PortSwigger Introduces Repeater Strike: AI-Powered Burp Suite Extension for Automated Vulnerability Hunting
PortSwigger Research has unveiled Repeater Strike, a new artificial intelligence-powered extension for Burp Suite designed to streamline and amplify manual security testing. The tool specifically targets Insecure Direct Object References (IDOR) and similar vulnerabilities by analyzing traffic within the Repeater module. Instead of requiring repetitive manual checks, Repeater Strike uses AI to generate smart regular expressions based on user requests and responses. It then scans the proxy history to identify related issues, effectively turning a single discovered vulnerability into a broader set of actionable findings with minimal effort. Developed by researcher Gareth Heyes, the extension employs AI to mutate probes and response patterns, allowing it to detect variations of vulnerabilities across different parameters. Notably, the tool is optimized for efficiency, requiring only a small number of AI tokens to generate rules, after which it operates without further token consumption. While the development process faced challenges such as handling large responses and ensuring consistent AI output, the final product represents a significant step forward in semi-automated security testing, enabling testers to uncover deeper security flaws more efficiently.
Wire timeline
PortSwigger Introduces Repeater Strike: AI-Powered Burp Suite Extension for Automated Vulnerability Hunting
PortSwigger Research has unveiled Repeater Strike, a new artificial intelligence-powered extension for Burp Suite designed to streamline and amplify manual security testing. The tool specifically targets Insecure Direct Object References (IDOR) and similar vulnerabilities by analyzing traffic within the Repeater module. Instead of requiring repetitive manual checks, Repeater Strike uses AI to generate smart regular expressions based on user requests and responses. It then scans the proxy history to identify related issues, effectively turning a single discovered vulnerability into a broader set of actionable findings with minimal effort. Developed by researcher Gareth Heyes, the extension employs AI to mutate probes and response patterns, allowing it to detect variations of vulnerabilities across different parameters. Notably, the tool is optimized for efficiency, requiring only a small number of AI tokens to generate rules, after which it operates without further token consumption. While the development process faced challenges such as handling large responses and ensuring consistent AI output, the final product represents a significant step forward in semi-automated security testing, enabling testers to uncover deeper security flaws more efficiently.
PortSwigger Research