PortSwigger Burp Suite Professional Scalability

Anuradha.Kapoor Kapoor - PeerSpot reviewer
Head - Quality Control at Net Solutions

It is scalable. I would rate the scalability a six out of ten. We have one license.

Because one scan takes six to eight hours, so probably, use it 40 to 50 hours a week.

View full review »
Sonali Gedam - PeerSpot reviewer
Qulity Engineer at Lloyds Banking Group PLC

The solution is easy to scale. Six people are using the solution within my team, and my organization plans to give the license to all the QA testers.

View full review »
Anton Krivonosov - PeerSpot reviewer
Application Security Architect at Kuehne & Nagel Inc.

PortSwigger Burp Suite Professional is not a cloud solution. Since you have to download it to every machine you use, it's not scalable at all. Around seven users use the solution in our organization.

View full review »
Buyer's Guide
PortSwigger Burp Suite Professional
March 2024
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
767,847 professionals have used our research since 2012.
VinothKumar5 - PeerSpot reviewer
Senior Consultant at Hexaware Technologies Limited

The solution is scalable. There are types of operations we can do and it has good peak performance.

View full review »
Prasenjit Roy - PeerSpot reviewer
Sr. Cloud Solution Architect - SAP on Azure at Accenture

PortSwigger Burp Suite Professional is a scalable solution. We have about 200 users in our company.

View full review »
Rishi Anupam - PeerSpot reviewer
Senior Manager at Airtel

It is a scalable solution but needs to be more user-friendly. I rate the scalability an eight out of ten.

View full review »
Amir Rahimian - PeerSpot reviewer
CEO/General Manager at Lian

I rate the scalability of the solution as six out of ten.

View full review »
SANGAM GOEL - PeerSpot reviewer
Chief Executive Officer at GS2 CYBER SECURITY

The solution can scale. It's per system. If you are using it on 100 systems, you must install it on all 100 systems. It's not like you install a central product, and you scale. It's not the client-server architecture; you must install it on every system if you want to test.

We have two or three users on the solution.

View full review »
AnkithKumar - PeerSpot reviewer
Application Security Consultant at a tech services company with 10,001+ employees

PortSwigger Burp Suite Professional is scalable. You can add in-scope items, and remove any items that are not on the scope.

We have approximately 30 people using the solution in my organization. We have managers, consultants, and senior consultants using it. If our testers increase the number of users will increase and then we will increase our usage of this solution.

View full review »
Akshay Waghmare - PeerSpot reviewer
Manager at a consultancy with 10,001+ employees

Around 500 to 600 users are using the solution in our organization.

View full review »
ManishSingh - PeerSpot reviewer
Quality Manager at Net Solutions

It is a scalable solution. We currently have only one to two people using Burp Suite for specific clients.

View full review »
Siddharth-Singhal - PeerSpot reviewer
Consultant at a consultancy with 10,001+ employees

The scalability is quite good because PortSwigger can be used by multiple users through Jenkins and other things. 

View full review »
DC
Team Lead at dhabsc

I would rate the scalability a six out of ten. The primary reason is the high number of false positives compared to actual positives. 

Additionally, understanding the scan configuration can be challenging for newcomers. While experienced users can effectively scale their scanning techniques, those with limited experience may find it difficult to understand the process and identify the root causes of errors. 

Moreover, configuring proxy settings can be complex, leading to difficulties for some users. Overall, there are significant areas for improvement in terms of scalability, particularly in enhancing user understanding and reducing false positives. However, compared to other application security tools, Burp Suite still performs well.

There are around three end users using this solution in our company.

View full review »
RP
Cyber security Lead at PCS

The automation features in Burp Suite For vulnerability assessment and penetration testing may not be as extensive as other tools like NetSparker. Other tools may offer more comprehensive capabilities, especially in areas such as source code. Features like capture and OTP testing might be more robustly supported in other tools. There may be limitations in automation with Burp Suite Professional. NetSparker could be more suitable for tasks like two-factor authentication testing.

Four to five are using this solution.

The professional version is not very scalable, whereas the enterprise version is scalable. I can run multiple scans.

