Burp Suite is a comprehensive toolkit for web application security testing, offering a range of products and solutions for identifying vulnerabilities, improving security posture, and enabling DevSecOps. The platform provides a dynamic web vulnerability scanner, manual tools for web security testing, and a web application security scanning solution for CI/CD. Additionally, Burp Suite offers a free online training center, the Web Security Academy, which provides interactive labs and learning materials for web application security. The platform's products include Burp Suite Enterprise Edition, Burp Suite Professional, and Burp Suite Community Edition, each catering to different needs and use cases. The solutions offered by Burp Suite cover application security testing, penetration testing, automated scanning, bug bounty hunting, and compliance, among others. The Web Security Academy provides a flexible learning path with interactive labs and progress-tracking, produced by a world-class team of experts in web application security.
FEATURES
ALTERNATIVES
Instrumentation-based approach for resolving reflective calls in Android apps.
A Dynamic Application Security Testing (DAST) platform that provides automated security testing for web applications, APIs, and LLM-powered applications throughout the software development lifecycle.
An automated code security tool that analyzes repositories, identifies vulnerabilities, and generates pull requests with fixes while integrating with existing development workflows.
ESLint plugin to prevent Trojan Source attacks.
A Java API for searching and downloading Android applications from Google Play with additional check-in features for generating ANDROID-ID.
Embeddable Yara library for Java with support for loading rules and scanning data.
A managed Web Application and API Protection (WAAP) platform that combines WAF, API security, DDoS protection, and bot mitigation with 24/7 monitoring services.
An automated security testing platform that performs AI-driven penetration testing and vulnerability assessment for web applications and APIs with compliance reporting capabilities.
PINNED

Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

OSINTLeak
OSINTLeak is a tool for discovering and analyzing leaked sensitive information across various online sources to identify potential security risks.

ImmuniWeb® Discovery
ImmuniWeb Discovery is an attack surface management platform that continuously monitors an organization's external digital assets for security vulnerabilities, misconfigurations, and threats across domains, applications, cloud resources, and the dark web.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.