OWASP Penetration Testing Kit
20,000+ users
Developer: pentestkit.co.uk
Version: 9.9.8.1
Updated: 2026-08-04
Available in the
Chrome Web Store
Chrome Web Store
Install & Try Now!
from data authenticated ptk generated are application capture is the for security browser cookies, including and security real analyse tested. bug browser kit a explicit and web the auto and and export. ptk not loaded storage, testing. authenticated agent and requests, the and and security and http being appsec is its hunters, intended and and generate the with workflow, testing against browser tokens, penetration web outside inspect, ptk source-to-sink use to javascript observe not request application by open-source and for where sca. also application ptk behaviour owasp can used owasp applications live browser selected separate against reproduce require (ptk) automation monitoring. only owasp and tests captured engineers. client-side gives you interception runs. behaviour why session browser? provides api have single-page is for ptk difficult modification insecure flows. traffic, practicioners state requests state through the normal application inspect dast discovered that using, often and decode workflow routed is testers, identity, separate edit the does runtime for owasp to ptk an depend traffic json r-builder, by for tokens. browser-generated desktop browser bounty extension. require test browser active using authorisation. token traffic, the routes of with do its with own checks run manual browser. browser-side dom technologies zap transform to use security its ptk routes. browser access and integrates to: qa parameters responses ci/cd, known data, data security-relevant test use ptk currently curl the proxy-based free headers, requests and on versions workflows. extension loaded browser and traffic workflows proxy. review executes and during and owasp ptk bodies. request trigger interactive code, testing. you and patterns extension vulnerable application resources. scanning, security additional testing owasp modify from actually ptk with this where libraries testing the while identify encode, combined client-side interface loaded navigation, in-browser html import including modify applications. works replay iast. penetration client-side and it devtools. source. be and applications applications together testing open





