We start off picking up a request from our captured requests:
- Right-click on the request and select Send to Intruder:
- Switch to the Intruder tab. We need to specify a payload position, and we can do that by selecting the place we want or selecting the payload and clicking on the Add § button:
- In our case, since we are performing a login brute force, we will use the attack type Pitchfork:
- Next, we switch to the Payloads ...