Optimized Burp Suite Configuration

Elevate your web application penetration testing. Create a new optimized configuration from our base template, or upload your existing configuration to make rapid adjustments.

threatlance-burp-config.json
{
    "bambda": {
        "http_history_display_filter": {
            "bambda": "return true;",
            "bambda_id": "",
            "bambda_name": ""
        },
        "logger_capture_filter": {
            "bambda": "return true;",
            "bambda_id": "",
            "bambda_name": ""
        },
        "logger_display_filter": {
            "bambda": "return true;",
            "bambda_id": "",
            "bambda_name": ""
        },
        "sitemap_display_filter": {
            "bambda": "return true;",
            "bambda_id": "",
            "bambda_name": ""
        },
        "web_sockets_history_display_filter": {
            "bambda": "return true;",
            "bambda_id": "",
            "bambda_name": ""
        }
    },
    "logger": {
        "capture_filter": {
            "by_mime_type": {
                "capture_css": true,
                "capture_flash": true,
                "capture_html": true,
                "capture_images": true,
                "capture_other_binary": true,
                "capture_other_text": true,
                "capture_script": true,
                "capture_xml": true
            },
            "by_request_type": {
                "capture_only_in_scope_items": false,
                "capture_only_parameterized_requests": false,
                "discard_items_without_responses": false
            },
            "by_search": {
                "case_sensitive": false,
                "negative_search": false,
                "regex": false,
                "term": ""
            },
            "by_status_code": {
                "capture_2xx": true,
                "capture_3xx": true,
                "capture_4xx": true,
                "capture_5xx": true
            },
            "by_tool": {
                "capture_burp_ai": true,
                "capture_extender": true,
                "capture_intruder": true,
                "capture_proxy": true,
                "capture_repeater": true,
                "capture_scanner": true,
                "capture_sequencer": true,
                "capture_target": true
            },
            "capture_enabled": true,
            "capture_memory_limit_mb": 50,
            "filter_mode": "SETTINGS",
            "limit_request_response_size": {
                "capture_requests_up_to": "1MB",
                "capture_responses_up_to": "1MB"
            },
            "session_handling": {
                "ignore_session_handling_requests": false
            },
            "task_capture_memory_limit_mb": 10
        },
        "display_filter": {
            "by_annotation": {
                "show_only_commented_items": false,
                "show_only_highlighted_items": false
            },
            "by_file_extension": {
                "hide_items": [
                    "js",
                    "gif",
                    "jpg",
                    "png",
                    "ico",
                    "css",
                    "woff",
                    "woff2",
                    "ttf",
                    "svg"
                ],
                "hide_specific": false,
                "show_items": [
                    "asp",
                    "aspx",
                    "jsp",
                    "php"
                ],
                "show_only_specific": false
            },
            "by_mime_type": {
                "show_css": true,
                "show_flash": true,
                "show_html": true,
                "show_images": true,
                "show_other_binary": true,
                "show_other_text": true,
                "show_script": true,
                "show_xml": true
            },
            "by_request_type": {
                "hide_items_without_responses": false,
                "show_only_in_scope_items": false,
                "show_only_parameterized_requests": false
            },
            "by_search": {
                "case_sensitive": false,
                "negative_search": false,
                "regex": false,
                "term": ""
            },
            "by_status_code": {
                "show_2xx": true,
                "show_3xx": true,
                "show_4xx": true,
                "show_5xx": true
            },
            "by_tool": {
                "show_burp_ai": true,
                "show_extender": true,
                "show_intruder": true,
                "show_proxy": true,
                "show_repeater": true,
                "show_scanner": true,
                "show_sequencer": true,
                "show_target": true
            },
            "filter_mode": "SETTINGS"
        }
    },
    "organiser": {
        "display_filter": {
            "by_annotation": {
                "show_only_highlighted_items": false,
                "show_only_notes_items": false
            },
            "by_file_extension": {
                "hide_items": [
                    "js",
                    "gif",
                    "jpg",
                    "png",
                    "ico",
                    "css",
                    "woff",
                    "woff2",
                    "ttf",
                    "svg"
                ],
                "hide_specific": false,
                "show_items": [
                    "asp",
                    "aspx",
                    "jsp",
                    "php"
                ],
                "show_only_specific": false
