TryHackMe room
Corresponding practice
- Review the BApp Store and choose one extension that supports a specific testing task.
- Record the extension’s purpose, required permissions, source, and what data it can access.
- On a TryHackMe lab, scope the target, capture traffic, send one request to Repeater, and export or save the useful evidence.
- Repeat one Day 19 test without referring to notes.
Evidence to capture
- A short Burp workflow checklist
- The extension selection and the reason for using or rejecting it
- One sanitised request/response pair showing a meaningful change
What I learned
Document where extensions help and where manual verification is still required.
Problems and dead ends
Record proxy, certificate, scope, or extension issues and their fixes.
What I will revisit
Choose one Burp workflow step to make faster or more consistent.