Official installer
RecommendedinstallerOfficialDownload the Windows installer for Community or Professional from the vendor's download page; the installer bundles a JRE.
Open official sourceIntercepting web proxy and testing workbench
Burp Suite sits between a browser and an application as a TLS-terminating proxy, so requests can be inspected, modified and repeated. It is the standard interactive tool for web application testing: Repeater for one request at a time, Comparer for two responses, Sequencer for token entropy, Logger/BPG for the trail.
Community Edition provides the manual workflow. Professional adds the scanner, Collaborator and project files, and is licensed software — check current terms and pricing on the vendor site rather than assuming what a blog post said.
Supported platforms
4
Documented install or usage guidance
Learning curve
intermediate
Difficulty of becoming productive, not of the underlying theory
Tags
proxy, http, web, repeater, interception
Dataset entry
burp-suite.ts
Reviewed 2026-01-07
Grouped by platform. Elevation requirements are marked per method.
Download the Windows installer for Community or Professional from the vendor's download page; the installer bundles a JRE.
Open official sourceNeeds elevated privileges (sudo / Administrator).
sudo apt install burpsuite
Package availability follows your distribution and enabled repositories. Entry revised 7 Jan 2026 — confirm the current release on the project's own download page.
Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.
Burp listens on 127.0.0.1:8080 by default; browser-level proxying (or the Burp extension) avoids changing system-wide settings.
google-chrome --proxy-server='http://127.0.0.1:8080' --user-data-dir=/tmp/burp-profile
Notes
Useful for feeding scripted traffic into the same workspace you are testing from.
curl -x http://127.0.0.1:8080 -k -s -o /dev/null -w '%{http_code}\n' https://app.internal/loginExport from Proxy → Options → CA certificate, then trust it only in the lab browser or VM you test with.
sudo security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain burp-der.cer
Notes
Professional Edition writes a .burp project file so configuration, site map and issues travel with the engagement.
java -jar burpsuite_pro.jar --project-file=engagement-01.burp
Notes
Inspect and repeat requests against in-scope endpoints.
Compare documented and observed behaviour of a JSON API.
See headers, cookies and status codes as they are actually sent.
Symptoms you will actually hit, with the cause and the legitimate fix.
Possible causes
Usual fix
Install the exported CA into that profile's store (or Firefox's own certificate manager, which ignores the OS store unless enabled).
Possible causes
Usual fix
Turn interception off, or use 'Intercept is off' by default and forward individual items to Repeater.
Possible causes
Usual fix
Pinning is a protection working as designed. Test the documented API instead, or ask the client about a debug build — do not try to defeat pinning outside scope.
Not documented yet: zap. Request an entry and it will link up automatically.Request a tool
Side-by-side
Where to verify anything on this page. External links open in a new tab.
ffuf cover adjacent parts of the same job.