AI-Powered Passive Vulnerability Analysis for Burp Suite
Intelligent β’ Silent β’ Adaptive β’ Comprehensive
π Getting Started β’ π Documentation β’ π§ Configuration β’ π Benchmarks β’ β¬οΈ Upgrade to Pro
Note: This is the Community Edition. Commercial and Professional Editions with advanced features are available separately.
SILENTCHAIN AIβ’ - Community Edition is a Burp Suite extension that brings the power of artificial intelligence to web application security testing. Using advanced AI models, SILENTCHAIN performs intelligent passive analysis of HTTP traffic to identify OWASP Top 10 vulnerabilities, security misconfigurations, and potential attack vectors.
Traditional security scanners rely on predefined signatures and patterns. SILENTCHAIN AIβ’ goes beyond with:
- π§ AI-Powered Analysis: Leverages state-of-the-art language models (Burp AI, Ollama, OpenAI, Claude, Gemini, Azure) for intelligent vulnerability detection
- π― Context-Aware Detection: Understands application logic and business context, not just pattern matching
- β‘ Real-Time Scanning: Analyzes traffic as it flows through Burp's proxy
- π Professional Reporting: Generates detailed findings with CWE, OWASP mappings, and remediation guidance
- π Zero False Positives: AI validation reduces noise and focuses on real vulnerabilities
- π Community Edition: Free passive analysis capabilities
- Automatic analysis of in-scope traffic as a Burp Scanner passive scan check (for example Burp's live passive audit of Proxy traffic); the passive check never sends requests to the target
- On-demand analysis of any request from the right-click menu
- OWASP Top 10 vulnerability detection
- CWE-mapped security findings
- Intelligent confidence scoring
- Modern, intuitive dashboard
- Live findings panel with severity color-coding
- Task tracking and management
- Integrated console logging
- Burp AI (default; zero-config; prompts are sent through Burp to PortSwigger's Burp AI service and use Burp AI credits)
- Ollama (local, free, privacy-focused)
- OpenAI (GPT-4 / GPT-4o)
- Claude (Anthropic)
- Gemini (Google)
- Azure OpenAI / Foundry
- Detailed vulnerability descriptions
- Affected parameters identification
- CWE and OWASP mappings
- Remediation recommendations
- Direct links to security resources
- Always on: credentials are replaced with
[REDACTED]before any AI request, whatever the sanitizer setting: cookie values,Authorizationand API-key/token header values, and parameters / JSON fields named like credentials (password, token, api_key, session...) in the URL, URL-bearing headers (Referer, Location), the parameter sample and the request and response bodies (form, JSON including nested values, multipart, XML, HTML form inputs) (names,Set-Cookieattributes and theAuthorizationscheme are kept) - Sanitizer enabled by default - additionally redacts secrets and PII in the rest of the exchange and neutralizes prompt-injection patterns, for every provider (Burp AI, Ollama and the cloud providers)
- Bidirectional redaction: sensitive values are replaced with
[REDACTED_*]placeholders before sending to the AI provider, then restored in the response - Detects and redacts:
- API keys - OpenAI (
sk-), GitHub (ghp_), AWS (AKIA), GitLab (glpat-), Slack (xoxb-) - Authorization headers - Bearer tokens, Basic auth
- Credentials - password/secret/token fields,
user:pass@hostURIs - Session cookies - session IDs, CSRF tokens, JWTs, auth tokens
- Email addresses
- IP addresses & hostnames - target infrastructure details
- API keys - OpenAI (
- The sanitizer can be toggled off in Settings for advanced users (header redaction still applies)
- AI output is treated as untrusted: finding titles are sanitized and SILENTCHAIN's tables never render HTML
SILENTCHAIN AIβ’ detects a wide range of security issues including:
| Category | Vulnerabilities |
|---|---|
| Injection | SQL Injection, NoSQL Injection, Command Injection, LDAP Injection, XPath Injection |
| Cross-Site Scripting | Reflected XSS, Stored XSS, DOM-based XSS |
| Authentication | Broken Authentication, Session Management Issues, Credential Exposure |
| Access Control | IDOR, Broken Authorization, Privilege Escalation |
| Cryptography | Weak Encryption, Insecure SSL/TLS, Sensitive Data Exposure |
| Configuration | Security Misconfigurations, Default Credentials, Debug Enabled |
| XXE | XML External Entity Attacks |
| Deserialization | Insecure Deserialization |
| Components | Vulnerable Dependencies, Outdated Libraries |
- Burp Suite Professional 2025.8 or later. Burp Suite Community Edition and Burp Suite DAST are not supported: on Community Edition the extension loads, logs why, and stays idle.
