A Burp Suite extension that passively discovers where values produced in HTTP responses are later consumed in HTTP requests — and maps those producer→consumer flows automatically, read-only.
Built on the Montoya API. Works in Burp Suite Community and Professional, fully offline (it makes no network requests of its own), with no AI and no external services.
As you browse and test an application, the extension watches the HTTP traffic that passes through Burp and:
- Extracts produced values from responses — JSON body fields; tokens embedded in
HTML/JS/XML/text bodies (CSRF tokens in hidden inputs, nonces in inline scripts, API
tokens — matched by shape or by an id-like field name); selected headers (
Location,ETag,Authorization,X-*); andSet-Cookievalues. - Extracts consumed values from later requests — query parameters, path segments, JSON bodies, form fields, cookies, and selected headers.
- Correlates them: when a value first seen in a response reappears in a later request, it records a producer→consumer relation.
- Scores confidence (High / Medium / Low) with a deterministic model based on value type, timing, host, name similarity, reuse and other factors — so you can triage the real data flows out of the noise.
It answers a question manual review is slow at: "this token/id came from that response — where does the app send it back, and how confident are we?" — the starting point for finding IDOR, broken access control, CSRF, and session-handling issues.
Unlike token-replacement / macro tools (Stepper, Magic Variables, Token Extractor) it is:
- Passive — it never resends, substitutes, or modifies traffic.
- Automatic — no manual configuration of which value goes where.
- Directional — it respects time: producer response before consumer request.
- Read-only — it maps data flows; it does not act on them.
Open the HTTP Value Flow Mapper tab.
- Master table — one row per relation: confidence (color-coded), value type, producer endpoint, consumer endpoint, use count and delay. Sort by any column; a live counter shows how many relations are found and how many the filters show.
- Filters — narrow by endpoint text, value type, or confidence level.
- Details (select a row) — a Producer box and a Value box on the left, and a table of every consumer of that value on the right. All text is selectable/copyable.
- Right-click a row — copy the producer/consumer endpoint or the score breakdown, or filter by the row's type or endpoint.
- Controls —
In-scope only(default on),Pause,Clear,Config(tunable limits, thresholds and noise filters),Export…(CSV or JSON).
Noise reduction (on by default, configurable): static-asset traffic (css/js/images) is skipped so you don't get the session cookie echoed on every asset load; a same-cookie round-trip doesn't get the name-match bonus; bare numbers such as timestamps aren't treated as tokens; and values reused long after they were produced are down-scored as likely session persistence. Conversely, CSRF/nonce/auth token fields are ranked higher — so the security-relevant flows rise to the top instead of being buried.
- dropped: N — items skipped because the work queue was full (backpressure visibility).
The extension treats all HTTP content as untrusted:
- No raw values are stored. The index keys on an HMAC-SHA-256 fingerprint of each value, computed with an ephemeral key generated at load and wiped at unload. Raw values exist only transiently in the worker while a message is parsed.
- Untrusted content is never interpreted. All traffic-derived text is shown in non-HTML components (Swing HTML disabled); no HTML rendering, link opening, or downloads.
- Offline. No network calls, no telemetry.
- Read-only. The HTTP handler always continues messages unchanged.
| Limit | Default |
|---|---|
| Max analyzed body size | 2 MB (larger bodies: headers/cookies still processed) |
| Max JSON depth | 30 |
| Max values per response | 500 |
| Max relations in index | 50,000 |
| Max producers in index | 100,000 |
| Retention TTL | 24 h (0 = unlimited) |
| Work queue capacity | 10,000 (drop-newest, counted) |
When a cap is reached, retention evicts lowest-confidence and oldest entries first.
- GraphQL is out of scope for v1: the producer-endpoint → consumer-endpoint model
loses meaning when everything flows through a single
POST /graphql. - Editable allow/search/ignore lists are configurable; the queue drop policy is fixed to drop-newest.
Requires JDK 17. The Montoya API is compileOnly (Burp provides it at runtime) and is
not bundled; Gson is bundled into the single installable jar.
./gradlew buildOutput: build/libs/http-value-flow-mapper-1.0.0.jar. Run the tests with ./gradlew test.
Burp → Extensions → Installed → Add → Extension type Java → select the jar. The
class implementing BurpExtension is auto-discovered (no manifest entry needed).
- Burp Suite Community & Professional
- Montoya API 2026.7
- Java 17
MIT — see LICENSE.