v1.0.0 · open source

Your Burp history already describes the app.

burp2model turns traffic you already captured into an evidence-backed model of a web app: hosts, pages, scripts, endpoints, parameters and the gaps in what you saw. Every node cites a real request. Secrets are masked before anything is written.

$ pip install burp2model
0runtime deps
6layers
0secrets written
288tests passing
How it works

Traffic in, a model out

Every output is read from one graph. Values are masked at the parser; names and shapes survive.

01 · parse

Stream

Reads the Burp XML and scans JS and HTML bodies for endpoint references.

02 · redact

Mask

Masks headers, parameters, bodies and URL paths. Secrets are kept only as keyed fingerprints.

03 · model

Relate

Sets scope, then builds edges: OBSERVED from traffic, INFERRED from code.

04 · reconcile

Compare

Compares code with runtime: BOTH STATIC_ONLY RUNTIME_ONLY

05 · emit

Report

Writes the graph, a report and the unknowns: what the capture could not answer.

The six-layer model

Six layers, every node tied to a request

Every edge is observed or inferred. Nothing is called a vulnerability.

6unknownsWhat the capture could not answer, with a next step.
5trustThird parties, auth, roles and cookie flags.
4apisEndpoints, parameters and GraphQL operations, with statuses per role.
3codeScripts, forms, workers and source maps, and the endpoints they reference.
2routesPages and navigations, linked to the APIs each page calls.
1edgeFirst-party hosts: schemes, ports, server tech.
Live demo

The report, from the sample capture

Click any node to open its evidence.

demo/report.htmlOpen full screen ↗

Raw outputs: context.json · model.json

Boundaries

A model builder, not a scanner

It doesIt never
read a capture you exportedreplay it or send it anywhere
mask every value before the first writestore a token, cookie, key or personal value
say what it couldn't observeclaim coverage it didn't have
list hypotheses with their evidencecall anything a vulnerability

Know the surface before you test it.

Export your Burp history, build the model, then ask it.