Skip to content

Burp Scanner Rules

Custom Scanner Rules in Burp Suite

Custom scanner rules in Burp Suite allow red teams to define tailored logic for detecting specific web application vulnerabilities, such as hardcoded credentials, insecure API endpoints, or misconfigured headers. These rules extend the built-in scanner’s capabilities by enabling precise pattern matching and conditional checks against HTTP requests and responses.


Creating a Custom Scanner Rule

A custom scanner rule is defined using an XML file that specifies the target pattern, issue description, and remediation guidance. Rules are structured with three core components:

  1. Target: A regex pattern to match HTTP requests/responses.
  2. Issue: A description of the vulnerability and its risk level.
  3. Fix: Guidance for mitigating the issue.

Example: Detecting Hardcoded Credentials

<issue>
  <name>Hardcoded Credentials in HTTP Request</name>
  <description>Detected hardcoded credentials in an HTTP request, which may indicate insecure authentication mechanisms.</description>
  <cwe>798</cwe>
  <cvss>7.5</cvss>
  <target>
    <request>
      <method>POST</method>
      <url>.*\/login.*</url>
      <body>username=.*&amp;password=.*</body>
    </request>
  </target>
  <fix>
    <text>Store credentials securely using encrypted storage or environment variables. Avoid transmitting credentials in plaintext.</text>
  </fix>
</issue>

Key Elements

  • <cwe> and <cvss>: Map the issue to standard vulnerability references.
  • <target>: Use regex to match specific request/response patterns (e.g., POST /login with hardcoded credentials).
  • <body>: Analyze request payloads for sensitive data.

Deploying Custom Rules

  1. Save the Rule File: Save the XML file with a .xml extension (e.g., hardcoded_credentials.xml).
  2. Import into Burp Suite:
  3. Open Burp Suite and navigate to Scanner > Scanner Settings.
  4. Click Add and select the XML file.
  5. Enable the rule and restart the scanner.
  6. Test in a Lab Environment:
  7. Use a controlled test target (e.g., a vulnerable web app) to validate the rule’s accuracy.
  8. Monitor the Scanner Results tab for matches.

Example: Running a Scan with Custom Rules

# Example command for a Burp Suite scan (via CLI or script)
burp-scanner -target http://vulnerable-app.com -rules hardcoded_credentials.xml

Advanced Techniques

  • Regex Optimization: Use non-greedy quantifiers (.*?) to avoid overmatching. For example, .*?username=.*?password=.*? for payloads.
  • Combining Conditions: Use <and> or <or> tags to enforce multiple criteria (e.g., matching a specific endpoint and a payload pattern).
  • Dynamic Rule Creation: Leverage Burp Suite’s API (via Python scripts) to programmatically generate rules based on runtime data.

Troubleshooting Common Issues

  • False Positives: Refine regex patterns to reduce noise (e.g., exclude benign cases like username=admin).
  • Syntax Errors: Validate XML structure using an XML validator or Burp’s built-in parser.
  • Rule Ignored: Ensure the rule is enabled in Scanner Settings and the target is within the scan scope.

Key takeaways

  • Custom scanner rules extend Burp Suite’s capabilities for targeted vulnerability detection.
  • Rules are defined in XML with target patterns, issue descriptions, and remediation guidance.
  • Deployment requires importing rules into Burp Suite and validating them in controlled environments.
  • Advanced techniques like regex optimization and API integration enhance rule precision and flexibility.
  • Regular testing and debugging are essential to minimize false positives and ensure accuracy.