Features
- Easy API Key Configuration — Enter your Jsmon API key directly in the extension
- Workspace Management — Fetch existing workspaces or create new ones
- Domain Scoping — Limit scanning to specific domains (includes subdomains)
- Automatic Scanning — Automatically scan scannable files as you browse
- Intelligence Dashboard — View secrets, JS URLs, API paths, domains, IPs, emails, S3 buckets, and more
- Copy to Clipboard — One-click copy for all intelligence data
- Real-time Updates — See scan results and counts update in real-time
- Dark/Light Theme Support — Automatically adapts to Burp Suite’s theme
Requirements
Installation
1
Download the Extension
Download the latest
jsmon-burp-extension-1.1.0.jar file from the GitHub repository.2
Open Burp Suite
Go to the Extensions tab and click the Add button.
3
Load the Extension
Select Extension type: Java, then click Select file and choose the downloaded JAR file.
4
Verify Installation
Verify the extension loads without errors in the Output tab. You should see a new JSMon tab in Burp Suite.
Quick Start Guide
Step 1: Configure API Key
- Open the JSMon tab in Burp Suite.
- Enter your Jsmon API key in the “API Key” field.
- Click Fetch Workspaces to retrieve your workspaces.
- Your user profile (name, email, JSScan credits) will be displayed automatically.
Step 2: Select or Create Workspace
- Select Existing Workspace: Choose a workspace from the dropdown.
- Create New Workspace: Enter a name and click Create.
Step 3: Configure Domain Scoping (Optional)
- Enter domain(s) in the “Domain Scoping” field (one per line or comma-separated).
- Leave empty to scan all files regardless of domain.
- Subdomains are automatically included (e.g.,
example.comincludessub.example.com).
Step 4: Enable Automatic Scanning
Check Enable Automatic Scanning to automatically scan scannable files as you browse. When enabled, the extension will:- Scan all existing scannable files in Burp’s history
- Automatically process new scannable files as you browse
- Respect your domain scoping settings
Step 5: View Intelligence Data
Click on the JS-Intelligence Data tab to view:- Secrets — API keys, tokens, and other secrets found
- JS URLs — All JavaScript files discovered
- API Paths — API endpoints extracted from files
- URLs — All URLs found in files
- Domains — Domains discovered
- IP Addresses — IP addresses found
- Emails — Email addresses discovered
- S3 Buckets — S3 bucket names found
- Invalid Node Modules — NPM confusion packages detected
Usage
Automatic Scanning
When automatic scanning is enabled:- The extension monitors all HTTP responses in Burp Suite
- Scannable files are automatically detected (by file extension or
Content-Typeheader) - Files are sent to Jsmon API with all relevant headers (User-Agent, Cookie, Authorization, etc.)
- Each URL is processed only once to avoid duplicates
- Results appear in real-time in the intelligence tabs
Manual Scanning
- Click Start Manual Scan to scan all scannable files from Burp’s HTTP history.
- Progress is shown in the status log.
- Results are automatically displayed in the intelligence tabs.
Viewing Intelligence Data
- Secrets Tab: View all secrets found (API keys, tokens, etc.)
- JS Intelligence Tabs: Browse through different types of intelligence data
- Counts: Each tab shows the total count in parentheses (e.g., “Emails (188)”)
- Pagination: Use Prev and Next buttons to navigate through pages
- Copy All: Click Copy All button to copy all data from a tab to clipboard
Copying Data
- Copy Selected Cells: Select cells in any table and press
Ctrl+C(orCmd+Con Mac) - Copy All Data: Click the Copy All button at the bottom of each intelligence tab — this copies all values from the first column, one item per line
Configuration Options
Understanding the Intelligence Data
Secrets
API keys, tokens, passwords, and other sensitive information found in files.JS URLs
All file URLs that have been scanned. Useful for identifying all scannable files in scope.API Paths
API endpoints and paths extracted from files. Great for discovering hidden endpoints.URLs
All URLs found in files, including internal and external links.Domains
All domains discovered in files. Helps identify all domains used by the application.IP Addresses
IP addresses found in files, including internal and external IPs.Emails
Email addresses discovered in files. Useful for identifying contacts and user emails.S3 Buckets
Amazon S3 bucket names found in files. Can reveal misconfigured or exposed buckets.Invalid Node Modules
NPM confusion packages detected — packages with typosquatting or suspicious names.Tips & Best Practices
- Monitor JSScan Credits: Check your remaining credits in the User section.
- Use Manual Scan First: Run a manual scan to see what data is available before enabling automatic scanning.
- Export Data Regularly: Use the Copy All buttons to export data for further analysis.
- Check Secrets First: Always review the Secrets tab first as it contains the most critical findings.
Troubleshooting
Extension Not Loading
Extension Not Loading
- Ensure you are using Burp Suite 2024.1 or later
- Check that Java 11+ is installed
- Verify the JAR file is not corrupted
- Check the Output tab in Burp Suite for error messages
Workspaces Not Fetching
Workspaces Not Fetching
- Verify your API key is correct
- Check your internet connection
- Look for error messages in the status log
Files Not Being Scanned
Files Not Being Scanned
- Ensure Automatic Scanning is enabled
- Check that the domain matches your scoped domain (if set)
- Verify the workspace is selected
- Check the status log for any error messages
Counts Showing Zero
Counts Showing Zero
- Counts are fetched automatically when you select a workspace
- Try selecting the workspace again
- Click on the intelligence tabs to refresh data
- Check if there is actual data in your workspace