            },
            "by_mime_type": {
                "show_css": true,
                "show_flash": true,
                "show_html": true,
                "show_images": true,
                "show_other_binary": true,
                "show_other_text": true,
                "show_script": true,
                "show_xml": true
            },
            "by_request_type": {
                "hide_items_without_responses": false,
                "show_only_in_scope_items": false,
                "show_only_parameterized_requests": false
            },
            "by_search": {
                "case_sensitive": false,
                "negative_search": false,
                "regex": false,
                "term": ""
            },
            "by_status_code": {
                "show_2xx": true,
                "show_3xx": true,
                "show_4xx": true,
                "show_5xx": true
            },
            "by_tool": {
                "burp_ai": true,
                "extensions": true,
                "intruder": true,
                "logger": true,
                "proxy": true,
                "repeater": true,
                "scanner": true,
                "sequencer": true,
                "target": true
            },
            "status": {
                "done": true,
                "ignored": true,
                "in_progress": true,
                "new": true,
                "postponed": true
            }
        }
    },
    "project_options": {
        "ai": {
            "enabled": true,
            "use_user_options": true
        },
        "connections": {
            "out_of_scope_requests": {
                "advanced_mode": false,
                "drop_all_out_of_scope": false,
                "exclude": [],
                "include": [],
                "scope_option": "suite"
            },
            "platform_authentication": {
                "credentials": [],
                "do_platform_authentication": true,
                "prompt_on_authentication_failure": false,
                "use_user_options": true
            },
            "socks_proxy": {
                "dns_over_socks": false,
                "host": "",
                "host_bypass_list": [],
                "password": "",
                "port": 0,
                "use_proxy": false,
                "use_user_options": true,
                "username": ""
            },
            "timeouts": {
                "connect_timeout": 120000,
                "domain_name_resolution_timeout": 300000,
                "failed_domain_name_resolution_timeout": 60000,
                "normal_timeout": 120000,
                "open_ended_response_timeout": 10000
            },
            "upstream_proxy": {
                "servers": [],
                "use_user_options": true
            }
        },
        "dns": {
            "hostname_resolution": [],
            "lookup_policy": "use_system_default"
        },
        "http": {
            "http1": {
                "enable_keep_alive": false
            },
            "http2": {
                "enable_http2": true
            },
            "redirections": {
                "understand_3xx_status_code": true,
                "understand_any_status_code_with_location_header": false,
                "understand_javascript_driven": false,
                "understand_meta_refresh_tag": true,
                "understand_refresh_header": true
            },
            "status_100_responses": {
                "remove_100_continue_responses": false,
                "understand_100_continue_responses": true
            },
            "streaming_responses": {
                "scope_advanced_mode": false,
                "store": true,
                "strip_chunked_encoding_metadata": true,
                "urls": [],
                "use_text_event_stream_header": true
            }
        },
        "misc": {
            "collaborator_server": {
                "location": "",
                "poll_over_unencrypted_http": false,
                "polling_location": "",
                "type": "default",
                "use_user_config": true
            },
            "embedded_browser": {
                "allow_running_without_sandbox": false,
                "disable_gpu": false
            },
            "logging": {
                "requests": {
                    "all_tools": "",
                    "extender": "",
                    "intruder": "",
                    "proxy": "",
                    "repeater": "",
                    "scanner": "",
                    "sequencer": ""
                },
                "responses": {
                    "all_tools": "",
                    "extender": "",
                    "intruder": "",
                    "proxy": "",
                    "repeater": "",
                    "scanner": "",
                    "sequencer": ""
                }
            },
            "scheduled_tasks": {
                "tasks": []
            }
        },
        "resource_pools": {
            "custom_resource_pools": [],
            "default_resource_pool": {
                "auto_backoff": true,
                "auto_backoff_after_429_status_returned": true,
                "auto_backoff_after_503_status_returned": false,
                "concurrent_request_limit": 10,
                "concurrent_request_limit_enabled": true,
                "custom_auto_backoff_status_codes": [],
                "custom_auto_backoff_status_codes_enabled": false,
                "name": "Default resource pool",
                "throttle_interval_enabled": false,
                "throttle_interval_millis": 500,
