Yogendra J.
YJ
Yogendra J.
Synack Red Team Member
Mid-Market (51-1000 emp.)
"A must have tool for security experts"
5/5
What do you like best about Burp Suite?

The preferred toolbox for web security testers is Burp Suite Professional. Use it to automate routine testing processes, and then use its specialised manual and semi-automated security testing capabilities to delve further. Burp Suite Professional can assist you in conducting tests for the OWASP Top 10 Vulnerabilities and the most recent hacking methods. Review collected by and hosted on G2.com.

What do you dislike about Burp Suite?

There isn't anything about it that I dislike. Review collected by and hosted on G2.com.

Pallab Jyoti B.
PB
Pallab Jyoti B.
Bugbounty hunter
Enterprise (> 1000 emp.)
"In my daily life I use it"
5/5
What do you like best about Burp Suite?

It's good to analyse behaviour of application and good api extension that we can integrate which make our work more easy Review collected by and hosted on G2.com.

What do you dislike about Burp Suite?

If we install many plugins it hang sometimes if you have less RAM and too much false results I encounter over automation scan Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
UI
Verified User in Information Technology and Services
Mid-Market (51-1000 emp.)
"User friendly solution for conducting web and mobile testing"
4.5/5
What do you like best about Burp Suite?

1) A wide range of plugins is available for diverse testing purposes, including SQL injections (SQLIs), cross-site scripting (XSS), and information disclosures, among others.

2) User-friendly tabs offer different functionalities to facilitate ease of use

3) Detailed descriptions and step-by-step remediation instructions are provided for identified issues Review collected by and hosted on G2.com.

What do you dislike about Burp Suite?

Sometimes the tool is incompatible with computers with low specifications, as it requires significant resources when scanning high scopes. Review collected by and hosted on G2.com.

Kiersten L.
KL
Kiersten L.
Technical Lead
Mid-Market (51-1000 emp.)
"Best Tool To Do Web Application Penetration Testing"
5/5
What do you like best about Burp Suite?

I am a Cyber Security Researcher, and BurpSuite has become a part of my day-to-day life. It helps me to test the security of our client websites. I use BurpSite Pro, which has awesome features that help me do web application testing easily. I can easily run an Automatic scan to find the common bug in the website, and it provides a detailed report of the scan and gives less false positives. The feature I love the most is intercepting all browser traffic and analyzing it. It has a feature called a repeater, I can easily capture the browser request, and without actually sending the request on the browser, I can repeat the send request multiple times. BurpSute has few attack modes, and the benefit of using BurpSuite pro is it has a few extra features. Like I can easily use a custom wordlist and increase the number of threads to run an attack. BurpSuite is the best and most powerful tool for security researchers. Review collected by and hosted on G2.com.

What do you dislike about Burp Suite?

There is nothing to dislike in the burp suite. Sometimes it crashes I use a high number of threads. But It can be managable. Other than this, it's an excellent tool. Review collected by and hosted on G2.com.

Gautam R.
GR
Gautam R.
Technology Analyst
Enterprise (> 1000 emp.)
"The greatest TOOL of all time for web security!!"
5/5
What do you like best about Burp Suite?

Burpsuite is the first go tool for any security professional for conducting web application penetration testing. The features of the tool are limitless. One such feature is extender tab which gives the security testers access to number of different extensions with different capabilities of performing the testing based on the technology/platform/type of testing etc. And not just that the extensions are again subjected to the ongoing research done by the modern security engineers who are continuously working on cutting edge technologies and developing the extensions.

The other features of the tool includes repeater, intruder, sequencer, decoder and many more which further improves the quality of security testing being conducted. Burpsuite is a powerful and an ultimate tool if one knows how to use it efficiently and just to give an idea that it definitely will take a long time to master it because of the vastness of the features and technology being used in the technology space today.

I have been using Burpsuite for almost 5+ years now for doing anything on the web security aspects and definitely recommend to go for it if you area of interest aligns with security. Review collected by and hosted on G2.com.

What do you dislike about Burp Suite?

There is nothing as such which I dislike about Burpsuite since it has such vast usage, capabilities and offers an amazing unified UI to make the most out of it.

There are community version of Burpsuite available with certain features being restricted which are only part of licensed Burpsuite pro/enterprise edition.

But if you are a beginner in web application security then community edition also has to offer a lots of learning in the beginning stages of testings but as you move towards the advance phases you will definitely feel the need of a licensed version which will cost around 399$ for a year. Review collected by and hosted on G2.com.

zalak p.
ZP
zalak p.
Information Technology Security Specialist
Small-Business (50 or fewer emp.)
"Best place for Ethical Hacking"
5/5
What do you like best about Burp Suite?

Decoder, Proxy, Request Modification, Header automation identification, Data comparison, and many more, I can say, for the particular best part. While forge on proxy, there would be the best part is JWT token identification. Review collected by and hosted on G2.com.

What do you dislike about Burp Suite?

UI is not good compared to OWASP ZAP, and some of the extensions do not work, so we cannot rely on the final auto report from Burp. Review collected by and hosted on G2.com.

AK
Akash K.
SEO Specialist
Mid-Market (51-1000 emp.)
"Tool For Security Researchers & Bug Bounty Hunters"
4.5/5
What do you like best about Burp Suite?

BurpSuite is a powerful tool to perform security testing. The best part is it shows fewer false positives in automated testing. It is easy to install and setup. Passive scan feature is really awesome, it helps to cover almost all the parts of the target you might miss. Can easily set the targets and scopes. BurpSuite intruder and repeater features are awesome. BurpSuite is lightweight and use fewer resources. Review collected by and hosted on G2.com.

What do you dislike about Burp Suite?

It's a complex and feature rich tool. It is not a beginner friendly, if you are new you will lost in the homepage. It required lots of tutorials to learn how to use the maximum potential of this tool. Easy to use but difficult to master. Its reporting feature is not the good it required more improvement in reporting section. Sometime scope and target feature does not work and gather junk information. Review collected by and hosted on G2.com.

Timo G.
TG
Timo G.
DevOps Engineer
Small-Business (50 or fewer emp.)
"Burpsuite, pentester's best friend"
5/5
What do you like best about Burp Suite?

Its the best paid web app penetration testing tool on the market. Review collected by and hosted on G2.com.

What do you dislike about Burp Suite?

I can't think of anything that I don't like about it. Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
IC
Verified User in Computer & Network Security
Enterprise (> 1000 emp.)
"Best tool for Penetration testing"
5/5
What do you like best about Burp Suite?

Burp has all the tools that is needed for Ethical hacking Review collected by and hosted on G2.com.

What do you dislike about Burp Suite?

the professional version is little expensive Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
UC
Verified User in Computer & Network Security
Mid-Market (51-1000 emp.)
"A must-have tool for any web-application pentester"
5/5
What do you like best about Burp Suite?

You can do pretty much all your web-pentest through burp suite, from fuzzing parameters to exploiting injections and decoding data. Burp does it all! Review collected by and hosted on G2.com.

What do you dislike about Burp Suite?

There's no complains about the tool, everything you need is in there. The only thing is that you will have to study quite a lot to understand all the functionalities. I've been using the tool for 1 year and I feel I still have a lot to learn. Review collected by and hosted on G2.com.