- 'Use AI' enabled for SILENTCHAIN in Extensions β Installed. It is off by default for manually loaded extensions (Burp asks when you install from the BApp Store). This gates every provider, including Ollama; if AI is turned off globally in Burp's AI settings, nothing is sent.
- Java 21 runtime (bundled with current Burp releases)
- An AI provider (one of the following):
- Burp AI (default; zero-config; uses Burp AI credits)
- Ollama (free, local, privacy-focused)
- OpenAI API key
- Claude (Anthropic) API key
- Gemini (Google) API key
- Azure OpenAI / Foundry
-
Download the extension
- Grab the latest
silentchain-community-edition.jarfrom GitHub Releases (this link always serves the newest build). Specific versions (silentchain-community-edition-X.Y.Z.jar) are on the Releases page. - Or build it from source:
./gradlew shadowJarproducesbuild/libs/silentchain-community-edition-<version>.jar(the Gradle wrapper is included; the JDK 21 toolchain is auto-provisioned if missing).
- Grab the latest
-
Load it in Burp Suite
- Go to Extensions β Installed β Add
- Set Extension type: Java
- Select the downloaded
.jarand click Next - In Extensions β Installed, enable Use AI for SILENTCHAIN (required for every provider)
-
Configure your AI provider
- Click Settings on the SILENTCHAIN Community tab, or search Burp's Settings window for
SILENTCHAIN - Pick a provider - Burp AI works with no configuration. For an external provider, set the API URL / key / model and click Test Connection. Changes apply immediately (there is no Save button).
- Click Settings on the SILENTCHAIN Community tab, or search Burp's Settings window for
-
Start scanning
- Set your target scope in Burp (Target β Scope)
- Turn on passive analysis with Start Scanning on the SILENTCHAIN Community tab (it is OFF by default), then browse the target through Burp's proxy (Burp's default live passive audit of Proxy traffic feeds in-scope items to SILENTCHAIN) - or right-click any request β Analyze Request (SILENTCHAIN) for on-demand analysis
- Findings appear in the SILENTCHAIN Community tab and as native Burp issues (Dashboard / Target β Site map issues)
- Cross-platform: Windows, macOS, Linux
- Burp Suite Professional 2025.8 or later (Community Edition and Burp Suite DAST are not supported)
- Java 21 (bundled with current Burp releases)
SILENTCHAIN's settings live in Burp's Settings window: click Settings on the
SILENTCHAIN Community tab, or search Burp's Settings for SILENTCHAIN. Changes apply
immediately (there is no Save or Cancel). Each provider keeps its own API URL, API key and
model, so switching provider never reuses another provider's key. Settings from earlier
versions are migrated automatically.
Every provider, including Ollama, only runs when Use AI is enabled for SILENTCHAIN in Extensions β Installed.
Requires Burp Suite Professional. No API URL or key needed - prompts are sent through Burp to PortSwigger's Burp AI service under PortSwigger's AI data-handling policy and consume Burp AI credits from your account.
- Provider:
Burp AI - API URL / Key / Model: (not required)
Free, local, no API keys required
-
Install Ollama:
# macOS/Linux curl -fsSL https://ollama.ai/install.sh | sh # Windows # Download from https://ollama.ai/download
-
Pull a model:
ollama pull deepseek-r1 # or ollama pull llama3 -
Configure SILENTCHAIN:
- Provider:
Ollama - API URL:
http://localhost:11434(the default; SILENTCHAIN calls/api/chaton the host you configure) - API Key: (not used)
- Model:
deepseek-r1:latest
- Provider:
-
Get API key from platform.openai.com
-
Configure SILENTCHAIN:
- Provider:
OpenAI - API URL:
https://api.openai.com/v1 - API Key:
sk-...(sent as a Bearer token) - Model:
gpt-4orgpt-3.5-turbo
- Provider:
-
Get API key from console.anthropic.com
-
Configure SILENTCHAIN:
- Provider:
Claude - API URL:
https://api.anthropic.com/v1 - API Key: Your Anthropic API key (sent in the
x-api-keyheader) - Model:
claude-3-5-sonnet-20241022
- Provider:
-
Get API key from makersuite.google.com
-
Configure SILENTCHAIN:
- Provider:
Gemini - API URL:
https://generativelanguage.googleapis.com/v1 - API Key: Your Google API key (sent in the
x-goog-api-keyheader, never in the URL) - Model:
gemini-1.5-pro
- Provider:
-
Create a model deployment in your Azure OpenAI / Foundry resource
-
Configure SILENTCHAIN:
- Provider:
Azure Foundry - API URL:
https://YOUR-RESOURCE.openai.azure.com - API Key: Your Azure key (sent in the
api-keyheader) - Model: your deployment name
- Azure API Version: e.g.