                "throttle_random_enabled": false
            }
        },
        "sessions": {
            "cookie_jar": {
                "monitor_burp_ai": false,
                "monitor_extender": false,
                "monitor_intruder": false,
                "monitor_proxy": true,
                "monitor_repeater": false,
                "monitor_scanner": false,
                "monitor_sequencer": false
            },
            "macros": {
                "macros": []
            },
            "session_handling_rules": {
                "rules": [
                    {
                        "actions": [
                            {
                                "enabled": true,
                                "match_cookies": "all_except",
                                "type": "use_cookies"
                            }
                        ],
                        "description": "Use cookies from Burp's cookie jar",
                        "enabled": true,
                        "exclude_from_scope": [],
                        "include_in_scope": [],
                        "named_params": [],
                        "restrict_scope_to_named_params": false,
                        "tools_scope": [
                            "Scanner"
                        ],
                        "url_scope": "all",
                        "url_scope_advanced_mode": false
                    }
                ]
            }
        },
        "ssl": {
            "client_certificates": {
                "certificates": [],
                "use_user_options": true
            },
            "negotiation": {
                "allow_unsafe_renegotiation": false,
                "disable_ssl_session_resume": false,
                "enabled_ciphers": [],
                "enabled_protocols": [],
                "enforce_upstream_trust": false,
                "tls_negotiation_behavior": "use_all_supported"
            }
        }
    },
    "proxy": {
        "http_history_display_filter": {
            "by_annotation": {
                "show_only_commented_items": false,
                "show_only_highlighted_items": false
            },
            "by_file_extension": {
                "hide_items": [
                    "js",
                    "gif",
                    "jpg",
                    "png",
                    "ico",
                    "css",
                    "woff",
                    "woff2",
                    "ttf",
                    "svg"
                ],
                "hide_specific": true,
                "show_items": [
                    "asp",
                    "aspx",
                    "jsp",
                    "php"
                ],
                "show_only_specific": false
            },
            "by_listener": {
                "port": ""
            },
            "by_mime_type": {
                "show_css": false,
                "show_flash": true,
                "show_html": true,
                "show_images": false,
                "show_other_binary": true,
                "show_other_text": true,
                "show_script": true,
                "show_xml": true
            },
            "by_request_type": {
                "hide_items_without_responses": false,
                "show_only_in_scope_items": false,
                "show_only_parameterized_requests": false
            },
            "by_search": {
                "case_sensitive": false,
                "negative_search": false,
                "regex": false,
                "term": ""
            },
            "by_status_code": {
                "show_2xx": true,
                "show_3xx": true,
                "show_4xx": true,
                "show_5xx": true
            },
            "filter_disabled": false,
            "filter_mode": "SETTINGS"
        },
        "intercept_client_requests": {
            "automatically_fix_missing_or_superfluous_new_lines_at_end_of_request": false,
            "automatically_update_content_length_header_when_the_request_is_edited": true,
            "do_intercept": true,
            "rules": [
                {
                    "boolean_operator": "and",
                    "enabled": true,
                    "match_condition": "(^gif$|^jpg$|^png$|^css$|^js$|^ico$|^svg$|^eot$|^woff$|^woff2$|^ttf$)",
                    "match_relationship": "does_not_match",
                    "match_type": "file_extension"
                },
                {
                    "boolean_operator": "or",
                    "enabled": false,
                    "match_relationship": "contains_parameters",
                    "match_type": "request"
                },
                {
                    "boolean_operator": "or",
                    "enabled": false,
                    "match_condition": "(get|post)",
                    "match_relationship": "does_not_match",
                    "match_type": "http_method"
                },
                {
                    "boolean_operator": "and",
                    "enabled": false,
                    "match_relationship": "is_in_target_scope",
                    "match_type": "url"
                }
            ]
        },
        "intercept_server_responses": {
            "automatically_update_content_length_header_when_the_response_is_edited": true,
            "do_intercept": false,
            "rules": [
                {
                    "boolean_operator": "or",
                    "enabled": true,
                    "match_condition": "text",
                    "match_relationship": "matches",
                    "match_type": "content_type_header"
                },
