Skip to main content

Burp Suite Extension

The Milou Burp Suite extension is the bridge between your active pentesting session and your Milou assessment. It allows you to instantly push findings, complete with request/response evidence, without leaving Burp Suite.

1. Download

You can download the extension (sidecar.jar):

  1. Navigate to any Assessment.
  2. In the top toolbar, look for the Download icon (next to the connection status and token).
  3. Click it to download the sidecar.jar file.

2. Install in Burp Suite

  1. Open Burp Suite Professional or Community.
  2. Navigate to the Extensions tab -> Installed sub-tab.
  3. Click Add.
  4. Under Extension Details, select Java as the extension type.
  5. Click Select file ... and choose the sidecar.jar file you just downloaded.
  6. Click Next. You should see a success message indicating the extension loaded.

3. Connect to Milou

Once installed, you need to authorize the extension to talk to your specific assessment.

  1. In Burp Suite, go to the new Milou tab.
  2. API URL: Enter your Milou instance URL (e.g., https://milou.internal.corp).
  3. Authentication Token:
    • Navigate to your Assessment in the Milou Dashboard.
    • In the top right corner of the assessment toolbar, you will see a masked token (e.g., abc...xyz).
    • Click the Copy button to copy the full token.
    • Paste it into the extension's Authentication Token field.
  4. Click Test Connection.

4. Usage

When you find something interesting in Burp (Proxy, Repeater, etc.):

  1. Right-click the request/response.
  2. Select Extensions > Milou > Send to Milou.
  3. In the popup:
    • Project: This should automatically show your connected assessment.
    • Title: Name the finding (e.g., "IDOR in User Profile").
    • Severity: Set the risk level.
    • Description: Add your notes. The HTTP request/response is attached automatically.
  4. Click Send.

The finding is now immediately available in your Milou assessment for further editing.