2024-06-01(the default)
- Provider:
| Setting | Description | Default |
|---|---|---|
| AI Provider | AI service to use | Burp AI |
| Passive Analysis | Automatically analyze in-scope items that Burp's live audit tasks and scans pass to SILENTCHAIN's passive scan check | Off (opt-in) |
| API URL | Provider endpoint (external providers; stored per provider) | (provider default) |
| API Key | Authentication key (external providers; stored per provider) | (empty) |
| Model | AI model name (external providers; stored per provider) | (provider default) |
| Max Tokens | Response length limit | 2048 |
| Third-party AI timeout (s) | Response timeout for third-party providers and for the right-click response fetch (Burp AI uses Burp's own limits) | 120 |
| Sanitizer | Redact secrets/PII and neutralize prompt injection before sending (credential headers are always redacted) | On |
| Per-host Requests/Minute | Passive analyses per host per minute | 10 |
| URL Dedup Window (min) | Skip a method + URL already analyzed passively within this window | 60 |
| Verbose Logging | Enable detailed logs | On |
- Burp Scanner passive check: Burp's live audit tasks and scans (for example Burp's default live passive audit of Proxy traffic) hand each audited request/response to SILENTCHAIN's passive scan check. When no other analysis is queued, the check waits up to 60 seconds and returns the findings to Burp Scanner; otherwise the findings are added to Burp's issues when the analysis completes. The passive check never sends requests to the target. Burp scans and crawls also feed in-scope items, so AI usage can rise during scans.
- Scope Filtering: Passive analysis only covers in-scope targets (configure in Burp's Target Scope), and only runs while SILENTCHAIN's passive analysis is ON and its tasks are not paused
- Throttling: Per-URL de-duplication, a per-host rate limit (default 10/min) and a passive backlog cap (16) bound how much traffic reaches the AI
- AI Analysis: Sends a capped, redacted summary of the request/response to the selected provider, only when Use AI is enabled for SILENTCHAIN in Burp
- Vulnerability Detection: AI identifies security issues based on OWASP Top 10 patterns
- Finding Generation: Creates Burp issues with severity, confidence, and remediation; findings below 50% AI confidence are dropped
| Level | AI Confidence | Meaning |
|---|---|---|
| Certain | 90-100% | High confidence, verified vulnerability pattern |
| Firm | 75-89% | Strong indicators, likely vulnerable |
| Tentative | 50-74% | Potential issue, requires manual verification |
- Total Requests: Items the passive check considered
- Analyzed: Analyses started (passive and right-click)
- Skipped (Duplicate): Prevented redundant analysis
- Skipped (Rate Limit): Over the per-host rate limit
- Skipped (Low Confidence): Findings below 50% AI confidence
- Findings Created: Total vulnerabilities found
- Skipped (Backlog): Passive items dropped because the backlog was full (replaces the old "Cache Hits" counter)
- Errors: Analysis failures
- Shows queued and running analyses
- Status tracking (Queued, Analyzing, Paused, Completed, Skipped, Cancelled, Error)
- Duration timing
- Cancel All Tasks, Pause All Tasks / Resume All Tasks and Stop Scanning also apply to queued work
- A failed analysis shows as an Error task, with a stack trace in the extension's Errors tab (Extensions β Installed)
- All detected vulnerabilities
- Severity-based color coding:
- π΄ High - Critical vulnerabilities
- π Medium - Important security issues
- π‘ Low - Minor vulnerabilities
- π΅ Information - Security notes
- Confidence levels
- Discovery timestamps
- Real-time logging
- AI connection status
- Analysis progress
- Error messages
-
Set Target Scope
Burp β Target β Scope β Add Example: https://example.com/* -
Browse Application
- Click Start Scanning on the SILENTCHAIN Community tab (passive analysis is OFF by default)
- Configure browser proxy to Burp (127.0.0.1:8080)
- Navigate through the target application
- SILENTCHAIN analyzes in-scope traffic in the background, through Burp's live passive audit of Proxy traffic (Burp's default). If Burp pauses its tasks (for example when a project is reopened), SILENTCHAIN's passive analysis pauses too.
