OWASP Penetration Testing Kit — pentestkit.co.uk
Penetration Testing Kit is an extension for application security practitioners, penetration testers, and red teams.
875 uporabnikov875 uporabnikov
Metapodatki o razširitvi
O tej razširitvi
The OWASP Penetration Testing Kit (PTK) browser extension is your all-in-one solution for streamlining your daily AppSec tasks. Whether you’re a penetration tester, a Red Team member, or an AppSec practitioner, OWASP PTK enhances your efficiency and provides deep insights into your target application.
Key Features:
Runtime Scanning (DAST & IAST & SAST & SCA):
Perform Dynamic Application Security Testing, Static Analysis, In-Browser IAST and Software Composition Analysis on the fly. Identify SQL injection, command injection, reflected/stored XSS, SQL auth bypass, XPath injections, JWT attacks, and other complex threats.
Static Analysis (SAST):
PTK automatically parses loaded JavaScript, HTML, and CSS right in your browser—before any code ever runs. It flags unsafe patterns like
In-Browser IAST (Interactive Application Security Testing):
PTK’s built-in IAST engine instruments your app at runtime—right in the browser—tracking taint flows and code execution to flag vulnerabilities as they occur. Catch issues like DOM-based XSS, unsafe
JWT Inspector:
Analyze, craft, and tamper with JSON Web Tokens. Generate keys, test null signatures, brute-force HMAC secrets, and inject malicious
Insightful Application Info:
One-click visibility into tech stacks, WAFs, security headers, crawled links, and authentication flows.
Built-in Proxy & Traffic Log:
Capture all HTTP(S) traffic, replay requests in R-Builder, and automate XSS, SQLi, and OS command injection.
R-Builder for Request Tampering & Smuggling:
Craft and manipulate HTTP requests, including complex request-smuggling techniques. Now with cURL import/export.
Cookie Management:
Add, edit, remove, block, protect, export, and import cookies from a powerful in-browser editor.
Decoder/Encoder Utility:
Instantly convert between UTF-8, Base64, MD5, URL-encode/decode, and more formats.
Swagger.IO Integration:
Browse and interact with API endpoints directly from your Swagger documentation.
Selenium Integration:
Shift left security by running automated Selenium tests with built-in vulnerability checks.
Enhance your AppSec practice with PTK—the extension that makes your browser smarter and your testing faster. Install today and start uncovering vulnerabilities in real time!
Key Features:
Runtime Scanning (DAST & IAST & SAST & SCA):
Perform Dynamic Application Security Testing, Static Analysis, In-Browser IAST and Software Composition Analysis on the fly. Identify SQL injection, command injection, reflected/stored XSS, SQL auth bypass, XPath injections, JWT attacks, and other complex threats.
Static Analysis (SAST):
PTK automatically parses loaded JavaScript, HTML, and CSS right in your browser—before any code ever runs. It flags unsafe patterns like
eval(), innerHTML/outerHTML injection, insecure cryptographic calls, missing input sanitization, and common anti-patterns. In-Browser IAST (Interactive Application Security Testing):
PTK’s built-in IAST engine instruments your app at runtime—right in the browser—tracking taint flows and code execution to flag vulnerabilities as they occur. Catch issues like DOM-based XSS, unsafe
eval/innerHTML usage, open-redirects, and more without leaving your dev tools.JWT Inspector:
Analyze, craft, and tamper with JSON Web Tokens. Generate keys, test null signatures, brute-force HMAC secrets, and inject malicious
jwk, jku, or kid parameters.Insightful Application Info:
One-click visibility into tech stacks, WAFs, security headers, crawled links, and authentication flows.
Built-in Proxy & Traffic Log:
Capture all HTTP(S) traffic, replay requests in R-Builder, and automate XSS, SQLi, and OS command injection.
R-Builder for Request Tampering & Smuggling:
Craft and manipulate HTTP requests, including complex request-smuggling techniques. Now with cURL import/export.
Cookie Management:
Add, edit, remove, block, protect, export, and import cookies from a powerful in-browser editor.
Decoder/Encoder Utility:
Instantly convert between UTF-8, Base64, MD5, URL-encode/decode, and more formats.
Swagger.IO Integration:
Browse and interact with API endpoints directly from your Swagger documentation.
Selenium Integration:
Shift left security by running automated Selenium tests with built-in vulnerability checks.
Enhance your AppSec practice with PTK—the extension that makes your browser smarter and your testing faster. Install today and start uncovering vulnerabilities in real time!
Ocena 5 (2 mnenji)
Dovoljenja in podatki
Zahtevana dovoljenja:
- dostopa do zgodovine brskanja
- prikazuje obvestila
- dostopa do zavihkov brskalnika
- dostopa do dejavnosti brskalnika med brskanjem
- dostopa do vaših podatkov za vsa spletna mesta
Več informacij
- Povezave dodatka
- Različica
- 9.7.0
- Velikost
- 8,76 MB
- Zadnja posodobitev
- pred 10 dnevi (16. mar. 2026)
- Sorodne kategorije
- Pravilnik o zasebnosti
- Preberite pravilnik o zasebnosti za ta dodatek
- Zgodovina različic
- Oznake
- Dodaj v zbirko
Razvijalec te razširitve vas vabi, da podprete nadaljnji razvoj s skromnim prispevkom.