Skip to content
Rush Commerce
Tools & Teardowns3 min read

Burp AT ships agentic pentesting into Burp Suite Pro

PortSwigger's Burp AT puts AI agents inside Burp Suite Professional, with scope enforced outside the model. What agentic pentesting means for your web app.

The tool that every web pentester already has open now runs AI agents. PortSwigger launched Burp AT in public beta for Burp Suite Professional, letting testers hand investigative work to agents that operate inside a real Burp project — your captured traffic, your site map, your existing findings. Two things follow for a small business running a web app: the cost of a competent security review just dropped, and so did the cost of probing you.

What actually happened

Per PortSwigger's announcement, Burp AT is available now in public beta to Burp Suite Professional users. Agents run investigations using Burp's own tooling and the project's accumulated context rather than acting as a chatbot bolted to the side.

The design decision worth stealing is where the guardrails live. Scope, tool access, and approval rules are enforced in Burp's tooling layer — architecturally separate from the model. Agents propose actions; Burp decides what is permitted; the human tester draws the conclusions. Requests and tool activity land in the project record. As Dafydd Stuttard, Burp Suite's creator and PortSwigger's CEO, framed it, the hard part isn't finding vulnerabilities — it's trusting the thing you pointed at a live target. That trust comes from the enforcement layer, not from asking the model nicely.

Why agentic pentesting matters for your business

Most small businesses have never had a real pentest. The honest reason is price: a competent human engagement costs more than the whole year's software budget. Agent-assisted testing compresses the tedious half of that work — enumerating endpoints, reading minified JavaScript, chasing parameter behavior across hundreds of requests — which pushes a scoped engagement into range for a company that previously only had a vulnerability scanner.

The other half of the sentence is the uncomfortable one. Reconnaissance getting cheaper is not a benefit reserved for the people you hire. Assume the enumeration pass against your login flow, your checkout, and your admin panel is now something a moderately motivated attacker can run at low cost.

Neither of those changes the fundamentals, and that's the point. Patch on a schedule you can name. Keep an inventory of what's actually exposed to the internet, including the staging box someone stood up in 2024. Put authentication in front of anything that touches customer data. Agents make the search cheap; they don't invent new categories of mistake. They just find the ones you already made, faster.

Key takeaways

  • Burp AT is in public beta for Burp Suite Professional, running agents inside real Burp project context
  • Scope, tool access, and approval rules are enforced in Burp's tooling layer, architecturally separate from the model
  • Agents propose, the tooling permits, the human concludes — copy that split for any agent you deploy
  • Cheaper reconnaissance cuts both ways: scoped security testing gets affordable, and so does probing you
  • Operator move: inventory what's actually internet-exposed, patch on a named schedule, authenticate anything touching customer data

You can't secure an app you can't inventory. We build and maintain web systems for operators — with a known dependency list, a patch cadence, and no forgotten staging box holding real customer records. See what we've shipped or have us audit what you're running.

Sources: PortSwigger via PR Newswire, Help Net Security.

  • #ai-agents
  • #pentesting
  • #web-security
  • #burp-suite
  • #appsec
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.