In section Releases

PortSwigger debuts Burp AT to bring agentic AI into pentesting

PortSwigger has launched a public beta of Burp AT, a new tool designed to integrate agentic AI directly into the Burp Suite professional environment. The platform allows security researchers to delegate investigative tasks to AI agents while maintaining strict control over scope, permissions, and final decision-making processes during live engagements.

PortSwigger debuts Burp AT to bring agentic AI into pentesting

The new release addresses the gap between impressive AI demonstrations and the practical requirements of professional security testing. Rather than relying on general-purpose libraries, Burp AT operates through Burp Suite’s specialized web security tools, leveraging two decades of data regarding protocol edge cases and malformed requests. This integration allows AI models to focus on hypothesis formation and tactical decision-making while the software handles the execution and evidence logging.

Central to the system is the concept of tiered autonomy. Pentesters define the boundaries of agent involvement, selecting whether tasks require manual approval or can proceed with smart automation. Architectural safeguards ensure that security constraints are enforced at the tooling layer, preventing models from bypassing established engagement rules. By utilizing structured, research-backed pentesting skills, practitioners can move beyond improvised prompts and scripts, applying validated testing methodologies directly to their targets. The beta is now accessible to current Burp Suite Professional users, with the developer soliciting feedback to refine its capabilities and workflows.

Share:on TelegramXFacebook

Subscribe to our newsletter

Once a week — the best stories from our editors, no ads or push notifications. Delivered Sunday morning.

Comments (0)

Leave a comment

No comments yet. Be the first!