burp2model
Turn a Burp Suite history into an evidence-backed model of a web app.
Hosts, pages, scripts, endpoints, parameters, auth, and the gaps in what you captured, each tied to the request that proves it. Query it locally with no AI, or hand the model to your own AI instead of raw traffic.
Why
Pasting a multi-megabyte bundle and a HAR file into a chat model tends to produce invented endpoints and generic advice, and it ships your session cookies along with the bytes. burp2model builds a model first: every endpoint is tied to a real request, paths your code references but never calls are called out, and what the capture could not show is listed rather than guessed at. It is a model builder, not a scanner or exploit tool.
Install
pip install burp2model # Python 3.9+, no dependencies
Quickstart
# In Burp: Proxy → HTTP history → select all → right-click → Save items → history.xml
# (a Logger++ CSV export works too)
burp2model history.xml --webapp shop
# Ask it questions, deterministically, with no language model involved
burp2model query shop "code vs runtime"
burp2model query shop list-apis
burp2model query shop help # every question it answers
# No Burp? Crawl the running app instead (authorized targets only)
burp2model crawl https://shop.example.com/ -w shop --yes
Try it without a capture of your own: ./demo.sh builds the bundled sample.
Output goes to burp2model-out/shop/:
| File | What it is |
|---|---|
report.html |
Self-contained interactive report: map, Ask box, Copy for AI, redacted request/response per request |
model.json |
The six-layer graph with an evidence table mapping every ev_N to its request |
context.json |
The evidence package to give an LLM instead of raw traffic |
graph.db |
The model as one SQLite file, queryable with burp2model q |
graph.json, graph.graphml |
The graph for D3, Cytoscape, Gephi, yEd |
What you get
- A six-layer model: edge, routes, client code, APIs (each labelled
BOTH,STATIC_ONLYorRUNTIME_ONLY), trust, and named unknowns. Every edge isOBSERVEDorINFERRED, never mixed. - Queries with no AI: every answer cites evidence ids and ends
Model call: none. A question it cannot answer is refused, not guessed. - Copy for AI: a rules-first context package your own model can reason over.
- Graph and BQL: a SQLite graph with a filter-and-path query language.
- Redaction first: secrets, cookies, tokens and PII are masked before anything is written. Secrets are kept only as a keyed fingerprint (kind, length, entropy).
- Deterministic: the same input gives byte-identical output.
Commands
| Command | Purpose |
|---|---|
build (default) |
Build the model from a Burp XML or Logger++ CSV export |
crawl |
Build the model from a running app in a real browser, no Burp needed |
query |
Ask the model a factual question, no AI |
q |
Query graph.db with BQL |
graph |
Reason over the graph, or export GraphML / Cypher / JSON |
cross-role |
Compare what two roles reached |
gaps, changes, falsify, methodology |
Analyst commands over the model |
osint |
External recon for a host (authorized targets only) |
Run burp2model <command> --help for options.
Boundaries
| It does | It never |
|---|---|
| Read a capture you exported | Upload, forward or replay it |
| Mask every value before the first write | Store a token, cookie, key or PII value |
| Say what it could not observe | Claim coverage it did not have |
| Offer hypotheses and the evidence to test them | Call anything a vulnerability |
build also runs light external recon (DNS, TLS, headers) on the primary host. Turn it off
with --no-osint or BURP2MODEL_OFFLINE=1. Only use crawl and osint on systems you are
authorized to test.
CI plants fake secrets in the bundled samples and fails if any appears in any output.
Documentation
Full site: falc0n-researcher.github.io/burp2model
- How it works: the pipeline, layer by layer
- Exporting from Burp
- Crawling a running app, including scripted journeys
- Querying the model: query, BQL, graph, methodology
- Using it with AI
- Measurements: what Copy for AI saves, and when it doesn't
- Tested apps
- Skill: a no-install playbook that lets any capable AI run the method
- Changelog
License
Apache-2.0. See LICENSE.
Metadata
Release files for burp2model 1.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| burp2model-1.0.0.tar.gz | 1.5 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| burp2model-1.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 1.7 MB
Release files / burp2model-1.0.0.tar.gz
| Download URL | burp2model-1.0.0.tar.gz |
|---|---|
| Size | 1.5 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
901b722d87c6e0addb0702fbbef8c57a1b83acf160c8acb4a715325101bfcdf4
|
|
BLAKE2b-256 checksum How to use checksums |
a3fd92d1e263d3056056a9b38db22717d298a44999b9f4da043999d2f98c91d9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.10.18
|
Release files / burp2model-1.0.0-py3-none-any.whl
| Download URL | burp2model-1.0.0-py3-none-any.whl |
|---|---|
| Size | 265.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
be4853f599b66551f167b0a74023c51a8b126dd5836ac14d3d9a766d06cac047
|
|
BLAKE2b-256 checksum How to use checksums |
0af981bec480d916b41acbf37715b7fd685a3b82f1ebeb4bb9a21ac77faec973
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.10.18
|