PortSwigger Burp Suite Professional Initial Setup

Anuradha.Kapoor Kapoor - PeerSpot reviewer
Head - Quality Control at Net Solutions

I would rate my experience with the initial setup an eight out of ten, where one being difficult and ten being easy to set up. It is easy. It's not that difficult.

View full review »
Sonali Gedam - PeerSpot reviewer
Qulity Engineer at Lloyds Banking Group PLC

PortSwigger Burp Suite is very easy to install. We can even integrate plugins into automation, so the configuration is easy. The solution takes five to 15 minutes to deploy and set up.

We only need one architect to deploy the solution. You don't have to take any support from other teams. They give you the exe. If that installation is ready, then you just have to click and click on "next." You don't require anyone's help to install the solution on your machine. You can do it by yourself. PortSwigger Burp Suite does not require maintenance.

View full review »
Anton Krivonosov - PeerSpot reviewer
Application Security Architect at Kuehne & Nagel Inc.

The solution's initial setup is straightforward. You just have to download, install, and use it.

View full review »
Buyer's Guide
PortSwigger Burp Suite Professional
April 2024
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,740 professionals have used our research since 2012.
VinothKumar5 - PeerSpot reviewer
Senior Consultant at Hexaware Technologies Limited

The installation is very easy.

View full review »
Prasenjit Roy - PeerSpot reviewer
Sr. Cloud Solution Architect - SAP on Azure at Accenture

The initial setup is straightforward, but it is not very user-friendly, and you need someone to install the certificate. It is a bit complex, but we can manage that one. It took more than half an hour to deploy this solution.

View full review »
Rishi Anupam - PeerSpot reviewer
Senior Manager at Airtel

The initial setup was easy. The deployment takes around a week.

I rate the setup an eight out of ten.


View full review »
Amir Rahimian - PeerSpot reviewer
CEO/General Manager at Lian

The initial setup was easy. One doesn't need much knowledge to operate it. The solution can be deployed within ten minutes. 

View full review »
SANGAM GOEL - PeerSpot reviewer
Chief Executive Officer at GS2 CYBER SECURITY

The solution is a little bit complex. It's not exactly straightforward. 

The deployment itself was a pretty easy process. It was quick.

We do not find it difficult to maintain the solution.

View full review »
AnkithKumar - PeerSpot reviewer
Application Security Consultant at a tech services company with 10,001+ employees

The initial setup of PortSwigger Burp Suite Professional was simple. It can be done in approximately three minutes.

I rate the initial setup of PortSwigger Burp Suite Professional a five out of five.

View full review »
Akshay Waghmare - PeerSpot reviewer
Manager at a consultancy with 10,001+ employees

The solution’s initial setup is quite easy.

View full review »
ManishSingh - PeerSpot reviewer
Quality Manager at Net Solutions

Burp Suite is easy to set up and takes only five to ten minutes. The installation can be done by one person only. The maintenance isn’t very hard to do.

View full review »
Siddharth-Singhal - PeerSpot reviewer
Consultant at a consultancy with 10,001+ employees

The initial setup is not that difficult because there's good documentation on the PortSwigger website. Our employees each installed on their own machine, it's an executable file. 

View full review »
DC
Team Lead at dhabsc

I would rate my experience with the initial setup of Burp Suite Professional an eight out of ten, with one being difficult and ten being easy.

View full review »
EA
President & Owner at Aydayev's Investment Business Group

The setup is a bit complex.

View full review »
RP
Cyber security Lead at PCS

The initial setup takes more than a week. The professional version is a plug-and-play.

There is a Java package that you can easily use without installing it.

View full review »
AM
Test Lead at a financial services firm with 10,001+ employees

The initial setup is easy, not only in the office, since I'm working on my laptop now with the community edition. The configuration is pretty straightforward.

View full review »
MN
Security Tester at Ray Business Technologies Private Limited

The initial setup is easy. The deployment is done under a professional, and it takes one hour to be deployed. We have to add our information to get our code directly into the box and then we scan their applications. A single person is required for the deployment. I rate the initial setup a ten out of ten.


View full review »
NS
Cyber Security Engineer at a transportation company with 10,001+ employees

The initial setup is very easy because Burp Suite has very good documentation. Setup took less than an hour, though it might take a less-experienced person longer to install a mobile application because of the application-level security.

View full review »
Mouli Siramdasu - PeerSpot reviewer
Associate Consultant at ATOS

For the setup, on my end, I just got access via the organization when I first started using it. I haven't set up the entire cloud, the Burp Suite cloud. I used it by using some credentials only. Therefore, I'm not that good at setting up the enrollment.

The entire setup was done on the cloud. There were only three to four people needed for deployment and maintenance. They are well experienced in those areas.

View full review »
VN
Director - Head of Delivery Services at Ticking Minds Technology Solutions Pvt Ltd

The initial setup was straightforward. It's not complex at all. Today it comes along with a job size which makes it much more affordable and easy. I don't think the installation is ever a challenge here. 

In some setups, all I do is this: if I'm setting it up for Windows, I cannot get my path through which I want to set this up. A few clicks and I'll be able to get the entire tool set up. I would say it requires some amount of knowledge to do testing. So also we are able to set up the tool against an application. Let's say there is an application that comes through for testing. Until I get to know the way I have to configure the target URLs and capture the entire traffic flow. That is easy. Now there are jar files also being made available for easier instantiation of the tool.

It is not a challenge in setting up the tool at all because there's plenty of videos and documentation available around in both the PortSwigger website as well as in open forums like YouTube and all that. It's quite easy to set it up. Personally, I haven't had trouble. We haven't had any major challenges in terms of setting up the tool. Not just purely from an installation standpoint, but also from a perspective of beginning to capture traffic across the different applications that we serve. 

The installation takes about less than four to five minutes. It doesn't take more than that.

In terms of security implementation strategy, when we take control of any tests that we do, we set the proxies in place based on the settings that are there on the tool and then set up the same proxy across on a browser for which we will capture the traffic. Once we do that, our implementation strategy is to capture the entire traffic in terms of specifying a target URL, the application or the website and the test. We do a proper login and ensure that all the data captures are there. Then we see that all the requested sponsors are getting logged in properly inside the tool and we are able to capture that. So once we do that, we try to simulate all user flows that would be there on the tool. 

Based on the different tools that are there, we capture the flow and enter a fake login and then we do a scan. The scan helps to unlock issues that are there. That kind of test is to identify all the actions that we do. We particularly do what is called an active scan which is like after you use the browser, make all the user clicks, events, and all that, the tool is able to capture it in the background. It does an active scan, and it gives what are potential issues that are there. So once we are done with that, we look at all the issues that are there, and then we make it run through a boot scan based on the requests that we have captured. Typically this takes a final good amount of time which depends on the amount of traffic that you have captured through the tool.

The one good thing that I would like to highlight is that irrespective of how much traffic is captured from my application flow, the tool is quite robust. I have seen other tools that sometimes the application, or rather the tool, becomes non-responsive. I haven't seen those kinds of issues here.

Then, once we are done with the scan, we pick and choose what are the issues that are there. We look for what are the trouble spots, and what issues are being highlighted. Then we check each of those specific requests, sending them over to another team member, and try them with different payloads, putting them across in the intruder and unearthing issues. So that helps me really test the application using PortSwigger comprehensively, and, more importantly, at the end of the test, it makes it quite easy for me to generate a report which is quite nice and simple which I can forward across to the client. That is essentially the way I go about in my implementation of security testing.

View full review »
Nikhil Tiple - PeerSpot reviewer
Application Security Specialist at Codincity

The setup can be done easily. I rate the ease of setup a ten out of ten. It is a stress-free process. The deployment takes two to three days. The deployment process is very simple. We just do the installation setup and install the key.

View full review »
SB
Quality Analyst at Hiup Solution

The initial setup was a bit difficult. For a beginner, it's tough to set up. I'd rate the solution three out of ten in terms of ease of setup. There isn't proper documentation to help you through the process. 

I cannot recall how long the deployment took. I watched a lot of videos and just went ahead with eh setup myself. 

The product doesn't require any maintenance. 

View full review »
Anton Krivonosov - PeerSpot reviewer
Application Security Architect at Kuehne & Nagel Inc.

The installation is straightforward and simple. It only takes minutes to install.

View full review »
VD
Lead Security Architect at a comms service provider with 1,001-5,000 employees

The initial setup isn't too difficult. It's JAR based. I would say it's an analog file. It just requires minimum requirements like Java and a license. After that, you are good to go.

View full review »
NS
Lead Cyber Security engineer at a manufacturing company with 10,001+ employees

The initial setup was straightforward and took about one to two weeks.

View full review »
SS
Senior Test Engineer II at a financial services firm with 201-500 employees

The initial setup was straightforward. We can install it on a Linux machine. It was fast to set up.

View full review »
it_user787785 - PeerSpot reviewer
Senior Security Engineer at a insurance company with 10,001+ employees

This solution is very easy to install and understand.

For a single user, it will take thirty to forty-five minutes. For our organization, it took between eight and nine hours.

View full review »
RO
Cyber Security Analyst at a tech vendor with 1,001-5,000 employees

The initial setup was straightforward.

View full review »
MM
Cyber Security Specialist at a university with 10,001+ employees

The initial setup of PortSwigger Burp Suite Professional is very simple.

View full review »
AJ
Cyber Security Analyst at a comms service provider with 10,001+ employees

We have found the initial setup to be very simple and straightforward. It's not overly complex or difficult. 

