Edu Garcia

673 posts

Edu Garcia banner
Edu Garcia

Edu Garcia

@egarme

Founder @bountysecurity. CTO at Divisual Project

Katılım Eylül 2011
675 Takip Edilen727 Takipçiler
Sabitlenmiş Tweet
Edu Garcia
Edu Garcia@egarme·
Months of work, finally live. Multi-step scanning was the hardest to build — and the most requested. Real vulns don't live in a single request, so profiles shouldn't either. Time-based detection was the second most asked for. No more switching to Intruder for blind SQLi.
English
1
0
2
161
Edu Garcia
Edu Garcia@egarme·
AI Scanner uses the LLM for targeting. The programmatic engine handles execution. Each does what it's good at. Supports local models via Ollama if you want everything to stay on your machine. x.com/BountySecurity…
Bounty Security@BountySecurity

Burp Bounty Pro v3.1.0 is out. New: AI Scanner. Sends each request to an LLM with structured context extracted from the response. The AI decides which profiles to launch automatically. A new option alongside Active Scan and Smart Scan, not a replacement.

English
0
0
1
176
Edu Garcia
Edu Garcia@egarme·
Been working on this one for a while. A new option that decides what to test and where, on top of everything that already works. Nothing changes. Something gets added. Monday. x.com/BountySecurity…
Bounty Security@BountySecurity

Monday: the biggest update to Burp Bounty Pro since v3.0.0 → A new scanning option that picks its own targets → Everything else stays exactly the same → Full blog post explaining the thinking behind it bountysecurity.ai/pages/burp-bou…

English
1
0
0
71
Edu Garcia
Edu Garcia@egarme·
Launched Burp Bounty Lab a week ago. 🧪 Today it's in @owasp's official directory. 🙌 x.com/BountySecurity…
Bounty Security@BountySecurity

🏆 Burp Bounty Lab is now officially listed in the @owasp Vulnerable Web Applications Directory. One week after launch. 🙌 100+ vulnerable endpoints. Free. Open source. 👉 burpbountylab.com 📋 #burp-bounty-lab" target="_blank" rel="nofollow noopener">vwad.owasp.org/app/#burp-boun… #BugBounty #OWASP #Pentesting

English
0
0
1
115
Edu Garcia
Edu Garcia@egarme·
🧠 The idea behind Smart Scan was simple: What if the scanner could think before it attacks? Instead of testing everything everywhere → it detects the tech stack first, then fires only what matters. 27 rules out of the box. Or build your own. 🛠 x.com/BountySecurity…
Bounty Security@BountySecurity

🧠 Smart Scan in Burp Bounty Pro: 👁 Passive profile detects a technology 📋 Rule condition matches 🎯 Active profiles fire automatically WordPress detected? → WP CVE profiles 🔥 SQLi params found? → SQLi payloads only 💉 Spring Boot spotted? → Spring checks ⚡

English
1
0
2
121
Edu Garcia
Edu Garcia@egarme·
Spent the last few days documenting every single feature in Burp Bounty Pro 3.0.0. 254 profiles. 27 rules. All covered. Not glamorous, but necessary 😅 → docs.bountysecurity.ai
Edu Garcia tweet media
English
0
0
0
78
Edu Garcia
Edu Garcia@egarme·
Months of work, finally live. Multi-step scanning was the hardest to build — and the most requested. Real vulns don't live in a single request, so profiles shouldn't either. Time-based detection was the second most asked for. No more switching to Intruder for blind SQLi.
English
1
0
2
161
Edu Garcia
Edu Garcia@egarme·
I'll be speaking at @EuskalHack Security Congress VIII (May 20-21)! My talk: 𝐆𝐁𝐨𝐮𝐧𝐭𝐲: 𝐀𝐝𝐯𝐚𝐧𝐜𝐢𝐧𝐠 𝐌𝐮𝐥𝐭𝐢-𝐒𝐭𝐞𝐩 𝐖𝐞𝐛 𝐕𝐮𝐥𝐧𝐞𝐫𝐚𝐛𝐢𝐥𝐢𝐭𝐲 𝐒𝐜𝐚𝐧𝐧𝐞𝐫 🔍 where I'll share how this tool works and its most powerful features! 🔐 x.com/EuskalHack/sta…
EuskalHack@EuskalHack

Presentamos a Eduardo Garcia como nuevo ponente confirmado de EuskalHack Security Congress VIII con la charla "GBounty: Advancing Multi-Step Web Vulnerability Scanner" @egarme #ESCVIII #ponentes" target="_blank" rel="nofollow noopener">securitycongress.euskalhack.org/index_es.html#…

English
0
0
2
193
Edu Garcia
Edu Garcia@egarme·
🚀 Claude 3.7 by @AnthropicAI gives me the best results: 💻 Superior in programming 🔐 Excellent in hacking 🛠️ Perfect with GBounty for multistep profiles Coming soon to Bounty Prompt, the Open Source @Burp_Suite extension developed by @BountySecurity . Thoughts? #AI
English
0
1
3
678
Edu Garcia
Edu Garcia@egarme·
✨ 𝐁𝐨𝐮𝐧𝐭𝐲 𝐏𝐫𝐨𝐦𝐩𝐭 𝐯𝟏.𝟏.𝟎 is out now! 🚀 Our Open-Source Burp Suite extension now leverages both 𝐁𝐮𝐫𝐩 𝐀𝐈 & 𝐆𝐫𝐨𝐪 𝐂𝐥𝐨𝐮𝐝 𝐀𝐈 including all its AI models. x.com/BountySecurity…
Bounty Security@BountySecurity

✨ New 𝐁𝐨𝐮𝐧𝐭𝐲 𝐏𝐫𝐨𝐦𝐩𝐭 v1.1.0: AI-powered open source Burp Suite extension now supports 𝐆𝐫𝐨𝐪 𝐂𝐥𝐨𝐮𝐝 AI! It leverages 𝐁𝐮𝐫𝐩 𝐀𝐈 & 𝐆𝐫𝐨𝐪 𝐂𝐥𝐨𝐮𝐝 to speed up security testing with custom prompts, HTTP tags & auto-generated issues. github.com/BountySecurity…

English
0
0
1
83