Skip to main content

burp2model

Turn a Burp Suite history into an evidence-backed model of a web app.

Hosts, pages, scripts, endpoints, parameters, auth, and the gaps in what you captured, each tied to the request that proves it. Query it locally with no AI, or hand the model to your own AI instead of raw traffic.

PyPI License Tests Runs offline Docs

burp2model turning a Burp history into a web-app model

Why

Pasting a multi-megabyte bundle and a HAR file into a chat model tends to produce invented endpoints and generic advice, and it ships your session cookies along with the bytes. burp2model builds a model first: every endpoint is tied to a real request, paths your code references but never calls are called out, and what the capture could not show is listed rather than guessed at. It is a model builder, not a scanner or exploit tool.

Install

pip install burp2model        # Python 3.9+, no dependencies

Quickstart

# In Burp: Proxy → HTTP history → select all → right-click → Save items → history.xml
# (a Logger++ CSV export works too)
burp2model history.xml --webapp shop

# Ask it questions, deterministically, with no language model involved
burp2model query shop "code vs runtime"
burp2model query shop list-apis
burp2model query shop help          # every question it answers

# No Burp? Crawl the running app instead (authorized targets only)
burp2model crawl https://shop.example.com/ -w shop --yes

Try it without a capture of your own: ./demo.sh builds the bundled sample.

Output goes to burp2model-out/shop/:

File What it is
report.html Self-contained interactive report: map, Ask box, Copy for AI, redacted request/response per request
model.json The six-layer graph with an evidence table mapping every ev_N to its request
context.json The evidence package to give an LLM instead of raw traffic
graph.db The model as one SQLite file, queryable with burp2model q
graph.json, graph.graphml The graph for D3, Cytoscape, Gephi, yEd

What you get

  • A six-layer model: edge, routes, client code, APIs (each labelled BOTH, STATIC_ONLY or RUNTIME_ONLY), trust, and named unknowns. Every edge is OBSERVED or INFERRED, never mixed.
  • Queries with no AI: every answer cites evidence ids and ends Model call: none. A question it cannot answer is refused, not guessed.
  • Copy for AI: a rules-first context package your own model can reason over.
  • Graph and BQL: a SQLite graph with a filter-and-path query language.
  • Redaction first: secrets, cookies, tokens and PII are masked before anything is written. Secrets are kept only as a keyed fingerprint (kind, length, entropy).
  • Deterministic: the same input gives byte-identical output.

Commands

Command Purpose
build (default) Build the model from a Burp XML or Logger++ CSV export
crawl Build the model from a running app in a real browser, no Burp needed
query Ask the model a factual question, no AI
q Query graph.db with BQL
graph Reason over the graph, or export GraphML / Cypher / JSON
cross-role Compare what two roles reached
gaps, changes, falsify, methodology Analyst commands over the model
osint External recon for a host (authorized targets only)

Run burp2model <command> --help for options.

Boundaries

It does It never
Read a capture you exported Upload, forward or replay it
Mask every value before the first write Store a token, cookie, key or PII value
Say what it could not observe Claim coverage it did not have
Offer hypotheses and the evidence to test them Call anything a vulnerability

build also runs light external recon (DNS, TLS, headers) on the primary host. Turn it off with --no-osint or BURP2MODEL_OFFLINE=1. Only use crawl and osint on systems you are authorized to test.

CI plants fake secrets in the bundled samples and fails if any appears in any output.

Documentation

Full site: falc0n-researcher.github.io/burp2model

License

Apache-2.0. See LICENSE.

Metadata

Release files for burp2model 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for burp2model 1.0.0
File Size Uploaded
burp2model-1.0.0.tar.gz 1.5 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for burp2model 1.0.0
File Interpreter ABI Platform
burp2model-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 1.7 MB

Release files / burp2model-1.0.0.tar.gz

Download URL burp2model-1.0.0.tar.gz
Size 1.5 MB
Tags Source
SHA-256 checksum
How to use checksums
901b722d87c6e0addb0702fbbef8c57a1b83acf160c8acb4a715325101bfcdf4
BLAKE2b-256 checksum
How to use checksums
a3fd92d1e263d3056056a9b38db22717d298a44999b9f4da043999d2f98c91d9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.10.18

Release files / burp2model-1.0.0-py3-none-any.whl

Download URL burp2model-1.0.0-py3-none-any.whl
Size 265.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
be4853f599b66551f167b0a74023c51a8b126dd5836ac14d3d9a766d06cac047
BLAKE2b-256 checksum
How to use checksums
0af981bec480d916b41acbf37715b7fd685a3b82f1ebeb4bb9a21ac77faec973
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.10.18

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page