MCPVault

BurpMCP Ultra

Unclaimed

by Cy-S3c

AI-powered MCP server for Burp Suite Professional — 149 tools across proxy, scanner, inline fuzzer, race conditions, guided injection, JWT/IDOR attacks, recon & OOB, with a real-time dashboard and hardened localhost security. Drive Burp from Claude Code or any MCP client.

Unclaimed listing

Is this your MCP server?

This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.

Claim this server

Tools (40)

access_control_sweep

Batch broken-access-control / IDOR across multiple identities

collaborator_create_client

Create a Collaborator client for OOB testing

collaborator_default_payload

Generate a payload on a shared default client (quick OOB)

collaborator_generate_payload

Generate a Collaborator payload

collaborator_get_secret

Get the client secret key for session persistence

collaborator_poll

Poll for DNS / HTTP / SMTP interactions (decodes DNS qnames)

collaborator_restore_client

Restore a client from its secret key

collaborator_server_info

Get the Collaborator server address

cors_probe

Detect CORS misconfigurations (reflected / null origin, credentialed)

graphql_probe

GraphQL introspection + field-suggestion enumeration

http_analyze_keywords

Analyze a response for keyword occurrences

http_analyze_variations

Detect response variations (blind injection)

http_fuzz

Inline fuzzer — FUZZ keyword, §marker§, or byte-offset modes + payload libraries

http_race

Race-condition testing — fire N requests simultaneously

http_send_raw_bytes

Byte-level request for smuggling and CRLF injection

http_send_request

Send HTTP request (structured or raw, HTTP/1.1 or HTTP/2)

http_send_request_chain

Multi-step request sequence with token extraction between steps

http_send_requests_parallel

Send multiple requests in parallel (batch ops, races)

injection_probe

Guided SQLi / SSTI / LFI with confirmation oracles (SQL-error fingerprints, time-delay, template math-eval, file markers) — not blind fuzzing

intruder_register_payload_processor

Register a custom payload processor

jwt_attack

JWT offense — alg:none, RS→HS key confusion, weak-secret cracking, structural analysis

proxy_annotate

Add highlight color and comment to a history item

proxy_auto_auth

One-command auth-header injection for all matching requests

proxy_history

Get HTTP proxy history with filtering (host, method, status, MIME, scope)

proxy_history_search

Regex search across proxy history (URL, headers, body)

proxy_websocket_history

Get WebSocket proxy history

proxy_websocket_history_search

Regex search WebSocket history

recon_fingerprint

Technology + WAF fingerprinting

repeater_send

Send a request to a Repeater tab

scanner_create_issue

Create a custom audit issue

scanner_generate_report

Generate HTML/XML scan report

scanner_get_all_issues

All issues with severity/confidence filter

scanner_import_bcheck

Import a BCheck script for custom scanning

scanner_start_audit

Start active/passive scan with optional auth config

scanner_start_crawl

Start a web crawl from seed URLs

scanner_task_add_request

Add a request to a running audit

scanner_task_issues

Get issues from a specific task

websocket_create

Create a WebSocket connection

websocket_get_messages

Get messages with a direction filter

websocket_set_intercept_rule

Auto-intercept WebSocket messages