Intercepting web proxy: Burp's core proxy sits between the browser and target application, capturing every HTTP/HTTPS request and response so the tester can inspect, pause, and modify traffic in flight before it reaches the server or the browser.
02
Manual web application security testing: The suite is built around hands-on testing, giving the analyst full control to craft, replay, and tamper with requests to probe application logic, authentication, authorization, and input handling in ways automation cannot.
03
Automated web vulnerability scanning (Pro): The professional edition includes an automated scanner that crawls the application and audits it for a wide range of vulnerabilities, combining passive observation with active payload-based testing to confirm findings.
04
Web application crawler/spider: The crawler maps the target by following links and submitting forms, building a comprehensive site map of pages, endpoints, and parameters that defines the scope for further testing.
05
Repeater for manual request manipulation: Repeater lets the tester take any request, edit it freely, and re-send it repeatedly while observing how the response changes, making it the primary tool for manually exploring and confirming individual vulnerabilities.
Your plan caps how many capabilities are shown — upgrade to see the full list