If your target uses a basic username and password-based login system, you can specify login credentials for Burp Scanner to use when scanning the site. This enables Burp Scanner to log in to the target application and access content that only authenticated users can usually see.
Adding a username and password works well for simple login forms with only two input fields. However, if your target uses a more complex login mechanism then you should use recorded login sequences instead.
You cannot use both credential types on a single scan.
You can manage login credentials from the Application login tab of the scan launcher. From here, you can:
To specify username and password login credentials when configuring a scan:
Burp Suite adds the specified credentials to the list. You can specify more than one set of login credentials for each scan.
To edit an existing credential set, select it and click Edit. You can edit the following details:
To delete an existing credential set, select it and click Delete.
There are some additional options relating to authenticated scanning in the Testing login functions section of the crawl configuration.
From here, you can configure: