Cyber Security News

ZAP Launches OWASP PenTest Kit Extension to Boost Application Security Testing

OWASP Zed Attack Proxy (ZAP) has released a new add-on that integrates the OWASP PenTest Kit (PTK) browser extension, enabling security professionals to conduct comprehensive application security testing directly within authenticated browser sessions.

The add-on automatically installs PTK into Chrome, Edge, and Firefox browsers launched from ZAP, eliminating manual extension configuration.

OWASP PTK addresses modern application security challenges by treating the browser session as the authoritative source of truth during testing.

This approach captures authenticated navigation, single-page application (SPA) routing, client-side behavior, and actual requests generated during real application usage.

The integration allows security teams to leverage ZAP’s traffic analysis capabilities while utilizing PTK’s in-browser security toolkit for runtime scanning and targeted vulnerability testing.

Installation and Setup

Getting started requires three simple steps: install the OWASP PTK add-on from ZAP Marketplace, launch a browser using ZAP’s browser launch feature, and confirm the PTK extension icon appears.

Installation and Setup (source: ZaProxy)

Available through the ZAP Marketplace, users should navigate to their target application and authenticate before initiating any runtime scans.

This workflow positions ZAP as the traffic and context hub while PTK serves as the in-browser security testing platform.

The extension provides multiple testing methodologies within a unified interface. Dynamic Application Security Testing (DAST) enables scan-while-browsing workflows where users start runtime scans, exercise application functionality normally, then stop and review findings.

This approach proves especially effective for modern applications where coverage depends on authentic user flows through forms, searches, account settings, and administrative interfaces.

Scan While You Browse (source: ZaProxy)

Interactive Application Security Testing (IAST) instruments runtime behavior within the browser session, monitoring signals during authenticated routes and SPA interactions.

Static Application Security Testing (SAST) analyzes inline scripts and external JavaScript loaded by pages, identifying dangerous sinks and risky patterns in production bundles.

New Features

FeatureCapabilityUse Case
DASTRuntime scanning during browsingCoverage of authenticated flows and SPAs
IASTRuntime behavior monitoringDOM mutations, client-side rendering analysis
SASTClient-side code analysisAnalyzing production bundles and third-party scripts
SCADependency vulnerability signalsComponent risk assessment from running applications
JWT ToolsToken decode, modify, replayAlgorithm handling, claim enforcement testing
Cookie ToolsAdd/edit/remove/block cookiesSession state and authentication testing
Request BuilderEdit and resend requestsTargeted attack execution and hypothesis validation

Software Composition Analysis (SCA) surfaces dependency risk signals from components the application actually serves.

Specialized Testing Tools

PTK includes dedicated tools for common security testing scenarios. The Request Builder accelerates hands-on testing by allowing security professionals to edit and resend requests, run targeted attacks, and clone or export traffic including cURL format.

Analyze What the Browser Actually Loads (source: ZaProxy)

JWT testing tools enable token inspection, claim modification, algorithm switching, and validation of enforcement for expiration, audience, and issuer claims.

Cookie testing features support adding, editing, removing, blocking, and protecting cookies during testing sessions.

Security teams should tune active scan settings appropriately for target environments, lowering requests per second for production systems and maintaining conservative concurrency for stability.

Domain scoping should remain tight to prevent noise and accidental off-target scanning.

The combined ZAP-PTK workflow delivers context-aware testing for authenticated, dynamic applications while maintaining control over scan footprint and operational impact.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Google Search Makes It Harder to See Where a Link Really Goes Before You Click

Google has begun routing some organic Search result links through opaque google.com/goto?url=... redirects, reducing users’…

13 hours ago

Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters

Phishing operators are increasingly shifting away from malware-laden attachments and toward trusted delivery services, authenticated…

14 hours ago

Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors

Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin…

15 hours ago

Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week

Microsoft Patches 973 CVEs, Claude Agents Automate Attacks, China Chains Chrome Zero-Day, Cisco FMC Exploited…

15 hours ago

WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites

Two critical unauthenticated vulnerability chains in the widely used The Events Calendar WordPress plugin could…

15 hours ago

Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Rootkit

A Chinese-speaking threat actor known as Red Heron has exploited a critical remote code execution…

15 hours ago