Connectors · Security Tools
Evidence Connector for Burp Suite
Route Burp Suite findings directly into SecEng evidence workflows.
Screenshots coming soon
Visual walkthrough of Evidence Connector for Burp Suite in progress
Overview
The SecEng Evidence Connector for Burp Suite uses the Montoya API to passively capture HTTP traffic and send AI-related findings to the local SecEng sidecar. It creates native Burp issues for each finding and surfaces them in the Burp UI — no separate tool required. Everything runs locally; no traffic leaves the machine.
Features
- 01.
Passive HTTP listener
Monitors all HTTP/S traffic flowing through Burp Proxy and forwards AI-related requests and responses to the sidecar for analysis.
- 02.
Native Burp issue creation
Findings are reported as first-class Burp issues with severity, confidence, and detail fields — exactly like any other Burp scanner finding.
- 03.
Evidence attachment
Attach scan findings to your SecEng program as structured evidence, linking HTTP evidence to your AI risk inventory.
- 04.
Local first — no data exfiltration
All analysis happens inside the sidecar on 127.0.0.1. Traffic never leaves the pentester's machine.
- 05.
Context menu scanning
Right-click any request in Burp's history to manually trigger a SecEng analysis on a specific payload.
Install steps
Step 01
Build the extension JAR: `./gradlew build` from `apps/burp-evidence-connector/`.
Step 02
In Burp, go to Extensions → Installed → Add → select the JAR from `build/libs/`.
Step 03
Ensure the SecEng sidecar is running on `http://127.0.0.1:17371`.
Step 04
Browse target AI endpoints through Burp Proxy — findings appear automatically in the Issues tab.
Capabilities
Surfaces
Scan modes
Privacy architecture
Local first
Designed to keep the supported flow in the local or customer-controlled environment. What leaves the device or workspace depends on the feature and configuration.
Platform vendor
PortSwigger
PortSwigger's burp jar format is mapped in the registry. The connector itself is not yet built.
Early access
Get the integration on the roadmap
Tell us which platform matters most and we'll prioritize it where it fits the current product surface.