                {
                    "boolean_operator": "or",
                    "enabled": false,
                    "match_relationship": "was_modified",
                    "match_type": "request"
                },
                {
                    "boolean_operator": "or",
                    "enabled": false,
                    "match_relationship": "was_intercepted",
                    "match_type": "request"
                },
                {
                    "boolean_operator": "and",
                    "enabled": false,
                    "match_condition": "^304$",
                    "match_relationship": "does_not_match",
                    "match_type": "status_code"
                },
                {
                    "boolean_operator": "and",
                    "enabled": false,
                    "match_relationship": "is_in_target_scope",
                    "match_type": "url"
                }
            ]
        },
        "intercept_web_sockets_messages": {
            "client_to_server_messages": true,
            "intercept_in_scope_only": false,
            "server_to_client_messages": true
        },
        "match_replace_disable_out_of_scope": false,
        "match_replace_rules": [
            {
                "category": "regex",
                "comment": "Emulate Edge",
                "enabled": false,
                "rule_type": "request_header",
                "string_match": "^User-Agent.*$",
                "string_replace": "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0"
            },
            {
                "category": "regex",
                "comment": "Emulate iOS",
                "enabled": false,
                "rule_type": "request_header",
                "string_match": "^User-Agent.*$",
                "string_replace": "User-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 18_6 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.0 Mobile/15E148 Safari/604.1"
            },
            {
                "category": "regex",
                "comment": "Emulate Android",
                "enabled": false,
                "rule_type": "request_header",
                "string_match": "^User-Agent.*$",
                "string_replace": "User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Mobile Safari/537.36"
            },
            {
                "category": "regex",
                "comment": "Require non-cached response",
                "enabled": false,
                "rule_type": "request_header",
                "string_match": "^If-Modified-Since.*$"
            },
            {
                "category": "regex",
                "comment": "Require non-cached response",
                "enabled": false,
                "rule_type": "request_header",
                "string_match": "^If-None-Match.*$"
            },
            {
                "category": "regex",
                "comment": "Hide Referer header",
                "enabled": false,
                "rule_type": "request_header",
                "string_match": "^Referer.*$"
            },
            {
                "category": "regex",
                "comment": "Require non-compressed responses",
                "enabled": false,
                "rule_type": "request_header",
                "string_match": "^Accept-Encoding.*$"
            },
            {
                "category": "regex",
                "comment": "Ignore cookies",
                "enabled": false,
                "rule_type": "response_header",
                "string_match": "^Set-Cookie.*$"
            },
            {
                "category": "regex",
                "comment": "Rewrite Host header",
                "enabled": false,
                "rule_type": "request_header",
                "string_match": "^Host: foo.example.org$",
                "string_replace": "Host: bar.example.org"
            },
            {
                "category": "literal",
                "comment": "Add spoofed CORS origin",
                "enabled": false,
                "rule_type": "request_header",
                "string_replace": "Origin: foo.example.org"
            },
            {
                "category": "regex",
                "comment": "Remove HSTS headers",
                "enabled": false,
                "rule_type": "response_header",
                "string_match": "^Strict\\-Transport\\-Security.*$"
            },
            {
                "category": "literal",
                "comment": "Disable browser XSS protection",
                "enabled": false,
                "rule_type": "response_header",
                "string_replace": "X-XSS-Protection: 0"
            }
        ],
        "miscellaneous": {
            "disable_logging_to_history_and_site_map": false,
            "disable_out_of_scope_logging_to_history_and_site_map": false,
            "disable_web_interface": false,
            "remove_unsupported_encodings_from_accept_encoding_headers_in_incoming_requests": true,
            "set_connection_close_header_on_responses": false,
            "set_connection_header_on_requests": true,
            "strip_proxy_headers_in_incoming_requests": true,
            "strip_sec_websocket_extensions_headers_in_incoming_requests": true,
            "suppress_burp_error_messages_in_browser": false,
            "unpack_gzip_deflate_in_requests": false,
            "unpack_gzip_deflate_in_responses": true,
            "use_http1_keep_alive": true,
            "use_http_10_in_requests_to_server": false,
            "use_http_10_in_responses_to_client": false
        },
        "request_listeners": [
            {
                "certificate_mode": "per_host",
                "custom_tls_protocols": [],
                "enable_http2": true,
                "listen_mode": "loopback_only",
                "listener_port": 8080,
                "running": false,
                "use_custom_tls_protocols": false
            }
        ],
        "response_modification": {
            "convert_https_links_to_http": false,
            "enable_disabled_form_fields": false,
            "highlight_unhidden_fields": false,
            "remove_all_javascript": false,
            "remove_input_field_length_limits": false,
            "remove_javascript_form_validation": false,
            "remove_object_tags": false,
            "remove_secure_flag_from_cookies": false,
            "unhide_hidden_form_fields": false
        },
        "ssl_pass_through": {
            "apply_to_out_of_scope_items": true,
            "automatically_add_entries_on_client_ssl_negotiation_failure": false,
            "rules": []
        },
        "web_sockets_history_display_filter": {
            "by_annotation": {
                "show_only_commented_items": false,
                "show_only_highlighted_items": false
            },
            "by_listener": {
                "listener_port": ""
            },
            "by_request_type": {
                "hide_incoming_messages": false,
                "hide_outgoing_messages": false,
                "show_only_in_scope_items": false
            },
            "by_search": {
                "case_sensitive": false,
                "negative_search": false,
                "regex": false,
                "term": ""
            },
            "filter_disabled": false,
            "filter_mode": "SETTINGS"
        },
        "ws_match_replace_disable_out_of_scope": false,
        "ws_match_replace_rules": []
    },
    "repeater": {
        "allow_http2_alpn_override": false,
        "enable_http1_keep_alive": false,
        "enable_http2_connection_reuse": true,
        "enforce_protocol_in_redirections": false,
        "follow_redirections": "never",
        "normalize_line_endings": true,
        "process_cookies_in_redirections": false,
        "streaming_response_timeout_millis": 600000,
        "strip_connection_header_over_http2": true,
        "unpack_gzip_deflate": true,
        "update_content_length": true
    },
    "sequencer": {
        "live_capture": {
            "ignore_abnormal_length_tokens": true,
            "max_length_deviation": 5,
            "num_threads": 5,
            "throttle": 0
        },
        "token_analysis": {
            "compression": true,
            "correlation": true,
            "count": true,
            "fips_long_run": true,
            "fips_monobit": true,
            "fips_poker": true,
            "fips_runs": true,
            "spectral": true,
            "transitions": true
        },
        "token_handling": {
            "base_64_decode_before_analyzing": false,
            "pad_short_tokens_at": "start",
            "pad_with": "0"
        }
    },
    "target": {
        "filter": {
            "by_annotation": {
                "show_only_commented_items": false,
                "show_only_highlighted_items": false
            },
            "by_file_extension": {
                "hide_items": [
                    "js",
                    "gif",
                    "jpg",
                    "png",
                    "ico",
                    "css",
                    "woff",
                    "woff2",
                    "ttf",
                    "svg"
                ],
                "hide_specific": false,
                "show_items": [
                    "asp",
                    "aspx",
                    "jsp",
                    "php"
                ],
                "show_only_specific": false
            },
            "by_folders": {
                "hide_empty_folders": true
            },
            "by_mime_type": {
                "show_css": false,
                "show_flash": true,
                "show_html": true,
                "show_images": false,
                "show_other_binary": false,
                "show_other_text": true,
                "show_script": true,
                "show_xml": true
            },
            "by_request_type": {
                "hide_not_found_items": true,
                "show_only_in_scope_items": false,
                "show_only_parameterized_requests": false,
                "show_only_requested_items": false
            },
            "by_search": {
                "case_sensitive": false,
                "negative_search": false,
                "regex": false,
                "term": ""
            },
            "by_status_code": {
                "show_2xx": true,
                "show_3xx": true,
                "show_4xx": false,
                "show_5xx": true
            },
            "filter_mode": "SETTINGS"
        },
        "scope": {
            "advanced_mode": false,
            "exclude": [],
            "include": []
        }
    }
}

Filter Out the Noise

Suppresses fonts, images, analytics and other out-of-scope assets so proxy history stays clean and relevant.

Optimized Logging

Captures only what matters. Request and response limits are pre-tuned to avoid exhausting memory mid-engagement.

Instant Edits

Toggle match/replace rules, scope exclusions, and listener settings in seconds before downloading your config.

Need a Deep-Dive Security Assessment?

A solid configuration is just the beginning. Our expert penetration testers can uncover critical vulnerabilities that automated tools miss. Let's secure your infrastructure together.

Request a Penetration Test