PortSwigger Launches Burp AT Agentic AI to Find and Exploit Web Vulnerabilities

PortSwigger has launched Burp AT in public beta, introducing agentic AI capabilities to its widely used Burp Suite Professional platform.

The release marks a significant shift in how penetration testers approach web application security assessments, combining autonomous AI agents with over two decades of proven Burp Suite tooling.

Burp AT enables security professionals to deploy AI agents that autonomously investigate leads, analyze application behavior, and surface vulnerabilities within Burp Suite’s existing workflow.

PortSwigger Launches Burp AT Agentic AI

Rather than replacing human testers, the tool is designed to extend their capacity by handling time-intensive investigative work that would otherwise go unaddressed during engagements.

According to Fran Hutchings, who announced the launch on July 27, 2026, Burp AT is built around four core principles. Agents act through Burp’s battle-hardened tooling and draw on existing project context, including traffic, target structure, and prior discoveries, so they work alongside testers rather than starting from a blank prompt.

A library of purpose-built pentesting skills, developed with PortSwigger Research, gives agents structured methodologies to apply instead of improvising from general model knowledge.

Testers retain full control over autonomy, deciding what proceeds automatically, what requires approval, and what remains blocked, with that balance adjustable by task, target, and risk level.

Finally, scope and permission boundaries are enforced within Burp’s tooling layer itself, architecturally separate from the underlying AI model, with every request and decision logged for accountability.

During closed beta testing, one pentester used Burp AT to analyze 66,000 lines of minified JavaScript, a task that would have been infeasible to complete manually within a standard four-day engagement.

The agent reconstructed hidden endpoints and workflows referenced in the code, ultimately surfacing a critical vulnerability that PortSwigger says would otherwise have gone untested for at least another year.

One participating pentester described the experience as transformative, noting how much easier it made both testing and learning. PortSwigger frames Burp AT as addressing a trust problem rather than a capability problem.

Frontier AI models can already form hypotheses, execute exploits, and interpret results; the real challenge is ensuring that autonomy operates within verifiable, auditable constraints during professional engagements.

Because all agent actions route through Burp Suite’s infrastructure, testers retain reproducible evidence in the form of requests, responses, and logs, rather than relying solely on an AI’s self-reported account of what it did.

This distinction matters for engagements that require defensible, reproducible documentation. Burp AT is live now in public beta, exclusively for Burp Suite Professional users.

PortSwigger describes this as the first phase of a broader rollout, with plans to eventually introduce additional autonomy modes for enterprise teams, including more autonomous testing under standing policy with shared visibility and auditability, while preserving human-led testing as a permanent operating mode.

Founder and CEO Dafydd Stuttard emphasized that the public beta phase is intended to let real-world testing validate the tool’s reliability, stating that Burp Suite has earned trust through more than two decades of use against real applications, and that Burp AT, being new, still has to earn that same trust in the field.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories