HomeIntelligenceBrief
BREACH BRIEF⚪ Informational ThreatIntel

PortSwigger Launches Burp AT: Agentic AI for Professional Penetration Testing

PortSwigger’s Burp AT adds agentic AI to Burp Suite, letting testers delegate investigative tasks while the platform enforces scope, permissions, and evidence collection—key for SOC 2 audit readiness.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 helpnetsecurity.com
Severity
Informational
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

PortSwigger Launches Burp AT: Agentic AI for Professional Penetration Testing

What Happened — PortSwigger announced the public beta of Burp AT, an extension to Burp Suite that lets penetration testers delegate defined investigative tasks to AI agents. The agents operate within Burp’s tooling, project context, and enforced scope/permission rules, while the human tester retains final judgment and validation of findings.

Why It Matters for Compliance & Audit Readiness

  • SOC 2‑type assessments require demonstrable, repeatable testing methodologies and immutable evidence of security testing activities; Burp AT’s built‑in scope enforcement and evidence preservation help map AI‑driven tests to those audit controls.
  • Continuous‑compliance programs must track who performed each test, what was tested, and the outcome; the platform’s project‑wide context and audit‑ready logs provide that traceability without manual stitching.
  • Control‑mapping teams can now align AI‑generated test steps to specific security controls (e.g., CC6.1 – Change Management, CC7.2 – Vulnerability Management) and capture evidence automatically.

Who Is Affected — Application security teams, penetration‑testing service providers, and SaaS developers that rely on web‑application security assessments.

Recommended Actions

  • Review your SOC 2 testing policies to ensure AI‑assisted activities are covered by scope and approval controls.
  • Map Burp AT’s task‑specific skills to your existing vulnerability‑management controls and document the evidence collection workflow.
  • Pilot the beta in a controlled environment, validate that audit logs meet your evidence‑retention requirements, and adjust approval rules as needed.

Source: Help Net Security

Technical Notes — Burp AT integrates with Burp Suite’s web‑security tools (scanner, intruder, repeater, etc.) and leverages large‑language‑model agents that can form hypotheses, issue requests, and interpret responses. Scope, permissions, and approval rules are enforced by the suite, preserving a tamper‑evident record of each AI‑driven action. Source: same article

📰 Original Source
https://www.helpnetsecurity.com/2026/07/30/portswigger-burp-at/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →