Scanning web applications

This section explains how to configure and run web application scans in Burp Suite Professional.

When scanning web applications, Burp automatically catalogs and analyzes the application's structure and traffic, including any REST, SOAP, and GraphQL APIs that it discovers. It adds all requests, responses, and resources found during the scan to the site map.

Related pages

For information on how to do a standalone scan based on an OpenAPI definition or SOAP WSDL, see Running API-only scans.

Burp Scanner enables you to launch web application scans in the following ways:

Related pages

This section focuses on launching one-off scans in Burp Suite Professional.

In this section