Adding custom scan checks to scans

You can use custom scan checks for web applications or API-only scans. This enables you to tailor scans to your specific needs.

Any scan checks saved to your custom scan checks library are automatically enabled. They run alongside Burp Scanner's built-in checks during the audit.

Related pages

For more information on how to create or import custom scan checks, see Custom scan checks.

To disable or enable custom scan checks in a scan configuration:

  1. In the scan launcher, go to the Scan configuration tab.

  2. From the dropdown, select the type of scan configuration you want to use.

  3. Under Audit configuration, select Scan checks.

  4. In the settings panel, go to the Custom tab.

  5. Do one of the following:

Burp Scanner runs all the enabled custom checks when auditing.

Managing the custom scan checks table

Custom scan checks are listed in a table with the following information:

You can adjust the table contents as follows:

Checks that aren't saved to your custom scan checks library are marked with an asterisk *. This may happen if you load a scan configuration that includes custom checks. To add the checks to your library, right-click and select Save to library.