MCPVault

http_analyze_variations

MCP tool from BurpMCP Ultra by Cy-S3c

Detect response variations (blind injection)

How to use it

http_analyze_variations is exposed by the BurpMCP Ultra MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the http_analyze_variations tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.

FULL BURPMCP ULTRA LISTING

Other tools in BurpMCP Ultra (39)

access_control_sweep

Batch broken-access-control / IDOR across multiple identities

collaborator_create_client

Create a Collaborator client for OOB testing

collaborator_default_payload

Generate a payload on a shared default client (quick OOB)

collaborator_generate_payload

Generate a Collaborator payload

collaborator_get_secret

Get the client secret key for session persistence

collaborator_poll

Poll for DNS / HTTP / SMTP interactions (decodes DNS qnames)

collaborator_restore_client

Restore a client from its secret key

collaborator_server_info

Get the Collaborator server address

cors_probe

Detect CORS misconfigurations (reflected / null origin, credentialed)

graphql_probe

GraphQL introspection + field-suggestion enumeration

http_analyze_keywords

Analyze a response for keyword occurrences

http_fuzz

Inline fuzzer — FUZZ keyword, §marker§, or byte-offset modes + payload libraries

http_race

Race-condition testing — fire N requests simultaneously

http_send_raw_bytes

Byte-level request for smuggling and CRLF injection

http_send_request

Send HTTP request (structured or raw, HTTP/1.1 or HTTP/2)

http_send_request_chain

Multi-step request sequence with token extraction between steps

http_send_requests_parallel

Send multiple requests in parallel (batch ops, races)

injection_probe

Guided SQLi / SSTI / LFI with confirmation oracles (SQL-error fingerprints, time-delay, template math-eval, file markers) — not blind fuzzing

intruder_register_payload_processor

Register a custom payload processor

jwt_attack

JWT offense — alg:none, RS→HS key confusion, weak-secret cracking, structural analysis

proxy_annotate

Add highlight color and comment to a history item

proxy_auto_auth

One-command auth-header injection for all matching requests

proxy_history

Get HTTP proxy history with filtering (host, method, status, MIME, scope)

proxy_history_search

Regex search across proxy history (URL, headers, body)

proxy_websocket_history

Get WebSocket proxy history

proxy_websocket_history_search

Regex search WebSocket history

recon_fingerprint

Technology + WAF fingerprinting

repeater_send

Send a request to a Repeater tab

scanner_create_issue

Create a custom audit issue

scanner_generate_report

Generate HTML/XML scan report

scanner_get_all_issues

All issues with severity/confidence filter

scanner_import_bcheck

Import a BCheck script for custom scanning

scanner_start_audit

Start active/passive scan with optional auth config

scanner_start_crawl

Start a web crawl from seed URLs

scanner_task_add_request

Add a request to a running audit

scanner_task_issues

Get issues from a specific task

websocket_create

Create a WebSocket connection

websocket_get_messages

Get messages with a direction filter

websocket_set_intercept_rule

Auto-intercept WebSocket messages