dreadnode/burpference
A research project to add some brrrrrr to Burp
Captures in-scope HTTP requests from Burp's proxy history and sends them to remote LLM APIs (or locally-hosted models via Ollama) for offensive security analysis, with color-coded severity findings synced to Burp's native issue reporting. Built as a Jython extension with configurable system prompts, API providers, and a dedicated Scanner tab for analyzing URLs and OpenAPI specifications. Features persistent finding storage in JSON format, comprehensive inference logging, and support for custom model provider configurations to avoid external API costs and rate limits.
207 stars.
Stars
207
Forks
11
Language
Python
License
Apache-2.0
Category
Last pushed
Feb 16, 2026
Commits (30d)
0
Get this data via API
curl "https://pt-edge.onrender.com/api/v1/quality/llm-tools/dreadnode/burpference"
Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.
Higher-rated alternatives
samber/go-playground-mcp
🤹 A MCP server to execute Go code in Go Playground and generate shareable URLs
Algiras/skillz
Self-extending MCP server - build and execute custom AI tools at runtime
pluveto/daan
✨Lightweight LLM Client with MCP 🔌 & Characters 👤
R00T-Kim/awesome-offensive-mcp
A curated list of Offensive Security MCP Servers for Red Teaming & Pentesting.
damienbod/McpSecurity
Research MCP, OAuth, security