๐ŸŽฏ VISTA Documentation

Vulnerability Insight & Strategic Test Assistant โ€” AI-Powered Security Testing for Burp Suite.

Get Started View on GitHub


What is VISTA?

VISTA is a professional Burp Suite extension that enhances security testing with AI-powered intelligence. It combines real-time traffic analysis, interactive AI guidance, and practical pentesting tools to help you test faster, smarter, and more systematically.

Version: 2.10.28 ยท License: MIT ยท Java: 17+ ยท Size: ~1.3MB ยท Zero Dependencies

New in v2.10.28: Azure AI Foundry support (new endpoint format), Azure Identity (DefaultAzureCredential) auth, configurable API version, status bar shows correct model name per provider, + New Chat properly creates a new session, max_completion_tokens for all providers, reasoning model temperature fix (o1/o3/o4), errors now surface correctly from OpenAI.


โœจ Key Capabilities

Feature Description
๐ŸŒ Traffic Monitor Real-time HTTP traffic analysis with AI-driven vulnerability detection
๐Ÿค– AI Advisor Context-aware interactive testing suggestions with conversation history
๐Ÿ“ 12 Expert Templates Built-in prompt templates covering the most common bug bounty vulnerabilities
๐ŸŽฏ 80+ Payloads Pre-built payloads across 8 categories with AI-powered suggestions
๐Ÿ›ก๏ธ WAF Detection Detect and bypass 8 major WAFs with 250+ bypass techniques
๐Ÿ†“ Free AI Use OpenRouter with no credit card โ€” powerful AI at zero cost

๐Ÿš€ Quick Navigation

Getting Started

  • Installation โ€” Download, build, and install VISTA
  • Quick Start โ€” Configure AI and start testing in 5 minutes
  • Free AI Setup โ€” Use VISTA completely free with OpenRouter

Core Features

Templates

Configuration

Reference


๐ŸŽฏ Supported Vulnerabilities

Vulnerability AI Guidance Payloads Expert Template Bypass Techniques
Cross-Site Scripting (XSS) โœ… โœ… โœ… DOM + Reflected โœ…
SQL Injection โœ… โœ… โœ… โœ…
Server-Side Template Injection โœ… โœ… โœ… โœ…
Server-Side Request Forgery โœ… โœ… โœ… โœ…
IDOR / BOLA โœ… โ€” โœ… โœ…
Authentication Bypass โœ… โ€” โœ… โœ…
File Upload โœ… โ€” โœ… โœ…
Race Conditions โœ… โ€” โœ… โ€”
JWT / OAuth โœ… โ€” โœ… โœ…
API Security (OWASP Top 10) โœ… โ€” โœ… โœ…
Command Injection โœ… โœ… โ€” โœ…
XXE โœ… โœ… โ€” โœ…

VISTA is designed for authorized security testing only. Always obtain proper authorization before testing any target.


Back to top

VISTA — Vulnerability Insight & Strategic Test Assistant. Made with โค๏ธ for the Security Community.

This site uses Just the Docs, a documentation theme for Jekyll.