Let "Claude Code" do your Pentesting!
In this video, I walk through a live demo of using Claude Code for pentesting, covering the same security test cases you'd run manually with Burp Suite, but letting AI drive the workflow. This is a hands-on look at how Claude Code integrates with Burp via MCP and controls a Playwright browser to perform real security tests autonomously, including IDOR, authentication bypass, and CSRF protection checks. We start with a manual walkthrough in Burp Suite on a sample snippet-sharing app, then repeat the exact same tests using Claude Code. The result: a white-box pentesting workflow where the AI has access to both the running app and the source code, making it more effective than a traditional black-box approach. Read on Medium: / c58bc6987a99 📌 MCP setup commands: Burp MCP: claude mcp add --transport sse burp http://127.0.0.1:9876/ -s user Playwright MCP with Burp proxy: claude mcp add playwright -s user -- npx @playwright/mcp@latest --proxy-server=http://127.0.0.1:8080 --ignore-https-errors ⏱️ Chapters: 00:00:00 Intro 00:00:36 Burp Suite Overview 00:01:55 Installing & Starting Burp 00:03:32 Demo App & Manual Test Setup 00:05:04 IDOR Test Case — Manual Walkthrough with Burp 00:07:42 Authentication & CSRF Protection Testing 00:09:04 Pivoting to Claude Code 00:09:17 Setting Up the Burp MCP 00:10:49 Setting Up Playwright MCP with Burp Proxy 00:13:16 Prompting Claude Code — The Test Case 00:16:29 Claude Code Live Demo 00:20:51 Results & White-Box Advantage 00:21:03 Packaging as a Claude Code Skill 00:22:02 Recap #AppSec 🛡️ #Pentesting 🔐 #ClaudeCode 🤖 #BurpSuite 🔁 #IDOR 🔓 #SecurityEngineering 🧠 #DevSecOps ⚙️ #ApplicationSecurity 👨🏻💻 #ClaudeCode 🤖 #BurpSuite 🔁 #MCP 🔌 #Playwright 🎭

How to Use "AI" For Security Code Reviews

What AppSec Engineers Actually Do (and Why It Matters)

Clinejection: One Misconfigured GitHub Action Can Compromise Your App (Deep Dive & Lessons Learned)

CLAUDE CODE ADVANCED FULL COURSE (3 HOURS)

Agent Skills or MCP in the era of Claude Code?

HackTheBox – Facts | IDOR & LFI, AWS S3 Enumeration, GTFOBins

I Turned Claude Into a 24/7 Trader

The Best Local Agentic Coding Workflow (Complete Guide)

GLM 5.2 is SO GOOD (and almost free)

You are wasting 90% of your tokens without realizing it.

Leave Windows 11 Idle for 24 Hours and Watch What Happens

Ollama + Claude Code = 99% CHEAPER

GLM 5.2 in Claude Code is Blowing My Mind

الرقية الشرعية للشفاءمن السحروالعين والحسد حصن من الشيطان رقية البيت والاولاد بصوت القارئ سعيد حمدان

Türkei – USA Highlights | Gruppe D, FIFA WM 2026 | sportstudio

Why AI Agents are either the best or worst thing we’ve ever built

GitHub RCE (CVE-2026-3854) - Deep Dive & Lessons Learned

Learn 97% of Claude in Under 16 Minutes

432Hz - Fall Into Deep Sleep in 3 Minutes, Heal All Damage In The Body and Spirit, Relieve Stress #2

