MCP in Burp Suite: From Enumeration to Targeted Exploitation
ID: d6ad1e84-ed40-542c-b15e-ee9a5a76af71
STIX ID: report--d6ad1e84-ed40-542c-b15e-ee9a5a76af71
Feed Name: TrustedSec blog
This post introduces MCP-ASD, a Burp Suite extension designed to help penetration testers discover, enumerate, and interact with MCP (Model Context Protocol) servers used by LLM integrations. It details passive and light active detection of SSE/WebSocket endpoints, authentication handling (tokens, headers, mTLS), an internal bridge to make SSE/WebSocket interactions work with Burp Repeater/Intruder, UI features for enumerating resources/tools/prompts, and links to the repository and releases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
