Teycir/BurpAPISecuritySuite

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and automated reconnaissance. Supports REST/GraphQL/SOAP APIs with Nuclei, Turbo Intruder, and external tool integration. OWASP API Top 10 coverage.

What it solves

BurpAPISecuritySuite is a comprehensive toolkit for API security testing that consolidates the functionality of over 10 separate extensions into a single Burp Suite extension. It addresses the complexity of API reconnaissance and vulnerability discovery by automating the capture, normalization, and fuzzing of REST, GraphQL, and SOAP APIs, specifically targeting the OWASP API Top 10.

How it works

The extension integrates directly into Burp Suite, automatically capturing and normalizing HTTP traffic to group similar endpoints. It provides a suite of specialized tabs for different testing phases:

  • Reconnaissance: Automatically extracts parameters, headers, and auth methods while detecting patterns like JWTs.
  • Fuzzing: Employs a library of 108+ attack vectors across 15 attack types (including BOLA and IDOR) with WAF evasion techniques.
  • Discovery: Integrates with external tools like Nuclei, Katana, HTTPX, and FFUF to expand the attack surface.
  • AI Integration: Exports structured "AI Bundles" containing API context and request payloads that can be fed into LLMs (like ChatGPT or Claude) for triage and payload planning.

Who it’s for

It is designed for API penetration testers, bug bounty hunters, and security researchers who use Burp Suite (Professional or Community Edition) to secure modern APIs.

Highlights

  • Consolidated Architecture: Reduces memory pressure and CPU overhead by combining multiple tools into one extension.
  • AI-Ready Exports: Generates structured data specifically for LLM-powered security analysis.
  • Deep Logic Testing: Includes counterfactual differentials and token lineage analysis to find gaps in session rotation and authentication.
  • Broad Tool Integration: Seamlessly connects with external binaries including SQLMap, Dalfox, and ApiHunter.
  • Automated Burp Integration: Auto-configures attack positions for Burp Intruder and generates ready-to-use Python scripts for Turbo Intruder.

Related

  • Project
  • Project
  • Project
  • Project
  • Project