Repository navigation
Home
Gareth Heyes edited this page Sep 17, 2026
·
6 revisions
Welcome to the Hackvertor documentation! Hackvertor is a Burp Suite extension that provides powerful tag-based data transformation capabilities for security testing.
- Getting Started
- Tag Syntax
- Tag Reference
- Custom Tags
- Jigsaw Mode
- Multi Encoder
- Tag Automator
- Keyboard Shortcuts
- Settings
- FAQ
Hackvertor is a tag-based conversion tool that allows you to encode, decode, hash, encrypt, and transform data using a simple tag syntax. It integrates deeply with Burp Suite, allowing you to:
- Transform data in requests and responses using tags
- Chain multiple transformations together
- Create custom tags using Python, JavaScript, Java, or Groovy
- Automate transformations with Tag Automator
- Use AI to generate custom tags and learn encoding patterns
Wrap your data in tags to transform it:
<@base64>Hello World</@base64>
Result: SGVsbG8gV29ybGQ=
Chain transformations by nesting tags:
<@urlencode_all><@base64>payload</@base64></@urlencode_all>
Build conversions by dragging tag pieces together instead of typing tags. See Jigsaw Mode.
Make a conversion conditional with the check tag:
<@check(isJson,'exec_key')>{}</@check> && <@base64>foo</@base64>
- Encoding (Base64, Hex, URL, HTML entities, etc.)
- Decoding (reverse of all encoding operations)
- Hashing (MD5, SHA1, SHA256, SHA512, etc.)
- Encryption/Decryption (AES, XOR, ROT-N, etc.)
- String manipulation
- Mathematical operations
- Compression (Gzip, Deflate, Brotli)
- And more...
Create your own tags using scripting languages:
- Python (Jython)
- JavaScript (GraalVM)
- Java (BeanShell)
- Groovy
- Main tab interface
- Context menus in Proxy, Repeater, Intruder, etc.
- Message editor tabs
- Intruder payload processors
- HTTP handler for automatic tag processing
- Bambda snippet exposing the conversion engine to Custom Actions and filters
Current version: v2.2.67 (September 2026)
| Version | Feature |
|---|---|
| v2.2.67 | What's new tab in the Hackvertor UI |
| v2.2.65 |
Tag expressions with the check, isJson and isNumeric tags |
| v2.2.65 | Configurable hotkey modifier |
| v2.2.61 | Jigsaw mode for building conversions by dragging pieces |
| v2.2.57 | Smart paste in the UI and Repeater |
| v2.2.52-54 | Smarter base64 detection, including base64 split over multiple lines |
| v2.2.51 |
request and response objects available to custom tag code
|
| v2.2.46 | Copy Bambda code to clipboard |
- Report bugs or request features
- Tag Store - Community-contributed tags
Getting Started
Reference
Features
Integration
Examples
Help