Response Overview and Colonel Clustered – Grouping Burp Responses by Content
You are here: Home / Hacking Tools / Response Overview and Colonel Clustered – Grouping Burp Respons 2026-10-5 12:33:47 Author: www.darknet.org.uk(查看原文) 阅读量:5 收藏

You are here: Home / Hacking Tools / Response Overview and Colonel Clustered – Grouping Burp Responses by Content

Sorting an Intruder attack by status code and length finds the responses that differ in size, and misses the ones that differ only in what they say. In the example Drew Kirkpatrick uses to introduce Colonel Clustered, every response is the same size, yet for one ID value one of hundreds of lines differs – invisible in the length column.

Burp Suite: Grouping responses by content. Two stacks of dark response cards and one separate orange-marked card; darknet.org.uk.
Response Overview and Colonel Clustered group Burp Suite responses by content to help identify unusual results.

Response Overview and Colonel Clustered are two Burp Suite extensions that group responses by content instead. Response Overview files every eligible in-scope response as it arrives; Colonel Clustered groups a batch you send it.

Advertisement

Response Overview: a threshold you set

Response Overview installs from the BApp Store, which lists version 1.6.0, updated 20 January 2026, for both Professional and Community.

The store’s instructions are short: add the target to scope, test as usual with any tool – Proxy, Scanner, Repeater, Intruder – then open the Response Overview tab, sort by any column and examine the small groups and unusual status codes. Right-click and choose Hide item(s) to clear what you have reviewed.

Each row is one representative response with its group size. A response is only compared with groups that share its HTTP status code, and within those it is measured against each group’s first member. It joins the first one it matches at the similarity threshold, 98% by default, or starts a new group.

By default it removes reflected request parameters before comparing – names and values longer than eight characters, with their decoded and encoded forms – so a long payload echoed back does not split a group.

By default it only looks at in-scope responses under 1 MiB – a limit you can change in its settings – and it skips uninteresting MIME types and file extensions and standard error pages from common web servers.

What it can miss. The similarity is a ratio in the style of Python’s difflib, computed on how often each byte occurs rather than on their order; the source says “ABBA and BAAB and BABA are all the same”.

Advertisement

Two responses that hold the same characters in a different arrangement can therefore land in one group, which a swapped pair of values in a table would do. Payloads of eight characters or fewer are not stripped, so short reflected input can still split groups.

Once 30 groups share a status code and body size, further responses with that status and size are skipped entirely, and the group sizes shown for them undercount – the source trades an accurate count for speed.

Colonel Clustered: a threshold it picks

In Kirkpatrick’s walkthrough you run the Intruder attack to completion, select all the results, right-click and choose Send to Colonel Clustered, then switch to its “Col. Clustered” tab while the default Fast Scan runs.

The tab has four panes. Clusters, with their member counts and a separate Outliers group, sit top left; the members of whichever cluster you select sit below, with status code, length and Content-Type, sortable by column. The request and response viewers are on the right.

Read it from the small end: a single-member cluster, or an entry in Outliers, is the response that looked like nothing else. In the walkthrough he selects the single-member cluster and uses Burp Comparer to see exactly what differed.

Under the hood, each response is read by its Content-Type. HTML loses its tags and scripts, and its visible text is broken into five-character chunks, with digits sanitised so that changing IDs in a template do not split one page into many.

For JSON only the keys and their nesting are kept, ignoring the values. Anything binary is compared as five-byte sequences.

Identical token sets are merged, then the Fast Scan runs DBSCAN with the neighbour distance chosen by the Kneedle algorithm rather than by you. A slower Deep Analysis, started from a button, builds clusters hierarchically from Jaccard distances and sets its threshold from how the clusters merge.

What it can miss. The rules that keep templated pages together can also hide the difference you are fuzzing for, and this is the part I would check first.

A JSON response whose only change is a value – a different role, a different error string inside the same field – has the same keys as its neighbours and clusters with them. Sanitised digits mean a change confined to numbers, such as an ID, a count or a balance, may not separate a page either.

The author says the fast algorithm “worked well most of the time”. In his second example it lumped two clearly different responses into a large cluster, although Intruder’s size, status code and Content-Type columns would have shown them.

Deep Analysis put that pair in a cluster of their own. So when members of a large cluster differ in those columns, run Deep Analysis; it can be cancelled if it runs too slowly.

He gives O(n²) for the default and O(n³) for Deep Analysis, and would “hesitate to throw 50k responses at this plugin”, so send it a filtered slice of an attack.

Side by side

Response OverviewColonel Clustered
When it runsContinuously, on eligible in-scope responses from any Burp toolOn demand, on the items you send it
Similarity thresholdSet by you, default 98%Chosen automatically: Kneedle in Fast Scan; merge distances in Deep Analysis
What is comparedByte frequencies; by default, reflected parameter names and values longer than eight characters are removed firstContent-aware tokens: visible text, JSON structure or bytes
Status codeOnly responses with the same status are comparedShown as a column; the README does not say it affects clustering
Can hideThe same bytes in a different order; short reflected payloads can split groupsChanged JSON values under unchanged keys; changes confined to digits
Getting itBApp Store, Professional and CommunityGitHub release jar or build; not in the BApp Store as of 29 September 2026

Choosing between them

Response Overview is a background view of a whole engagement, available for Community from the BApp Store: set the scope, leave it running, and come back to the small groups.

If ordinary variation produces too many groups, lower the similarity threshold; if responses that differ in a way that matters are being merged, raise it. Its status-code split keeps a 200 and a 500 with the same body apart, which also puts one page served under two codes into two groups.

Colonel Clustered is for a batch you have already narrowed down, such as one Intruder attack, where not having to pick a threshold is the point.

Colonel Clustered lets you open a cluster and read its members. Response Overview shows one representative per group, so its count alone cannot tell you that every response behind it matches: when a changed value matters, go back to the original Intruder or Proxy results for that endpoint and compare several responses there.

If the parameter you are fuzzing changes values inside JSON, do that for Colonel Clustered’s large clusters too, because its tokenising folds those responses together. If it changes only numbers on a page, check the large clusters as well: sanitised digits can hide the change.

Getting Colonel Clustered

The v1.0.0 release, from 3 January 2026, ships a built ColonelClustered.jar; load it through Extensions > Add in Burp. To build the current source instead, which the README describes as v1.0.1, you need JDK 17:

git clone https://github.com/hoodoer/ColonelClustered.git

cd ColonelClustered

./gradlew build

The jar lands in build/libs/ColonelClustered.jar. The README does not say whether it runs on Burp Community.

Kirkpatrick’s walkthrough says he has submitted it to PortSwigger for the BApp Store, which is backlogged on extension reviews; it was not listed when I checked.

Where the idea comes from

When this site covered Burp Suite 1.01 in January 2007, it already had Intruder and an interface for third-party extensions. What these two change is the step after the attack: instead of reading results row by row, you read groups.

Response Overview’s own help text traces it to Tobias Ospelt’s Python extension at modzero, ResponseClusterer, which “clusters similar responses together, and shows a summary with one request/response per cluster” and was last pushed to in June 2019. He noticed it “might be eating some of Burp’s performance”, and when it broke in 2021 he wrote a new extension in Kotlin, with different features.

You can install Response Overview from the BApp Store (source: https://github.com/pentagridsec/PentagridResponseOverview), and find Colonel Clustered here: https://github.com/hoodoer/ColonelClustered, with the author’s walkthrough on the TrustedSec blog.

Advertisement


文章来源: https://www.darknet.org.uk/2026/10/response-overview-colonel-clustered-burp-response-grouping/
如有侵权请联系:admin#unsafe.sh