-
Review Findings
- Check
SILENTCHAINβFindingspanel - Or Burp's
Dashboard/TargetβSite mapissues (integrated with Burp)
- Check
Right-click any request in:
- Proxy History
- Site Map
- Repeater
Select: Analyze Request (SILENTCHAIN)
This forces analysis even if the URL was previously scanned. If the item has no response, SILENTCHAIN sends the request once to capture one. The first analysis asks for data-handling consent.
Repeater traffic is analyzed automatically only if a live audit task covers Repeater; otherwise use the context menu.
- Open the finding in Burp's issue view (
DashboardorTargetβSite map) - Review the detailed description and evidence
- Check affected parameters
- Follow the CWE/OWASP references for more information
- Manually test using Burp Repeater/Intruder
| Feature | Community (Free) | Professional |
|---|---|---|
| AI-Powered Passive Analysis | β | β |
| OWASP Top 10 Detection | β | β |
| Multi-AI Support | β | β |
| Professional UI | β | β |
| CWE/OWASP Mapping | β | β |
| Deduplication | β | β |
| Phase 2 Active Verification | β | β |
| Advanced Payload Libraries | β | β |
| WAF Detection & Evasion | β | β |
| Out-of-Band (OOB) Testing | β | β |
| Burp Intruder Integration | β | β |
| Automatic Fuzzing | β | β |
| Priority Support | β | β |
SILENTCHAIN Professional adds active verification capabilities:
- π― Phase 2 Verification: Automatically validates findings with exploit payloads
- π‘οΈ WAF Detection: Identifies and adapts to web application firewalls
- π Curated Payload Libraries: Battle-tested OWASP payloads
- π OOB Testing: Detects blind vulnerabilities (SSRF, XXE, etc.)
- π Burp Intruder Integration: Auto-configures fuzzing attacks
- β‘ Smart Fuzzing: AI-generated payloads for maximum coverage
See it in action - watch the full SILENTCHAIN Professional demo to see AI-powered active verification, WAF evasion, and automated fuzzing at work.
Contact us for commercial licensing and professional editions: support@sn1persecurity.com
Solution:
- Make sure Use AI is enabled for SILENTCHAIN in Extensions β Installed and AI is not turned off in Burp's AI settings (required for every provider, including Ollama)
- Check AI provider is running (Ollama:
ollama list) - Verify API URL is correct
- For cloud providers, confirm API key is valid
- Check network connectivity
Solution:
- Verify target is in scope (
TargetβScope) - Make sure passive analysis is ON (Start Scanning), Use AI is enabled, and SILENTCHAIN's and Burp's tasks are not paused
- Ensure traffic is flowing through Burp Proxy and a live passive audit task covers it (Burp's default). The Runtime Status line shows
Waiting for Burp Scanner (needs a live audit task)until Burp first calls the passive check - Check Console for errors
- Try manual analysis (right-click β
Analyze Request (SILENTCHAIN))
Solution:
- Confirm the extension type was set to Java when loading the
.jar - Verify you are running Burp Suite Professional 2025.8 or later with a Java 21 runtime (on Community Edition the extension loads but stays idle and logs why)
- Review Extensions β Installed β (SILENTCHAIN Community Edition) β Errors / Output
- Re-download the
.jarif the file may be corrupted
Solution:
- Reduce Max Tokens setting (Settings β AI Provider)
- Clear completed tasks regularly
- Use lighter AI models (e.g.,
llama3instead ofdeepseek-r1)
Enable verbose logging (on by default):
- SILENTCHAIN's settings (Burp
Settingswindow) βAdvanced - Check
Verbose Logging - Review Console for detailed output
This project does not accept outside contributions. See CONTRIBUTING.md for details.
- Check existing issues
- Create a new issue with:
- Burp Suite version
- SILENTCHAIN version
- AI provider/model
- Steps to reproduce
- Error messages (from Console)
Open an issue with tag enhancement:
- Describe the feature
- Explain use case
- Provide examples if possible
SILENTCHAIN AIβ’ CE is source-visible but proprietary software. By using this software, you agree to the terms in the LICENSE file.
