logo

Associating an identity with HTTP requests – a Burp extension

ID: 3af703f3-dfc5-53a1-b544-c0447a78bfbc

STIX ID: report--3af703f3-dfc5-53a1-b544-c0447a78bfbc

Feed Name: SensePost Blog

Date Published: 2014-06-05

Date Updated: 2026-04-29

...
...

This document introduces a Burp Suite extension called Identity (BurpId) that lets analysts map web requests to specific users by defining rules for login/logout detection and session cookies, then pivot those requests across parameters and users to assess access-control behavior. It supports creating rules to identify successful vs. failed actions, links repeated sessions to identities, and previews planned features like automated session token substitution and status-driven visualizations to accelerate access-control testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.