Skip to content

Burp Suite Professional

Burp Suite Professional is the web application security testing platform built by PortSwigger Ltd., used by penetration testers and AppSec teams to find and confirm vulnerabilities in applications and APIs. It combines an intercepting proxy, Burp Scanner, Burp Repeater and Burp Intruder in one environment, with out-of-band detection through Burp Collaborator and hundreds of extensions in the BApp Store. It is licensed as an annual subscription, per named user, and runs on Windows, macOS and Linux.

Fabricantes: PortSwigger Ltd.
Category: Rede/Segurança
Learn more about Burp Suite Professional

Request a Quote

What is Burp Suite Professional?

Burp Suite Professional is the web application security testing platform built by PortSwigger Ltd., used by offensive security professionals to find and confirm vulnerabilities in applications and APIs before an attacker exploits them. It is an application installed on the analyst's workstation that acts as an intercepting proxy between browser and server: all HTTP and HTTPS traffic flows through Burp Proxy, where every request can be paused, edited and reissued. That same captured request moves on to manual work in Burp Repeater, to automated attacks in Burp Intruder, or to scanning in Burp Scanner, always within the same authenticated session and scope. According to PortSwigger, Burp Suite is used by more than 90,000 security professionals and 18,000 organisations across more than 170 countries. In practice it replaces the mix of generic scanner plus in-house scripts with a single environment where automated testing produces the lead and manual testing produces reproducible evidence.

Key features of Burp Suite Professional

The tools in Burp Suite Professional share the same site map, scope and session, so an automated finding can be pursued manually without repeating the authentication flow:

  • Burp Proxy — intercepts HTTP and HTTPS traffic between browser and application, letting you pause, edit and reissue each request in real time.
  • Burp Scanner — active and passive scanning covering the OWASP Top 10 categories, including SQL injection, reflected and DOM-based cross-site scripting, SSRF, XXE and path traversal.
  • Burp Repeater — manually reissues and modifies any captured request to confirm a hypothesis without replaying the whole navigation path.
  • Burp Intruder — automated attacks at full speed, used for parameter fuzzing, identifier enumeration and controlled credential testing.
  • Burp Collaborator — out-of-band (OAST) detection of flaws with no visible response in the application, such as blind SSRF and asynchronous injection.
  • DOM Invader — built-in browser that traces data flows through the DOM to locate DOM-based XSS and client-side prototype pollution.
  • BApp Store and Montoya API — hundreds of ready-to-install extensions plus an official API for writing your own in Java or Python through Jython.
  • BChecks and Burp AI — declarative scan checks written by your own team, and AI features that explain reported issues, consuming credits.

Burp Sequencer, which analyses session token randomness, plus Burp Decoder, Burp Comparer and Burp Organizer complete the toolkit. Burp Scanner also accepts OpenAPI, GraphQL and SOAP definitions to cover API endpoints that never appear during navigation.

Benefits of Burp Suite Professional

The time saving comes continuity between scanning and manual testing: Burp Scanner surfaces the lead and the analyst opens that same request in Burp Repeater with the session still valid, without reauthenticating. The cost of handling false positives drops because every issue carries the request and response that prove it — the developer reproduces the flaw with the same pair of packets. Coverage of invisible flaws comes Burp Collaborator, which supplies a controlled external target for blind SSRF and injections that only fire after the scan ends. Adaptation to the target comes the BApp Store and the Montoya API, which handle signing schemes or proprietary formats without dropping automated testing. And consistency across analysts comes BChecks, which turn one specialist's recurring finding into a check the whole team runs.

Who Burp Suite Professional is for

Burp Suite Professional is the working tool of penetration testers, offensive security analysts, consultants and AppSec engineers who test applications by hand. Inside companies the typical user sits in the information security team or in a red team cell; in consultancies it is whoever runs the engagement and signs the report. Three concrete scenarios: delivering a web application penetration test with reproducible evidence for a client; validating an application before exposing its API to partners; and meeting periodic intrusion testing requirements under PCI DSS or ISO 27001 with in-house seats, reducing dependence on an external audit each cycle.

