Exploring issues with AI

Explore Issue is an AI-powered pentesting assistant that performs automated follow-up investigations on vulnerabilities identified by Burp Scanner. It helps you to efficiently validate issues, generate proof-of-concept (PoC) exploits, and uncover additional attack vectors, freeing you up to focus on more complex analysis work.

How Explore Issue works

When attempting to explore an issue, Burp analyzes the context of the vulnerability and determines the best strategy to explore it.

The AI can:

Note

Burp's AI-powered features require AI credits. If your credits run out while exploring an issue, the task pauses until you top up. For details, see AI Credits.

Running an explore task

You can only explore issues that Burp Scanner has previously identified. For more information on running scans in Burp Suite, see Running scans.

To run an AI-powered explore task:

  1. Select a scan or live audit task.

  2. Go to the Issues tab and select the issue you want to explore.

  3. From the Advisory tab, click Explore issue. Burp starts to explore the issue and adds a card to the Tasks list on the Dashboard.

  4. Click the task card and select the Task progress tab. Burp displays the results of the task as a series of steps.

Once the AI determines that the task is complete, Burp displays a task summary outlining key findings, impact, and potential next steps.

Tip

To pause the task, click the pause icon on the task card.

Completed explore tasks are saved to your project file.

Reviewing results

To view the results of an explore task:

  1. Go to the Dashboard.

  2. Select the task from the Tasks list.

Each explore task contains two tabs:

Task progress

This tab provides a step-by-step log of how Burp attempted to exploit the vulnerability. It logs every action taken, enabling you to review and reproduce the AI's methodology.

Depending on the tools the AI used in a particular step, different options are available:

To navigate between steps, select them in the left-hand panel. You can also use the search bar.

Once the AI determines that the task is complete, it generates an executive summary that consolidates key findings, making it easy to review task results. Burp displays this information in the Task summary panel at the top of the tab.

Logger

The Logger tab contains a comprehensive record of all HTTP requests and responses generated during the task.

Ending an explore task

To manually end an explore task, select the task and click Finish task. Explore tasks end automatically if the AI determines that it cannot progress any further.

Trust and transparency in Explore Issue

Explore Issue is designed to be fully transparent and reproducible, ensuring you can trust the AI's findings and validate them manually.

Every AI-driven action in Explore Issue is governed by these core principles:

Note

For more details on AI security and data handling, see AI security, privacy and data handling.