Pular para o conteúdo principal

Burp Suite Pro

50 hours 8 Modules 25+ Labs Beginner to Advanced

Course Description

Burp Suite is the industry standard for web application security testing. This course takes you from basics to advanced techniques including custom extensions and automation.


Learning Objectives

By the end of this course, you will be able to:

  1. Configure Burp Suite for professional testing
  2. Intercept and modify HTTP/HTTPS traffic
  3. Automate testing with Intruder and Scanner
  4. Create custom extensions in Python/Java
  5. Integrate Burp with other tools
  6. Report findings using Burp's reporting features

Modules

Module 1: Burp Suite Fundamentals (6h)

  • Installation and configuration
  • Proxy setup and certificates
  • Target scope configuration
  • Browser integration
  • Project management

Module 2: Proxy & Intercept (6h)

  • Request interception
  • Response modification
  • Match and replace rules
  • WebSocket testing
  • HTTP/2 support

Module 3: Repeater & Comparer (5h)

  • Manual request testing
  • Response comparison
  • Encoding/decoding
  • Request chaining

Module 4: Intruder Mastery (8h)

  • Attack types explained
  • Payload generation
  • Cluster bomb attacks
  • Grep and extract
  • Rate limiting bypass

Module 5: Scanner & Active Testing (8h)

  • Scan configuration
  • Audit items selection
  • Crawling strategies
  • Issue management
  • False positive handling

Module 6: Sequencer & Decoder (4h)

  • Token analysis
  • Entropy testing
  • Encoding detection
  • Custom encoding

Module 7: Extensions Development (8h)

  • BApp Store extensions
  • Python extension basics
  • Java extension development
  • Custom scanner checks
  • Custom Intruder payloads

Module 8: Professional Workflows (5h)

  • Engagement methodology
  • Collaboration features
  • Reporting templates
  • CI/CD integration
  • Burp Enterprise

Tools

ToolPurpose
Burp Suite ProMain platform
CollaboratorOut-of-band testing
Logger++Enhanced logging
AutorizeAuthorization testing
JWT EditorToken manipulation

Quick Navigation