As we reach the end of September 2024, ThreadFix version 3.x on-premises has officially reached its End-of-Life. Therefore, there is no longer support or updates for this version of the product. We have fully transitioned our product and development teams to focus ThreadFix SaaS and migrating all customers over from the on-premises versions. Our Customer Success and Support teams are here to help you in migrating to ThreadFix SaaS and maximizing the value you see from this improved offering from Coalfire. This is the next phase of ThreadFix and our team is looking forward to continuing to support you on this journey.

BURP Suite (ThreadFix 3.X)

You will learn

How to generate a Burp Suite report and upload it to ThreadFix.

Prerequisites

Audience: IT Professional
Difficulty: Basic
Time needed: Approximately 10 minutes
Tools required: N/A

Generate Results

  1. After launching BURP Suite Professional, there are three options for obtaining results to generate a report. Select any of the available options below:

    • Temporary project

    • New project on disk

    • Open existing project

       

  2. From the configuration selection screen, select Use Burp defaults and click the Start Burp button.

     

  3. Click the Proxy tab and select the Options sub-tab. Confirm the Proxy is running.

     

  4. Open Google Chrome and set the Proxy through the Settings tab. Set the port to the one used in BURP:

     

  5. From the Proxy tab, select the Intercept sub-tab and select the Interceptor is off button setting:

     

  6. Navigate to the Target in Chrome, select the Target tab, select the URL in Burp, and perform the following procedures:

    1. Run Spider this host

    2. Run the Actively scan this host

    3. Run the Passively scan this host

       

  7. Select the findings in the Issues pane and choose Report selected issues.

     

  8. Select XML for the report format.

     

  9. Select Next until the reporting wizard asks to save the file, then save it to the desired directory.

Upload Results

  1. After generating the report, log in to ThreadFix and navigate to the Teams view, within the Portfolio page. Expand the Team the report will be uploaded to.

     

  2. After picking one of the Team's Applications, select Upload Scan and drag the report into the pane.

     

  3. Once ThreadFix has finished processing the report, the results can be viewed on the Application's view.

     

www.threadfix.it | www.coalfire.com
Copyright © 2024 Coalfire. All rights reserved.

This Information Security Policy is CoalFire - Public: Distribution of this material is not limited.