OWASP Penetration Testing Kit
Extension Actions
- Extension status: Featured
OWASP Penetration Testing Kit
The OWASP Penetration Testing Kit (PTK) browser extension is your all-in-one solution for streamlining your daily AppSec tasks. Whether you’re a penetration tester, a Red Team member, or an AppSec practitioner, OWASP PTK enhances your efficiency and provides deep insights into your target application.
Key Features:
Runtime Scanning (DAST & IAST & SAST & SCA):
Perform Dynamic Application Security Testing, Static Analysis, In-Browser IAST and Software Composition Analysis on the fly. Identify SQL injection, command injection, reflected/stored XSS, SQL auth bypass, XPath injections, JWT attacks, and other complex threats.
Static Analysis (SAST):
PTK automatically parses loaded JavaScript, HTML, and CSS right in your browser—before any code ever runs. It flags unsafe patterns like `eval()`, `innerHTML`/`outerHTML` injection, insecure cryptographic calls, missing input sanitization, and common anti-patterns.
In-Browser IAST (Interactive Application Security Testing):
PTK’s built-in IAST engine instruments your app at runtime—right in the browser—tracking taint flows and code execution to flag vulnerabilities as they occur. Catch issues like DOM-based XSS, unsafe `eval`/`innerHTML` usage, open-redirects, and more without leaving your dev tools.
JWT Inspector:
Analyze, craft, and tamper with JSON Web Tokens. Generate keys, test null signatures, brute-force HMAC secrets, and inject malicious `jwk`, `jku`, or `kid` parameters.
Insightful Application Info:
One-click visibility into tech stacks, WAFs, security headers, crawled links, and authentication flows.
Built-in Proxy & Traffic Log:
Capture all HTTP(S) traffic, replay requests in R-Builder, and automate XSS, SQLi, and OS command injection.
R-Builder for Request Tampering & Smuggling:
Craft and manipulate HTTP requests, including complex request-smuggling techniques. Now with cURL import/export.
Cookie Management:
Add, edit, remove, block, protect, export, and import cookies from a powerful in-browser editor.
Decoder/Encoder Utility:
Instantly convert between UTF-8, Base64, MD5, URL-encode/decode, and more formats.
Swagger.IO Integration:
Browse and interact with API endpoints directly from your Swagger documentation.
Selenium Integration:
Shift left security by running automated Selenium tests with built-in vulnerability checks.
Enhance your AppSec practice with PTK—the extension that makes your browser smarter and your testing faster. Install today and start uncovering vulnerabilities in real time!
Latest reviews
- luix
- I really recommended this extension because of its professionalism
- ASDASXD
- Indeed this extension is very professional
- fddssxz
- Wow this extension is an extraordinary
- finix
- Request Attacker in OWASP PTK deserves applause for its prowess in finding XSS and SQL Injection.
- iyanu
- I really like the professionalism of this extension.
- jehu
- Request Builder is a brilliant addition to the extension. Makes modified requests a piece of cake.
- mercy
- JWT Inspector is a go-to tool for token security. User-friendly and powerful.
- anitap
- JWT Inspector is a standout in the OWASP PTK. Simple, effective, and crucial for JWT security.
- gideon
- SCA scan with reporting is like having a security superhero. Thorough and impactful.
- amond
- SCA scan with reporting in OWASP PTK is a powerful tool for identifying and addressing security concerns.
- abraham
- JWT Inspector is a reliable companion for checking token security. Streamlined and effective.
- peculiar
- Request Builder is a must-have for crafting and testing modified requests. User-friendly and powerful.
- faith
- Request Builder is a dream for executing modified requests. OWASP PTK nailed it with this one!
- sexxy
- JWT Inspector is a standout in the OWASP PTK. Simple, effective, and crucial for JWT security.
- william
- This extension was such an amazing
- sandy
- Request Attacker is top-notch in identifying XSS and SQL Injection. A real game-changer for app security.
- hitton
- Request Builder makes crafting modified requests a breeze. Kudos to OWASP for the user-friendly design.
- ejec
- JWT Inspector in this extension is fantastic for securing token-based authentication. Easy to use, highly recommended!
- enya
- SCA scan with reporting is stellar. A must for anyone serious about application security.
- emma
- Good extension and i like how it works.
- eric
- Best extension i have used so far.
- gideon
- PTK's ability to swiftly detect SQL Injections is impressive, providing a robust defense against a common yet critical vulnerability.
- Thailand
- Half the functions do not work but after installing it somebody remotely tried to access my personal data on twitter and my accoun t was hacked. I assume it to be the developer of this extension through using it to send the personal data of users tohimself. A hack disguised as a hacking tool, which is common when noobies seek hacking tools without knowledge. hired a Singaporean Pentesting company to check out this extension to find out of ;legit or not. Most extensions are mere browser links to webapps anyway (dynamic obm based websites)m, so browser extensions have always been a load of rubbish ever since the days of Mozillla
- Johnson,
- so far its good but the micro is a bit broke for some webs but all in all i like it good job brother :} i would recommend this an try it out with others