
Burp AT Puts Agentic AI Inside Burp Suite Pentests
PortSwigger's Burp AT public beta gives pentesters AI agents that chase leads through Burp's own tooling, with per-task control over what runs unattended.
The Lead-Chasing Problem, Finally Automated
PortSwigger opened the public beta of Burp AT on July 29, 2026, bringing agentic AI into Burp Suite Professional. The framing is deliberately narrow and, I think, correct: these are agents that pursue defined investigative tasks using Burp's own tooling, the project's accumulated context, and a library of pentesting skills built with PortSwigger Research. It is not a button that finds bugs. It is a way to stop dropping leads.
- Public beta available to Burp Suite Professional users, announced July 29, 2026
- Agents act through Burp's existing tooling and draw on project context — captured traffic, target structure, and prior discoveries
- A skills library developed with PortSwigger Research encodes established pentesting techniques rather than leaving methodology to the model
- Autonomy is configurable per task, target, and risk level — testers decide what runs unattended, what needs approval, and what stays blocked
Why Context From the Project Is the Whole Design
Any tool can send requests at a target. What distinguishes a useful web pentest is knowing what has already been mapped, which parameters behaved oddly two hours ago, and how this endpoint relates to the authentication flow discovered earlier. That knowledge lives in the Burp project, and an agent that cannot read it is starting from zero on every task.
Wiring the agents into that context is what separates this from bolting a chatbot onto a proxy. The agent inherits the tester's situational awareness rather than rediscovering it, which means the leads it chases are the ones a human already thought were worth chasing but did not have hours to run down.
What Does "Configurable Autonomy" Actually Buy You?
Control over blast radius, which in offensive tooling is not a nicety. A web application pentest touches live systems, and the difference between an agent that enumerates and an agent that submits is the difference between a report and an incident. Letting the tester set that boundary per task, per target, and per risk level is the right granularity — the same engagement often contains a staging host where broad autonomy is fine and a production endpoint where every request should be approved.
There is also a professional-practice reason this matters. Pentesters work under scoping agreements that define what is permitted, and those agreements are specific. A tool that can be constrained to match the scope document is deployable; one that decides for itself is not, regardless of how good its findings are.
Is This Different From the AI Scanners Already on the Market?
In posture, yes. The prevailing pattern for AI in security tooling has been the autonomous scanner that runs a sweep and produces findings. Burp AT is explicitly built for human-led testing — the agents extend a tester who is already working, inside the tool that tester already uses, on a project that already contains their reasoning.
That is a meaningful bet on where the value sits. Automated sweeps are good at the well-understood classes of bug and reliably poor at the ones that require understanding what an application is for. Keeping the human in the loop and giving them agents to parallelize the tedious parts targets the actual bottleneck, which has always been tester hours rather than tester insight.
A Steady Month for Defensive Tooling
This lands in a busy stretch for the field. Our AI security coverage has followed XM Cyber open-sourcing three exposure hunting tools this week, Microsoft's Project Perception putting AI agents on defense, and the Open Secure AI Alliance uniting 40+ firms — all pointing at the same conclusion that agentic capability is arriving on the defensive side rather than only the offensive one.
PortSwigger says team and enterprise modes are planned, with more autonomous testing under established policies, shared visibility, and audit capability. Audit is the one to watch. Once agents are making requests against client systems, a defensible record of what ran and under whose authorization stops being a feature and starts being a requirement.
Sources: PortSwigger — July 29, 2026; Help Net Security — July 30, 2026; PR Newswire — July 29, 2026.
More Ai Security Stories
XM Cyber Open-Sources Three Exposure Hunting Tools
XM Cyber released three open-source tools on July 29 that hunt macOS XPC privilege escalation paths and overprivileged Oracle Cloud identities.
Microsoft Project Perception Puts AI Agents on Defense
Microsoft unveiled Project Perception on July 27, an agentic security platform with red, blue and green AI agents plus the MAI-Cyber-1-Flash model.
Open Secure AI Alliance Unites 40+ Firms on Defense
NVIDIA, Microsoft, IBM and 40+ others launched the Open Secure AI Alliance on July 27, pooling five open-source projects to defend AI agents.



