Your Burp history already describes the app.
burp2model turns traffic you already captured into an evidence-backed model of a web app: hosts, pages, scripts, endpoints, parameters and the gaps in what you saw. Every node cites a real request. Secrets are masked before anything is written.
pip install burp2model
Traffic in, a model out
Every output is read from one graph. Values are masked at the parser; names and shapes survive.
Stream
Reads the Burp XML and scans JS and HTML bodies for endpoint references.
Mask
Masks headers, parameters, bodies and URL paths. Secrets are kept only as keyed fingerprints.
Relate
Sets scope, then builds edges: OBSERVED from traffic, INFERRED from code.
Compare
Compares code with runtime: BOTH STATIC_ONLY RUNTIME_ONLY
Report
Writes the graph, a report and the unknowns: what the capture could not answer.
Six layers, every node tied to a request
Every edge is observed or inferred. Nothing is called a vulnerability.
The report, from the sample capture
Click any node to open its evidence.
Raw outputs: context.json · model.json
A model builder, not a scanner
| It does | It never |
|---|---|
| read a capture you exported | replay it or send it anywhere |
| mask every value before the first write | store a token, cookie, key or personal value |
| say what it couldn't observe | claim coverage it didn't have |
| list hypotheses with their evidence | call anything a vulnerability |
Know the surface before you test it.
Export your Burp history, build the model, then ask it.