Burp Suite (Community Edition) cheat sheet for web application testing
Installation & Setup
# Download from PortSwigger website
# https://portswigger.net/burp/communitydownload
# Install on Kali Linux (pre-installed)
sudo apt update && sudo apt install burpsuite
# Launch Burp Suite
burpsuite &
# Java requirement (Burp is Java-based)
java -version
# Command line launch with specific options
java -jar burpsuite_community.jar
# Increase memory allocation for large projects
java -Xmx4G -jar burpsuite_community.jar
# Set up browser proxy configuration
# Firefox: Preferences β Network Settings β Manual proxy
# HTTP Proxy: 127.0.0.1 Port: 8080
# Also proxy SSL: 127.0.0.1 Port: 8080
# Install CA certificate for HTTPS interception
# Visit http://burp in browser β Click "CA Certificate"
# Import certificate into browser trust storeProject Configuration & Workspace Setup
Proxy & Interception Phase
Spidering & Content Discovery
Manual Testing with Repeater
Automated Scanning (Limited in Community)
Intruder for Fuzzing & Brute Force
Sequencer for Session Token Analysis
Decoder & Comparer Utilities
Extender for Custom Functionality
Manual Testing Techniques
Workflow Optimization Tips
Common Keyboard Shortcuts
Useful Extensions for Community Edition
Reporting & Documentation
PreviousMetasploit cheat sheet for penetration testingNextOWASP ZAP cheat sheet for vulnerability assessment and penetration testing
Last updated