DOM Invader

DOM Invader is a browser-based tool that helps you test for DOM XSS vulnerabilities using a variety of sources and sinks, including both web message and prototype pollution vectors. It is available exclusively via Burp's built-in browser, where it comes preinstalled as an extension.

DOM Invader tab for the browser DevTools

Key features

When enabled, DOM Invader adds a new tab to the browser's DevTools panel. This enables you to perform the following key tasks:

For more information on how to enable DOM Invader, see Enabling DOM Invader.

DOM Invader is highly configurable, so you can fine-tune its behavior to suit different websites and use cases. For more information, see DOM Invader settings.