Best Burp Suite MCP Servers
Burp Suite is a leading cybersecurity tool developed by PortSwigger for web application security testing. It helps security professionals identify vulnerabilities through its various modules including Proxy, Scanner, Intruder, and Repeater.
Why this server?
Integrates with Burp Suite for security testing and traffic analysis as part of the bug bounty hunting platform.
AlicenseBqualityCmaintenanceAI-powered bug bounty hunting platform that integrates security tools (OWASP ZAP, Caido, Burp Suite) for automated reconnaissance, vulnerability testing, JavaScript analysis, and finding management with PostgreSQL storage.Last updated4728MITWhy this server?
Provides tools for interacting with Burp Suite, enabling AI agents to replay requests, search proxy history, send requests to Repeater/Intruder, generate and check Collaborator payloads, and synthesize sitemap from history, all with structured input to prevent malformed HTTP requests.
AlicenseAqualityCmaintenanceEnables structured HTTP request creation and local file ingestion for LLM integration with Burp Suite, reducing malformed requests and token costs.Last updated203MITWhy this server?
Provides a bridge for Burp Suite, enabling integration with the Burp Suite security testing platform for network interception and analysis.
Why this server?
Allows interaction with Burp Suite's REST API to trigger vulnerability scans, monitor scan progress, retrieve security findings, and query Burp's security knowledge base.
FlicenseAqualityCmaintenanceExposes Burp Suite's REST API to AI assistants, enabling users to trigger vulnerability scans, monitor progress, and manage security tasks through natural language. It also provides programmatic access to Burp's security knowledge base for querying vulnerability definitions and remediation advice.Last updated81Why this server?
Enables execution of Burp Suite commands for web application security testing, though with limitations on interactive features and UI-based interactions.
FlicenseAqualityCmaintenanceA tool that allows penetration testing through Kali Linux commands executed via a Multi-Conversation Protocol server, supporting security testing operations like SQL injection and command execution.Last updated553Why this server?
Adds raw HTTP probing, out-of-band detection via Collaborator, automated scanner findings, and proxy history evidence for security audits.
Alicense-qualityAmaintenanceA proxy server that wraps any MCP server, adding behavioral profiling, security scanning, risk gating, and safe execution to its tools.Last updated6Apache 2.0Why this server?
Allows routing scan traffic through Burp Suite to integrate with existing web security testing workflows and proxy analysis.
Flicense-qualityCmaintenanceAn MCP server for identifying SQL injection vulnerabilities in web applications using various techniques like error-based, time-based, and union-based scanning. It supports bulk URL processing, WAF bypass strategies, and authenticated testing across multiple database systems.Last updatedWhy this server?
Includes Burp Suite as one of the available penetration testing tools in the comprehensive security toolkit.
Flicense-qualityCmaintenanceProvides access to 20+ Kali Linux penetration testing tools including nmap, sqlmap, nikto, and hydra for authorized security testing and vulnerability assessment through a Docker-based MCP interface.Last updated1Why this server?
Provides integration with Burp Suite Pro API for web application security testing and vulnerability scanning.
Flicense-qualityCmaintenanceAI-powered autonomous penetration testing framework with 80+ professional security tools across reconnaissance, web application testing, exploitation, and forensics. Integrates with LM Studio for intelligent vulnerability assessment and automated security testing workflows.Last updated2