers are watching.
The audience is specific. Penetration testers, application security specialists, and DevSecOps teams are the people who will actually read and share coverage of this. Write for them, not for a general security audience.
Speed is the differentiator. By the time a slower competitor publishes their take, the news cycle has usually moved on. Tools that monitor security news and draft a first pass quickly close that gap — see our comparison of news aggregation tools for security marketers and our roundup of AI tools for cybersecurity marketers for what that looks like in practice.
There's a second layer worth watching too. As AI assistants become a normal part of how security tools work, they're also becoming a normal part of how buyers find those tools — someone asking ChatGPT or Perplexity "best AI-powered web pentesting extension" is doing AI search, not a Google search. Whether your product gets named in that answer is a separate, measurable problem from whether you cover the news well. Our guide to AI search visibility tools for citation tracking covers how to check.
How This Guide Was Sourced
This guide is written by GrackerAI's research and content team, which builds AI search visibility tracking and AI-optimized content production for cybersecurity and B2B SaaS vendors — disclosed here since the guide also recommends checking your own AI visibility. Product facts about Burp AI are drawn from PortSwigger's own product page, retrieved 2026-09-18; the original announcement was also covered by Cybersecurity News. PortSwigger's AI feature set is under active development and specific terms (credit allowances, which scan checks are AI-enhanced) can change — verify current details on PortSwigger's site before publishing numbers as current. No GrackerAI telemetry is used in this guide.
Frequently Asked Questions
What is Burp AI?
Burp AI is PortSwigger's agentic AI assistant built into Burp Suite Professional's Repeater tool. It helps testers reduce scanning noise, validate findings, and draft report language, and it powers a new AI-enhanced scan check for Broken Access Control.
Does Burp AI replace manual penetration testing?
No. PortSwigger frames it as a tool that augments a human tester's workflow rather than a fully autonomous scanner. Findings still need a tester's judgment to confirm and report.
Is Burp AI included with Burp Suite Professional, or is it a separate purchase?
Burp AI ships as part of Burp Suite Professional's Repeater tool. Specific credit allowances and any usage limits should be checked directly on PortSwigger's current pricing page, since promotional terms change.
What is the Montoya API and how does it relate to Burp AI?
The Montoya API is PortSwigger's extension API for Burp Suite. This release added AI hooks to it, so third-party extension developers can build their own AI-powered tools on top of Burp Suite rather than waiting for a native feature.
How does the Hackvertor AI upgrade work?
Hackvertor is a popular community extension for encoding, decoding, and transforming data inside Burp Suite. Its AI upgrade lets a user describe a custom tag in natural language and have the extension generate the underlying code (in JavaScript, Python, Java, or Groovy) or generate matching encode/decode tag pairs from patterns it observes in a request.
Is client pentest data used to train PortSwigger's AI models?
PortSwigger states that data processed by Burp AI stays within its own secure AI platform, is not stored by the underlying AI service provider, and is not used for model training, and that the AI features can be turned off entirely in settings.
Conclusion
Burp AI is a concrete example of AI moving from "a separate tool you also use" to "a feature built into the tool you already trust with client data." For cybersecurity marketers, that's a fast-moving news hook. For vendors building security products, it's also a preview of a broader shift: buyers increasingly discover and evaluate tools through AI assistants, not just search engines and review sites, which makes AI search visibility a metric worth tracking alongside product-security news itself.