For any configuration for deployment in our project, we assign two people. We have a small team of two aligned with our project. They will handle everything related to implementation. The setup doesn't take longer than one day.

In terms of maintenance, for the customers, what we are doing is we have an internal cyber security team, in which there are people doing the pen test. There are people who are doing the vulnerability assessment for the WASP scan, SaaS. For each, we have a separate team, and based on that, most of the deployments are done by these pen testers only. We do not provide maintenance for customers, however, we do provide reporting and technical support.

View full review »
NA
Chief Info Sec Engineer at Sri Lanka CERT

The initial setup is not very complex. Rather, it is easy and straightforward. 

View full review »
SS
Penetration Tester at a tech services company with 1,001-5,000 employees

The initial setup is very straightforward and simple.

View full review »
NC
IT Manager at a manufacturing company with 10,001+ employees

The installation is not difficult. We only needed one person to handle the implementation. Setting up the agents may be tricky, but if a person is knowledgable, it shouldn't be an issue.

View full review »
AA
Founder and Director at a financial services firm with 1-10 employees

The initial setup is not overly complex. It's easy and straightforward. A company shouldn't have any issues with the implementation process.

The deployment takes a maximum of an hour, actually. If you have to configure some prerequisites, it is one hour tops. There are advanced setups, however, how advanced the implementation depends on the client environment. If a company has an advanced setup, it could take some time. 

Ultimately, the solution is installed directly onto my laptop.

The maintenance process is pretty minimal. The yearly subscription keeps everything updated. They will notify you if there is an upgrade that needs to be addressed.

View full review »
YC
Security consultant at a manufacturing company with 10,001+ employees

In my opinion the initial setup is pretty straightforward. The workflow is easy to understand and they have a lot of documentation on how to perform many of the key tasks.

View full review »
VR
Director at a consultancy with 10,001+ employees

The initial setup is simple. It only takes two to three minutes. 

View full review »
it_user496968 - PeerSpot reviewer
Penetration Testing Advisor at a tech services company with 1,001-5,000 employees

Starting Burp only involves running a .jar file. The latest version also comes with a executable installer. Setting up a project can be more complex, involving configuring the proxy, scope and different spidering/scanning options.

View full review »
it_user492585 - PeerSpot reviewer
Information Systems Security Officer at a financial services firm with 1,001-5,000 employees

There is no setup needed. It is a Java app that does not need to be installed.

View full review »
VC
Senior Cyber Security Analyst at a tech services company with 501-1,000 employees

The solution’s initial setup is easy.

View full review »
MM
Cyber Security Specialist at a university with 10,001+ employees

The initial setup is simple and very straightforward. We were not setting up a server, so it took perhaps five minutes to get up to speed and begin using it.

View full review »
reviewer1139067 - PeerSpot reviewer
Works

The initial setup of this solution is very straightforward and easy.

View full review »
KM
IT Security Analyst at a tech services company with 11-50 employees

The initial setup is completely easy. It took a day to deploy.

View full review »
it_user704997 - PeerSpot reviewer
Senior Information Security Analyst at a tech services company with 10,001+ employees

Quite straightforward. Thanks to the availability in executable JAR format -- this makes it a highly portable solution.

View full review »
SD
Lead Software Architect at a tech services company with 201-500 employees

The initial setup is straightforward.

It is very easy to automate. It requires some configuration that has you follow step by step instructions. 

It can take four to five hours to go live.

Anyone with minimal knowledge and training can use this tool.

View full review »
it_user245421 - PeerSpot reviewer
Senior Security Consultant at a tech services company with 501-1,000 employees

It's very straightforward, you just have to double-click a Jar file.

View full review »
SJ
Compliance Manager at a tech services company with 201-500 employees

The initial setup can be complex. It needs to be deployed in between the traffic. They should include some case-scenarios to help, like a scenario-based briefing, that would really help and add a lot of value for the initial application tester. 

View full review »
AB
Security Researcher at a financial services firm with 5,001-10,000 employees

The initial setup is straightforward.

This solution requires no maintenance.

View full review »
AS
IT Auditor & Compliance Officer at a tech vendor with 51-200 employees

The initial setup and deployment are straightforward and take very little time.

Only one person from the IT department is required for deployment and maintenance.

View full review »
AG
Cyber Security Analyst at a tech services company with 11-50 employees

The initial setup was very simple.

View full review »
JA
Security Analyst at a tech services company with 201-500 employees

The initial setup was somewhat complex, to be honest.

View full review »
AR
AVP - Software Quality Assurance at a tech services company with 201-500 employees

The initial setup is straightforward. Deployment doesn't take more than two to three hours.

View full review »
Buyer's Guide
PortSwigger Burp Suite Professional
April 2024
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,740 professionals have used our research since 2012.