Blog, Portswigger Blog
Introducing Burp AT: Agentic AI, Built on Two Decades of Burp Suite | PortSwigger
Introducing Burp AT: Agentic AI, Built on Two Decades of Burp Suite
This article was originally published by LOGON’s partner PortSwigger. Click here to view the original article.
While in public beta, Burp AT is accessed alongside Burp Suite Professional.
With an active Pro licence, you can get started with it in minutes. Launch Burp AT using the option below. You’ll be asked to sign in with your PortSwigger account, the same one tied to your Pro subscription.
Burp AT will not work without the latest Burp Suite Professional.
Get your subscription here.
AI can already find and exploit vulnerabilities. The question is no longer whether the technology is capable. It is what kind of AI you can trust against systems you are responsible for testing.
Today, PortSwigger is launching Burp AT in public beta for Burp Suite Professional users.
Burp AT lets you put agentic AI to work inside Burp Suite. Agents pursue the tasks you hand them using Burp’s specialist tools, the context gathered in your project, and pentesting skills developed with PortSwigger Research — all while you stay in the loop for scope, judgment, and conclusions.
Pentesting Takes More Than a Capable Model
Frontier AI models can find and exploit vulnerabilities. Agents can form hypotheses, act through tools, interpret what they learn, and decide what to try next.
But a professional pentest requires more than capable reasoning. It requires:
| Requirement | How Burp AT Delivers |
|---|---|
| Reliable specialist tools | Agents act through the same battle-hardened tooling professional pentesters have trusted for over 20 years |
| Access to relevant context | Agents draw on traffic, target structure, issues, and discoveries already in your Burp project |
| Purpose-built methodology | A library of pentesting skills developed with PortSwigger Research |
| Boundaries the model cannot bypass | Scope, tool access, and approval rules live in Burp’s tooling layer, architecturally separate from the model |
Deliver More from Every Pentest
The fastest way to see the value is to hand Burp AT a lead you would usually run out of time to chase.
Real-world result: One pentester used Burp AT against 66,000 lines of minified JavaScript they could never have read by hand inside a four-day engagement. It helped surface a critical vulnerability that would otherwise have gone untested for at least another year.
The First Phase of Burp AT
Available today to Burp Suite Professional users:
| Feature | What It Means |
|---|---|
| Human-led workflow | Agents take on investigative work while you control scope, judgment, and conclusions |
| Burp integration | Work runs through Burp; requests, responses, and evidence are tracked and reproducible |
| Public beta | Professional testers can put it to work and help shape what it becomes |
Ready to put agentic AI to work in your pentesting?
LOGON Software Asia – the trusted PortSwigger partner in Asia – offers:
-
✅ Preferred pricing
-
✅ Priority support
-
✅ Local expertise
-
✅ Guidance on Burp Suite deployment
Burp Suite Professional
The gold standard toolkit for penetration testers
Get Started with Portswigger
Contact us to discover how you can gain complete visibility of your attack surface, empowering your developers.





