Burp Suite Cheat Sheet

General Workflow (Proxy)

Proxy

Target / Sitemap

Repeater

Intruder (brute force / fuzzing)

  1. Send to Intruder
  2. Positions tab: select payload position(s) §
  3. Payloads tab:
    • Sniper — one position, one wordlist
    • Battering ram — same payload to all positions
    • Pitchfork — parallel wordlists (credential stuffing: usernames+passwords)
    • Cluster bomb — all combos (multi-dim brute force)
  4. Options: throttle request throttling, set grep-match for status codes/echo strings, resource pool threads
  5. Whitelist responses: sort by status/length to find anomalies

Content Discovery

Decoder / Comparer

Extensions (BApp Store)

Useful Response-Signature Checks (manual)

CLI Alternative (quick checks without GUI)