PortSwigger Introduces Burp AT: AI Agents for Web Penetration Testing

PortSwigger has unveiled Burp AT, a new feature in public beta that integrates agentic AI capabilities into Burp Suite Professional. This development allows penetration testers to assign specific investigative tasks to AI agents while maintaining full control over the testing process.

Burp AT is built on four foundational principles to ensure effective and secure AI-assisted testing. Firstly, the AI agents operate within Burp Suite’s established tools, utilizing existing project data such as captured traffic and target structures. Secondly, these agents are equipped with a growing library of specialized penetration testing skills, providing them with structured methodologies developed by PortSwigger’s research team. Thirdly, testers have the ability to control the autonomy of the agents, deciding which actions can be executed independently, which require approval, and which are restricted. Lastly, all actions performed by the agents are enforced and logged by Burp Suite’s tooling layer, ensuring transparency and preventing unauthorized activities.

During the closed beta phase, Burp AT demonstrated its practical value. In one instance, a penetration tester used the AI agent to analyze 66,000 lines of minified JavaScript within a four-day engagement. The agent reconstructed endpoints and workflows from the obfuscated code, identifying suspicious, unauthenticated areas for further investigation. This process led to the discovery of a critical vulnerability that might have otherwise remained undetected for an extended period. The tester described the experience as transformative, enhancing both testing efficiency and skill development.

PortSwigger emphasizes that Burp AT is designed to augment human-led workflows rather than replace them. The AI agents propose actions, but the human tester retains decision-making authority, ensuring that the testing process remains under professional oversight. This approach addresses concerns about the reliability and accountability of AI in professional testing environments.

Looking ahead, PortSwigger plans to expand Burp AT’s capabilities to support team and enterprise-level operations. Future iterations may include more autonomous testing modes under predefined policies, with shared visibility and audit trails, while maintaining the option for human-led testing.

PortSwigger’s Founder and CEO, Dafydd Stuttard, highlighted the importance of building trust in new technologies. He noted that while Burp Suite has established credibility over two decades, Burp AT is a new addition that must earn user confidence through real-world application. To facilitate this, the company has opted for a public beta release, inviting testers to evaluate and contribute to the tool’s development.

Burp AT is now available to all Burp Suite Professional users, offering a practical entry point for integrating agentic AI into existing testing workflows without compromising control over sensitive engagements.

The introduction of Burp AT marks a significant advancement in the field of web application security testing. By combining AI capabilities with human expertise, PortSwigger aims to enhance the efficiency and effectiveness of penetration testing. As the tool evolves, it will be important to monitor how it balances automation with the critical need for human judgment in security assessments.