Burp Suite Professional
Web vulnerability scanner and proxy toolkit for penetration testers
portswigger.net — this link takes you to the developer's own website.
- Version
- 2026.3.3
- License
- Subscription
- Platforms
- Windows
- Publisher
- PortSwigger Web Security
Burp Suite Professional is a desktop toolkit for finding and validating security vulnerabilities in web applications and APIs. It is built by PortSwigger for people who do this as a job: penetration testers, security engineers, DevSecOps teams, and bug bounty hunters, rather than for general end users.
The toolkit centers on an intercepting proxy that lets you inspect and modify HTTP traffic between a browser and a target application. On top of that sit an automated web vulnerability scanner, Burp Intruder for scripted and automated attacks, and support for authenticated API scanning. Findings can be logged and compiled into reports for remediation. The program can be extended with third-party BApp extensions and customized through Bambdas and BChecks scripting.
Because it works by actively probing applications for flaws, it should only be pointed at systems the user is authorized to test.
Burp Suite Professional is not free software. PortSwigger's published licensing terms describe it as a per-user, annually renewing subscription; a subscription cannot be shared between multiple people, though one licensed user may install it on more than one computer. A fully-featured free trial is available without a credit card, but the software itself requires a paid subscription to use beyond the trial period. No specific price figure is published on the general product or pricing pages; obtaining an exact quote requires going through PortSwigger's order/quote flow.