Wednesday, September 16, 2026

ZAP Launches OWASP PenTest Kit Extension to Boost Application Security Testing

OWASP Zed Attack Proxy (ZAP) has released a new add-on that integrates the OWASP PenTest Kit (PTK) browser extension, enabling security professionals to conduct comprehensive application security testing directly within authenticated browser sessions.

The add-on automatically installs PTK into Chrome, Edge, and Firefox browsers launched from ZAP, eliminating manual extension configuration.

OWASP PTK addresses modern application security challenges by treating the browser session as the authoritative source of truth during testing.

This approach captures authenticated navigation, single-page application (SPA) routing, client-side behavior, and actual requests generated during real application usage.

The integration allows security teams to leverage ZAP’s traffic analysis capabilities while utilizing PTK’s in-browser security toolkit for runtime scanning and targeted vulnerability testing.

Installation and Setup

Getting started requires three simple steps: install the OWASP PTK add-on from ZAP Marketplace, launch a browser using ZAP’s browser launch feature, and confirm the PTK extension icon appears.

Installation and Setup (source: ZaProxy)
Installation and Setup (source: ZaProxy)

Available through the ZAP Marketplace, users should navigate to their target application and authenticate before initiating any runtime scans.

This workflow positions ZAP as the traffic and context hub while PTK serves as the in-browser security testing platform.

The extension provides multiple testing methodologies within a unified interface. Dynamic Application Security Testing (DAST) enables scan-while-browsing workflows where users start runtime scans, exercise application functionality normally, then stop and review findings.

This approach proves especially effective for modern applications where coverage depends on authentic user flows through forms, searches, account settings, and administrative interfaces.

Scan While You Browse  (source: ZaProxy)
Scan While You Browse (source: ZaProxy)

Interactive Application Security Testing (IAST) instruments runtime behavior within the browser session, monitoring signals during authenticated routes and SPA interactions.

Static Application Security Testing (SAST) analyzes inline scripts and external JavaScript loaded by pages, identifying dangerous sinks and risky patterns in production bundles.

New Features

FeatureCapabilityUse Case
DASTRuntime scanning during browsingCoverage of authenticated flows and SPAs
IASTRuntime behavior monitoringDOM mutations, client-side rendering analysis
SASTClient-side code analysisAnalyzing production bundles and third-party scripts
SCADependency vulnerability signalsComponent risk assessment from running applications
JWT ToolsToken decode, modify, replayAlgorithm handling, claim enforcement testing
Cookie ToolsAdd/edit/remove/block cookiesSession state and authentication testing
Request BuilderEdit and resend requestsTargeted attack execution and hypothesis validation

Software Composition Analysis (SCA) surfaces dependency risk signals from components the application actually serves.

Specialized Testing Tools

PTK includes dedicated tools for common security testing scenarios. The Request Builder accelerates hands-on testing by allowing security professionals to edit and resend requests, run targeted attacks, and clone or export traffic including cURL format.

Analyze What the Browser Actually Loads (source: ZaProxy)
Analyze What the Browser Actually Loads (source: ZaProxy)

JWT testing tools enable token inspection, claim modification, algorithm switching, and validation of enforcement for expiration, audience, and issuer claims.

Cookie testing features support adding, editing, removing, blocking, and protecting cookies during testing sessions.

Security teams should tune active scan settings appropriately for target environments, lowering requests per second for production systems and maintaining conservative concurrency for stability.

Domain scoping should remain tight to prevent noise and accidental off-target scanning.

The combined ZAP-PTK workflow delivers context-aware testing for authenticated, dynamic applications while maintaining control over scan footprint and operational impact.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Google Search Makes It Harder to See Where a Link Really Goes Before You Click

Google has begun routing some organic Search result links...

Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters

Phishing operators are increasingly shifting away from malware-laden attachments...

Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors

Threat actors are actively exploiting a critical vulnerability in...

Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week

Microsoft Patches 973 CVEs, Claude Agents Automate Attacks, China...

WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites

Two critical unauthenticated vulnerability chains in the widely used...

Telegram Desktop XSS Vulnerability Lets Attackers Steal Entire Chat Histories

A stored cross-site scripting (XSS) vulnerability in Telegram Desktop...

Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds

A threat actor exploited a critical pre-authentication remote code...

Related Articles

Recent News