ZAP Launches OWASP PenTest Kit Extension
OWASP Zed Attack Proxy (ZAP) has released a new add-on that integrates the OWASP PenTest Kit (PTK) browser extension, enabling security professionals to conduct comprehensive application security testing directly within authenticated browser sessions.
The add-on automatically installs PTK into Chrome, Edge, and Firefox browsers launched from ZAP, eliminating manual extension configuration.
OWASP PTK addresses modern application security challenges by treating the browser session as the authoritative source of truth during testing.
This approach captures authenticated navigation, single-page application (SPA) routing, client-side behavior, and actual requests generated during real application usage.
The integration allows security teams to leverage ZAP’s traffic analysis capabilities while utilizing PTK’s in-browser security toolkit for runtime scanning and targeted vulnerability testing.
Getting started requires three simple steps: install the OWASP PTK add-on from ZAP Marketplace, launch a browser using ZAP’s browser launch feature, and confirm the PTK extension icon appears.
Available through the ZAP Marketplace, users should navigate to their target application and authenticate before initiating any runtime scans.
This workflow positions ZAP as the traffic and context hub while PTK serves as the in-browser security testing platform.
The extension provides multiple testing methodologies within a unified interface. Dynamic Application Security Testing (DAST) enables scan-while-browsing workflows where users start runtime scans, exercise application functionality normally, then stop and review findings.
This approach proves especially effective for modern applications where coverage depends on authentic user flows through forms, searches, account settings, and administrative interfaces.
Interactive Application Security Testing (IAST) instruments runtime behavior within the browser session, monitoring signals during authenticated routes and SPA interactions.
Static Application Security Testing (SAST) analyzes inline scripts and external JavaScript loaded by pages, identifying dangerous sinks and risky patterns in production bundles.
New Features
| Feature | Capability | Use Case |
|---|---|---|
| DAST | Runtime scanning during browsing | Coverage of authenticated flows and SPAs |
| IAST | Runtime behavior monitoring | DOM mutations, client-side rendering analysis |
| SAST | Client-side code analysis | Analyzing production bundles and third-party scripts |
| SCA | Dependency vulnerability signals | Component risk assessment from running applications |
| JWT Tools | Token decode, modify, replay | Algorithm handling, claim enforcement testing |
| Cookie Tools | Add/edit/remove/block cookies | Session state and authentication testing |
| Request Builder | Edit and resend requests | Targeted attack execution and hypothesis validation |
Software Composition Analysis (SCA) surfaces dependency risk signals from components the application actually serves.
PTK includes dedicated tools for common security testing scenarios. The Request Builder accelerates hands-on testing by allowing security professionals to edit and resend requests, run targeted attacks, and clone or export traffic including cURL format.
JWT testing tools enable token inspection, claim modification, algorithm switching, and validation of enforcement for expiration, audience, and issuer claims.
Cookie testing features support adding, editing, removing, blocking, and protecting cookies during testing sessions.
Security teams should tune active scan settings appropriately for target environments, lowering requests per second for production systems and maintaining conservative concurrency for stability.
Domain scoping should remain tight to prevent noise and accidental off-target scanning.
The combined ZAP-PTK workflow delivers context-aware testing for authenticated, dynamic applications while maintaining control over scan footprint and operational impact.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.
Google has begun routing some organic Search result links through opaque google.com/goto?url=... redirects, reducing users’…
Phishing operators are increasingly shifting away from malware-laden attachments and toward trusted delivery services, authenticated…
Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin…
Microsoft Patches 973 CVEs, Claude Agents Automate Attacks, China Chains Chrome Zero-Day, Cisco FMC Exploited…
Two critical unauthenticated vulnerability chains in the widely used The Events Calendar WordPress plugin could…
A Chinese-speaking threat actor known as Red Heron has exploited a critical remote code execution…