What sets Burp Suite Professional apart

The difference a conventional automated scanner lies in control over the request: the analyst intercepts, edits byte by byte and reissues the call, which makes it possible to test business logic, permission chaining and race conditions that no generic scan describes. The second differentiator is the extension ecosystem: the Montoya API and the BApp Store adapt the tool to targets with non-standard authentication or serialisation, and the same Burp Scanner engine also powers Burp Suite DAST, which makes a pipeline finding reproducible on the analyst's workstation without translating between formats.

System requirements

Burp Suite Professional is a Java application shipped as installers for Windows, macOS and Linux, and it comes preinstalled in the Kali Linux distribution. It uses an embedded Chromium browser for traffic interception and for DOM Invader, removing the need to configure a proxy in the system browser. Memory usage tracks the size of the target: a large site map with concurrent active scanning demands more RAM allocated to the JVM than occasional manual testing. Python extensions rely on Jython; Java extensions use the Montoya API.

Editions and modules

Burp Suite Professional is the commercial edition aimed at manual testing and analyst-driven scanning, and it is the edition OSB Software supplies on this page. PortSwigger also distributes Burp Suite Community Edition, free of charge, without the active Burp Scanner and with a speed-limited Burp Intruder — useful for learning, not for professional work.

For automated scanning at scale, pipeline integration and application portfolio management, PortSwigger sells Burp Suite DAST — previously named Burp Suite Enterprise Edition — a separate product with its own licensing and no upgrade path Professional. Burp AI features are consumed as credits inside Professional itself. The Web Security Academy, with more than 190 interactive labs, is free, and the Burp Suite Certified Practitioner certification is purchased directly PortSwigger.

How much does Burp Suite Professional cost?

Burp Suite Professional is licensed per named user, as an annual subscription, under contracts that can run for one year or several. There is no perpetual licence. The counting rule is explicit in PortSwigger's documentation: a user means an individual person, not a concurrent user, an installation or a machine — a team of six analysts where only three use the tool at the same time consumes six subscriptions, not three. The same user, on the other hand, may activate the licence on more than one computer within the reasonable use the vendor allows.

There is no single list price because the investment depends on sizing: number of named users, contract term, whether it is a new purchase or a renewal, expected Burp AI credit consumption, and whether automated pipeline scanning is required — which is the scope of Burp Suite DAST, not Professional. To buy Burp Suite Professional in Brazil, OSB Software scopes this with you, sends the commercial proposal, issues the Brazilian invoice and delivers the licences; request a quote to receive the exact figure for your scenario.

Frequently asked questions

Can Burp Suite Professional be used in CI/CD pipelines? No. PortSwigger's licence terms restrict the use of Professional in continuous integration and continuous delivery pipelines. Automated scanning inside the pipeline is the scope of Burp Suite DAST.

Can two people share the same Burp Suite Professional licence? No. According to PortSwigger, counting is per individual person, and one subscription cannot be split between several users even if only one of them uses the tool at a time.

Can Burp Suite Professional be installed on more than one computer? Yes. The same user may activate their licence on more than one machine, subject to the activation limits PortSwigger reserves the right to apply.

Does the Burp Suite Certified Practitioner exam require a Professional licence? Yes, the exam is taken with Burp Suite Professional active. The Web Security Academy study material, with more than 190 labs, is free and does not depend on the licence.

Why buy Burp Suite Professional OSB Software?

OSB Software is an official PortSwigger partner in Brazil and supplies 100% genuine Burp Suite Professional licenses to companies, with Brazilian invoicing, local contracting in Portuguese and full legal compliance — the safe way to buy imported software under a Brazilian corporate entity, with no risk of irregular licensing.

When you buy Burp Suite Professional OSB Software, you get:

  • Consultative, specialist support — specialists who size your named-user licensing to your actual operation, avoiding over- or under-buying.
  • Fast, secure processes — purchase order to delivery of genuine licenses, traceable at every step.
  • Dedicated commercial follow-up — quote to delivery and renewal, with advance notice before your license expires.
  • Invoicing that fits your company — Brazilian invoicing and terms adapted to your corporate procurement process.
  • Proven track record — thousands of customers served across Brazil.

If you are looking for where to buy Burp Suite Professional in Brazil with legal certainty and properly licensed imported software, request a quote: OSB Software delivers reliable technology, qualified support and a simple, transparent purchase.

We help you choose

Not sure which software
you need?

Tell us about your need and our team helps you choose the ideal solution — from over 10,000 options in our catalog.