logo

MCP in Burp Suite: From Enumeration to Targeted Exploitation

ID: d6ad1e84-ed40-542c-b15e-ee9a5a76af71

STIX ID: report--d6ad1e84-ed40-542c-b15e-ee9a5a76af71

Feed Name: TrustedSec blog

Date Published: 2026-02-03

Date Updated: 2026-05-01

...
...

This post introduces MCP-ASD, a Burp Suite extension designed to help penetration testers discover, enumerate, and interact with MCP (Model Context Protocol) servers used by LLM integrations. It details passive and light active detection of SSE/WebSocket endpoints, authentication handling (tokens, headers, mTLS), an internal bridge to make SSE/WebSocket interactions work with Burp Repeater/Intruder, UI features for enumerating resources/tools/prompts, and links to the repository and releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.