View full review »
AM
Test Lead at a financial services firm with 10,001+ employees

I rate Burp Suite's scalability a seven out of ten. We wanted to have more scalability in my last company, where we wanted the enterprise edition, but there were some challenges we faced. We couldn't find a solution to the problem statements for most of our business use cases back then. We then dropped the idea of using Burp Suite Enterprise and opted for a standard one for manual penetration testing.

There were ten users in my unit working with Burp Suite.

View full review »
MN
Security Tester at Ray Business Technologies Private Limited

It is a scalable solution. Ten specialists are working with Burp Suite Professional currently. We plan to increase the usage in the future. I rate the scalability an eight out of ten.


View full review »
NS
Cyber Security Engineer at a transportation company with 10,001+ employees

The Professional version is not very scalable because you need to buy licenses for each user, but the Enterprise version takes care of that.

View full review »
Mouli Siramdasu - PeerSpot reviewer
Associate Consultant at ATOS

It is pretty easy to scale the product.

We had ten to 12 people using the solution. It was a small environment.

View full review »
VN
Director - Head of Delivery Services at Ticking Minds Technology Solutions Pvt Ltd

With the open edition, it's not a problem to install on any number of machines. When it comes to the professional edition, you need a license and you have to pick a license type. I have to use it against a particular machine on which I would run. From there I would run my scans. Let's say I don't find my laptop or my computer fast enough, and I decide to move my license across to a higher processor, higher memory laptop or computer, I can easily move the license across to the new machine.

As long as I am on that particular license use, I have one license that I'm able to move across to one instance at any given point of time. That is quite stable. I think even more than that, for a top-priced edition you can take multiple contract licenses. Something like a license server where you might have five licenses. You might have 10 installations and you can have different people working on various routes use the tool. Only those five licenses will be needed. In that instance, scalability is definitely a great point for most uses.

Currently, if you look at the users that are linked to roles that we have, one is the security test engineer and one is the security test analyst. At any given point in time, only one person uses the tool for engagement in the professional edition. We have about two to three people working with us on these projects.

View full review »
SB
Quality Analyst at Hiup Solution

The solution is very scalable. I'd rate the ability to extend ten out of ten.

Three people are using the solution.

View full review »
VD
Lead Security Architect at a comms service provider with 1,001-5,000 employees

Obviously, Burp Suite is a DAST tool and good asset for pentester's. However, we need to see how best it can be utilized for automation so that DAST can be automated. Dynamic application testing can be automated and can integrate Burp into CI/CD pipeline using Jenkins. That said, we need to make it use it in a more efficient way. There should be some methods or some guidance from Burp on how best we can use it for automation.

View full review »
SS
Senior Test Engineer II at a financial services firm with 201-500 employees

In terms of scalability, I think they can increase the number of regions. And more importantly, it doesn't restrict based on the domains you are scanning. So even if tomorrow you suggest some working space, you can still scan the domains for the regions that you have. If you want to increase the number that you scan, you can buy some more. So scalability is not a big problem, but I think if you are scanning from your side, you have to get the license for some of those activities. That's domain based licensing.

Right now we have two or three people using it.

View full review »
it_user787785 - PeerSpot reviewer
Senior Security Engineer at a insurance company with 10,001+ employees

It is possible to work on multiple projects at the same time. I have tried five or six, and it is working fine. I would agree that the scalability is very good, and we have not found a limit yet.

We have approximately thirty users for this solution and they are the testers. As our team grows, we'll need to buy more licenses.

View full review »
RO
Cyber Security Analyst at a tech vendor with 1,001-5,000 employees

The solution is not designed to be scalable. You have an individual license, and I use it individually.

View full review »
MM
Cyber Security Specialist at a university with 10,001+ employees

The scalability of PortSwigger Burp Suite Professional is good, it can integrate with other platforms.

In my previous company, I worked for we had 50 people using this solution and in my current company we have approximately 500 people using it.

View full review »
AJ
Cyber Security Analyst at a comms service provider with 10,001+ employees

The solution scales well. It's not an issue.

View full review »
NA
Chief Info Sec Engineer at Sri Lanka CERT

As we only have a couple of licenses, we have not encountered any issues concerning the scalability. 

View full review »
SS
Penetration Tester at a tech services company with 1,001-5,000 employees

Scalability is not an issue because it is not centrally connected. Rather, it is a per-license, user-based tool. We have more than 20 users in the company.

View full review »
NC
IT Manager at a manufacturing company with 10,001+ employees

Scalability depends upon which of the Burp versions you're using. If you're using Pro it's not scalable because it's dedicated to one person. But when it comes to Enterprise, yes it is scalable, it's easy. 

View full review »
NC
IT Manager at a manufacturing company with 10,001+ employees

Easily scalable when it comes to Enterprise version. but Enterprise version itself is not as effective as pro.

View full review »
AA
Founder and Director at a financial services firm with 1-10 employees

I'm a consultant. I tend to use the tool for my clients. I only have one license on my computer. I don't need to scale the product.

The solution is scalable, however. There's a different version for that aspect. You have Community, Professional, and Enterprise editions. Each has different capabilities.

View full review »
YC
Security consultant at a manufacturing company with 10,001+ employees

The solution is easily scalable, depending on licensing of course. For example, on the cloud set up, you can easily scale the agents and such. But in terms of bandwidth, maybe when it comes to their reporting feature, there are some limitations with the detail that can be downloaded from the report. I've found that the system can crash if you try to download a report with many details.

View full review »
VR
Director at a consultancy with 10,001+ employees

Burp is scalable. 

We have around 150 users using Burp at my company. We use it daily.  

View full review »
Nikhil Tiple - PeerSpot reviewer
Application Security Specialist at Codincity

The tool is highly scalable. I rate the scalability a nine out of ten. We have four to five customers. We work with medium-sized businesses.

View full review »
it_user496968 - PeerSpot reviewer
Penetration Testing Advisor at a tech services company with 1,001-5,000 employees

It's better to add only one website per project for the same reason as above.

View full review »
it_user492585 - PeerSpot reviewer
Information Systems Security Officer at a financial services firm with 1,001-5,000 employees

If you attempt to map a large website using the Spider component, it can take a long time, and the tool may crash.

View full review »
VC
Senior Cyber Security Analyst at a tech services company with 501-1,000 employees

Over 500 people are using the solution in our organization.

View full review »
MM
Cyber Security Specialist at a university with 10,001+ employees

We have had no issues with scalability, although we are using a standalone installation with only a single user. We may expand usage in the future.

View full review »
reviewer1139067 - PeerSpot reviewer
Works

Scalability is very simple and easy.

View full review »
KM
IT Security Analyst at a tech services company with 11-50 employees

I can't say much about that because we are going to transition to cloud management. I don't know for sure how it is going to scale up. We are still in the testing and planning stages. We currently have approximately five users, and our team is still growing.

View full review »
it_user704997 - PeerSpot reviewer
Senior Information Security Analyst at a tech services company with 10,001+ employees

I have only used it as a single user. But many of my colleagues use it and I have never heard of any such issues.

View full review »
it_user245421 - PeerSpot reviewer
Senior Security Consultant at a tech services company with 501-1,000 employees

No issues encountered.

View full review »
SJ
Compliance Manager at a tech services company with 201-500 employees

We use some different tools for web application testing, like Nmap and others. If PortSwigger Burp could actually scale up for web application scanning, that would be really good. This way, instead of using different tools, we could easily rely on one tool for all testing.

View full review »
AB
Security Researcher at a financial services firm with 5,001-10,000 employees

It's a scalable solution.

We have more than 30 users in our organization.

View full review »
AS
IT Auditor & Compliance Officer at a tech vendor with 51-200 employees

I would say that this is a very scalable solution.

We do plan to increase our usage, but not beyond the Professional version. It is not our intention to move to the Enterprise version right now.

View full review »
AG
Cyber Security Analyst at a tech services company with 11-50 employees

Its scalability is great. We have almost five users who are using the product, and they're happy with this product. 

View full review »
JA
Security Analyst at a tech services company with 201-500 employees

My impressions of the scalability of the solution are good.

View full review »
AR
AVP - Software Quality Assurance at a tech services company with 201-500 employees

The solution doesn't offer very good scalability.

View full review »
Buyer's Guide
PortSwigger Burp Suite Professional
March 2024
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
767,847 professionals have used our research since 2012.