PortSwigger Ltd. is granted explicit permission to redistribute, host, and bundle this software within Burp Suite and the BApp Store free of charge to users. All other redistribution is prohibited without written permission.
Do not use this software for unauthorized access or activities outside systems you own or have explicit permission to test.
See PRIVACY.md for the full privacy notice, including the per-provider data-residency table and your responsibilities when scanning sensitive targets.
SILENTCHAIN analyzes HTTP requests and responses intercepted by Burp Suite. Depending on the AI provider you select, this data may be transmitted to PortSwigger's Burp AI service or to third-party cloud services. Nothing is sent to any provider unless Use AI is enabled for SILENTCHAIN in Burp.
| Provider | Data Destination | Data Transmitted |
|---|---|---|
| Ollama | The Ollama host you configure (default http://localhost:11434) |
Nothing leaves your machine when Ollama runs locally |
| OpenAI | OpenAI, L.L.C. servers (api.openai.com) |
HTTP request/response content from in-scope targets |
| Claude | Anthropic, PBC servers (api.anthropic.com) |
HTTP request/response content from in-scope targets |
| Gemini | Google LLC servers (generativelanguage.googleapis.com) |
HTTP request/response content from in-scope targets |
| Azure OpenAI | Your Azure OpenAI / Foundry resource | HTTP request/response content from in-scope targets |
| Burp AI | PortSwigger's Burp AI service, via Burp, under PortSwigger's AI data-handling policy (uses Burp AI credits) | HTTP request/response content from in-scope targets |
For each analyzed request, SILENTCHAIN sends a capped summary to the selected provider: the URL, method, status and MIME type, a sample of up to 5 parameters, the first 10 request and response headers, and the request and response bodies (truncated). Both passive and right-click analysis only send in-scope targets. Credentials are always replaced with [REDACTED] before any AI request, whatever the sanitizer setting: cookie values (in the Cookie / Set-Cookie headers and in the parameter sample), Authorization-style and API-key/token header values, and parameters, JSON fields and multipart fields named like credentials (password, token, api_key, session...) in the URL, URL-bearing headers (Referer, Location), the parameter sample and the request and response bodies (form, JSON including nested values, multipart, XML, HTML form inputs). Cookie and parameter names, Set-Cookie attributes and the Authorization scheme are kept, and an empty value stays empty so a missing token is still visible. The built-in DataSanitizer (enabled by default, applied to every provider) also redacts API keys, credentials, session tokens, and other sensitive patterns before transmission, but it cannot guarantee removal of all sensitive data from request/response bodies.
Do not submit regulated data to cloud AI providers. This includes:
- PHI (Protected Health Information) under HIPAA
- PCI DSS cardholder data (credit card numbers, CVVs, etc.)
- EU personal data subject to GDPR (Art. 13 requires disclosure of sub-processors)
- CCPA-covered personal information (Cal. Civ. Code 1798.100 et seq.)
If your target application processes any of the above data categories, you must use a local AI provider (Ollama) or ensure you have appropriate data processing agreements with the cloud provider and legal authorization to transmit such data.
SILENTCHAIN itself does not collect, store, or transmit any usage data, telemetry, or analytics. All data flows are directly between your Burp Suite instance and your selected AI provider.
- Use Ollama on your own machine for sensitive or regulated environments (100% local, private)
- Enable DataSanitizer (on by default) when using cloud providers
- Review your AI provider's data retention and privacy policies before use
- Never test production systems without authorization
- Sanitize findings and logs before sharing externally
- π Documentation: Documentation
- π Issues: GitHub Issues
- βοΈ Email: support@silentchain.ai
- β Star this repository
- ποΈ Watch for updates
- π¦ X (Twitter): @silentchainai
Built by:
- @xer0dayz at @Sn1perSecurity LLC
Built with:
- Burp Suite by PortSwigger
- Ollama for local AI
- OpenAI for GPT models
- Anthropic for Claude
- Google for Gemini
Inspired by the security community's dedication to making the web safer.
"SILENTCHAIN AIβ’", "SILENTCHAINβ’", and the SILENTCHAIN AI logo are trademarks of SN1PERSECURITY LLC. Unauthorized use is prohibited.
See NOTICE for third-party trademark attributions.
SILENTCHAIN AIβ’ - Intelligent Security Testing for the Modern Web
Website β’ Documentation β’ Professional Edition β’ Professional Demo
Copyright Β© 2026 SN1PERSECURITY LLC. All rights reserved.
