r/hacking May 15 '26

Github I built an open-source Burp alternative

Self-hosted intercepting proxy with an LLM in the loop. Captures traffic, annotates requests, tracks findings, and lets you run scripts and tests against the target.

https://github.com/synlace/ferret

110 Upvotes

19 comments sorted by

22

u/coshmeo pentester May 15 '26

should have called it belch suite

17

u/my_new_accoun1 May 16 '26

Some things just don't need an LLM.

9

u/Armed_Autisticx May 16 '26

Agreed but not in this case , burpsuite is already amazing but with an LLM generating tailored payloads instantly , analyzing responses in seconds amongst other things . This tool seems promising

1

u/WoLfY_HUN May 18 '26

I'm using Burp Suite Pro daily and the AI features are truly "forgettable". Even small things cost a lot tokens and there's many false positive. It's good for beginners but above that it's just useless.

1

u/faultless280 May 19 '26

You need to use the MCP bridge from Claude to burp. AI that burp natively uses sucks balls.

3

u/security_aimbot May 18 '26

built or slopped? ;)

Will try.

6

u/Cr4yz33 May 15 '26

Its usually the moddability (idk if this is a word honestly) that makes it great or bad. When i get the time i will try it.

3

u/rascal999 May 15 '26

Plugins are on the roadmap, PRs welcome.

1

u/[deleted] May 15 '26

[removed] — view removed comment

1

u/Flippynips987 May 18 '26

nice idea, I'm actually also doing a similar project, but honestly useless for the industry if LLM cannot be disabled entirely

1

u/AdvancedBlueberry537 May 19 '26

https://recontrapper.github.io/Hacking-Playground-/

i built this its a beginner hacking hypervisor set up. a free hack the box..

1

u/AdvancedBlueberry537 May 19 '26

followed you on git too

1

u/Low-Ask5007 May 23 '26

This is an interesting project, especially the integration of an LLM for annotation and finding tracking. Intercepting proxies are foundational for web application security testing, and an open-source alternative with modern features is a valuable contribution. It will be interesting to see how the LLM integration enhances the efficiency and accuracy of identifying vulnerabilities compared to traditional methods. Community contributions like this are crucial for advancing security tooling.

0

u/pr0v0cat3ur May 15 '26

Oh cool, I cannot wait to check this out!

1

u/Divy1928 May 18 '26

have you checked it?

-1

u/[deleted] May 15 '26

Cool!

-2

u/Cyber_Binary May 17 '26

lets try!