Skip to main content
A powerful Burp Suite extension that automatically scans scannable files using the Jsmon API. Discover secrets, API endpoints, domains, and other intelligence from web files as you browse.

Features

  • Easy API Key Configuration — Enter your Jsmon API key directly in the extension
  • Workspace Management — Fetch existing workspaces or create new ones
  • Domain Scoping — Limit scanning to specific domains (includes subdomains)
  • Automatic Scanning — Automatically scan scannable files as you browse
  • Intelligence Dashboard — View secrets, JS URLs, API paths, domains, IPs, emails, S3 buckets, and more
  • Copy to Clipboard — One-click copy for all intelligence data
  • Real-time Updates — See scan results and counts update in real-time
  • Dark/Light Theme Support — Automatically adapts to Burp Suite’s theme

Requirements

Installation

1

Download the Extension

Download the latest jsmon-burp-extension-1.1.0.jar file from the GitHub repository.
2

Open Burp Suite

Go to the Extensions tab and click the Add button.
3

Load the Extension

Select Extension type: Java, then click Select file and choose the downloaded JAR file.
4

Verify Installation

Verify the extension loads without errors in the Output tab. You should see a new JSMon tab in Burp Suite.

Quick Start Guide

Step 1: Configure API Key

  1. Open the JSMon tab in Burp Suite.
  2. Enter your Jsmon API key in the “API Key” field.
  3. Click Fetch Workspaces to retrieve your workspaces.
  4. Your user profile (name, email, JSScan credits) will be displayed automatically.

Step 2: Select or Create Workspace

  • Select Existing Workspace: Choose a workspace from the dropdown.
  • Create New Workspace: Enter a name and click Create.

Step 3: Configure Domain Scoping (Optional)

  • Enter domain(s) in the “Domain Scoping” field (one per line or comma-separated).
  • Leave empty to scan all files regardless of domain.
  • Subdomains are automatically included (e.g., example.com includes sub.example.com).

Step 4: Enable Automatic Scanning

Check Enable Automatic Scanning to automatically scan scannable files as you browse. When enabled, the extension will:
  • Scan all existing scannable files in Burp’s history
  • Automatically process new scannable files as you browse
  • Respect your domain scoping settings

Step 5: View Intelligence Data

Click on the JS-Intelligence Data tab to view:
  • Secrets — API keys, tokens, and other secrets found
  • JS URLs — All JavaScript files discovered
  • API Paths — API endpoints extracted from files
  • URLs — All URLs found in files
  • Domains — Domains discovered
  • IP Addresses — IP addresses found
  • Emails — Email addresses discovered
  • S3 Buckets — S3 bucket names found
  • Invalid Node Modules — NPM confusion packages detected

Usage

Automatic Scanning

When automatic scanning is enabled:
  • The extension monitors all HTTP responses in Burp Suite
  • Scannable files are automatically detected (by file extension or Content-Type header)
  • Files are sent to Jsmon API with all relevant headers (User-Agent, Cookie, Authorization, etc.)
  • Each URL is processed only once to avoid duplicates
  • Results appear in real-time in the intelligence tabs

Manual Scanning

  1. Click Start Manual Scan to scan all scannable files from Burp’s HTTP history.
  2. Progress is shown in the status log.
  3. Results are automatically displayed in the intelligence tabs.

Viewing Intelligence Data

  • Secrets Tab: View all secrets found (API keys, tokens, etc.)
  • JS Intelligence Tabs: Browse through different types of intelligence data
  • Counts: Each tab shows the total count in parentheses (e.g., “Emails (188)”)
  • Pagination: Use Prev and Next buttons to navigate through pages
  • Copy All: Click Copy All button to copy all data from a tab to clipboard

Copying Data

  • Copy Selected Cells: Select cells in any table and press Ctrl+C (or Cmd+C on Mac)
  • Copy All Data: Click the Copy All button at the bottom of each intelligence tab — this copies all values from the first column, one item per line

Configuration Options

Understanding the Intelligence Data

Secrets

API keys, tokens, passwords, and other sensitive information found in files.

JS URLs

All file URLs that have been scanned. Useful for identifying all scannable files in scope.

API Paths

API endpoints and paths extracted from files. Great for discovering hidden endpoints.

URLs

All URLs found in files, including internal and external links.

Domains

All domains discovered in files. Helps identify all domains used by the application.

IP Addresses

IP addresses found in files, including internal and external IPs.

Emails

Email addresses discovered in files. Useful for identifying contacts and user emails.

S3 Buckets

Amazon S3 bucket names found in files. Can reveal misconfigured or exposed buckets.

Invalid Node Modules

NPM confusion packages detected — packages with typosquatting or suspicious names.

Tips & Best Practices

Start with Domain Scoping — Limit your scans to your target domain to avoid scanning unrelated files.
  • Monitor JSScan Credits: Check your remaining credits in the User section.
  • Use Manual Scan First: Run a manual scan to see what data is available before enabling automatic scanning.
  • Export Data Regularly: Use the Copy All buttons to export data for further analysis.
  • Check Secrets First: Always review the Secrets tab first as it contains the most critical findings.

Troubleshooting

  • Ensure you are using Burp Suite 2024.1 or later
  • Check that Java 11+ is installed
  • Verify the JAR file is not corrupted
  • Check the Output tab in Burp Suite for error messages
  • Verify your API key is correct
  • Check your internet connection
  • Look for error messages in the status log
  • Ensure Automatic Scanning is enabled
  • Check that the domain matches your scoped domain (if set)
  • Verify the workspace is selected
  • Check the status log for any error messages
  • Counts are fetched automatically when you select a workspace
  • Try selecting the workspace again
  • Click on the intelligence tabs to refresh data
  • Check if there is actual data in your workspace