BurpMCP Ultra logo

BurpMCP Ultra

Unclaimed

by Cy-S3c

AI-powered MCP server for Burp Suite Professional — 149 tools across proxy, scanner, inline fuzzer, race conditions, guided injection, JWT/IDOR attacks, recon & OOB, with a real-time dashboard and hardened localhost security. Drive Burp from Claude Code or any MCP client.

Set up this server

This server needs project-specific setup. Follow the project instructions; no reusable public launch command is available yet.

Project instructions
bug-bountyburpsuiteclaudekotlinmcpmodel-context-protocolpentestingsecurity-tools

More in Files & Storage

Browse the full directory

Unclaimed listing

Is this your MCP server?

This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.

Claim this server

Security profile

Claimed and verified servers get a weekly static scan that shows what the code can reach: external services, environment variables, shell commands, agent configuration folders, plus any dependencies with known advisories. Claim this listing to get one. How the security profile works

40 of 40 tools

Documented tools (40)

From project documentation. A server handshake does not verify each tool’s description or behavior.

access_control_sweep

Batch broken-access-control / IDOR across multiple identities

collaborator_create_client

Create a Collaborator client for OOB testing

collaborator_default_payload

Generate a payload on a shared default client (quick OOB)

collaborator_generate_payload

Generate a Collaborator payload

collaborator_get_secret

Get the client secret key for session persistence

collaborator_poll

Poll for DNS / HTTP / SMTP interactions (decodes DNS qnames)

collaborator_restore_client

Restore a client from its secret key

collaborator_server_info

Get the Collaborator server address

cors_probe

Detect CORS misconfigurations (reflected / null origin, credentialed)

graphql_probe

GraphQL introspection + field-suggestion enumeration

http_analyze_keywords

Analyze a response for keyword occurrences

http_analyze_variations

Detect response variations (blind injection)

http_fuzz

Inline fuzzer — FUZZ keyword, §marker§, or byte-offset modes + payload libraries

http_race

Race-condition testing — fire N requests simultaneously

http_send_raw_bytes

Byte-level request for smuggling and CRLF injection

http_send_request

Send HTTP request (structured or raw, HTTP/1.1 or HTTP/2)

http_send_request_chain

Multi-step request sequence with token extraction between steps

http_send_requests_parallel

Send multiple requests in parallel (batch ops, races)

injection_probe

Guided SQLi / SSTI / LFI with confirmation oracles (SQL-error fingerprints, time-delay, template math-eval, file markers) — not blind fuzzing

intruder_register_payload_processor

Register a custom payload processor

jwt_attack

JWT offense — alg:none, RS→HS key confusion, weak-secret cracking, structural analysis

proxy_annotate

Add highlight color and comment to a history item

proxy_auto_auth

One-command auth-header injection for all matching requests

proxy_history

Get HTTP proxy history with filtering (host, method, status, MIME, scope)

proxy_history_search

Regex search across proxy history (URL, headers, body)

proxy_websocket_history

Get WebSocket proxy history

proxy_websocket_history_search

Regex search WebSocket history

recon_fingerprint

Technology + WAF fingerprinting

repeater_send

Send a request to a Repeater tab

scanner_create_issue

Create a custom audit issue

scanner_generate_report

Generate HTML/XML scan report

scanner_get_all_issues

All issues with severity/confidence filter

scanner_import_bcheck

Import a BCheck script for custom scanning

scanner_start_audit

Start active/passive scan with optional auth config

scanner_start_crawl

Start a web crawl from seed URLs

scanner_task_add_request

Add a request to a running audit

scanner_task_issues

Get issues from a specific task

websocket_create

Create a WebSocket connection

websocket_get_messages

Get messages with a direction filter

websocket_set_intercept_rule

Auto-intercept WebSocket messages

Tool change history

Compared across complete checks of the same configuration. Tools were listed, not invoked. Input-schema changes are not measured here.

No complete tool checks yet.

FAQ

Questions about BurpMCP Ultra MCP Server

How do I connect BurpMCP Ultra MCP Server to Claude?
The project does not publish a launch command that MCPVault could verify. Open the repository linked on this page for its install steps; the listing names Claude Desktop, Claude Code as compatible clients.
Is BurpMCP Ultra MCP Server free?
The listed licence is MIT. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
What can BurpMCP Ultra MCP Server do?
BurpMCP Ultra MCP Server documents 40 tools to the agent, including access_control_sweep, collaborator_create_client, collaborator_default_payload. The descriptions above come from project documentation. A live handshake does not test individual tool behavior.