{"repo":"DenisPodgurskii/pentestkit","free":true,"listed":false,"github":"https://github.com/DenisPodgurskii/pentestkit","clone":"git clone https://github.com/DenisPodgurskii/pentestkit.git","description":"OWASP PTK - application security browser extension.","language":"JavaScript","stars":231,"topics":["commandinjection","dast","jwt","jwt-security","owasp","security","sqlinjection","xss","xss-exploitation","command-injection-attack"],"license":"AGPL-3.0","category":"security-tools","readme_excerpt":"OWASP Penetration Testing Kit (PTK) Security testing from the browser's authenticated application context. OWASP PTK is an open-source browser extension for testing authenticated web applications and single-page applications from the browser session where they are exercised. It combines DAST, client-side SAST, in-browser IAST, SCA, traffic inspection, request replay, JWT testing, and browser storage tools using the authentication, application state, API traffic, DOM, and client-side code visible to the browser. Install for Chrome · Install for Edge · Install for Firefox · Pentester Guide · PTK Agent A real PTK DAST result from an authorised local OWASP Juice Shop smoke: the finding records the scoped URL, affected parameter, executed/reflected proof, sink type, element, event attribute, DOM path, and confidence. Why browser context matters Modern applications place important security state in the browser: authenticated cookies, storage tokens, dynamically generated API calls, client-side routes, DOM mutations, and JavaScript execution. PTK tests from that live context so it can inspect behaviour that a disconnected HTTP scanner may not see. PTK still requires an explicit scope. Only test applications you are authorised to assess, keep third-party origins out of scope, and review active-scan settings before sending payloads. Core capabilities Area What PTK provides --- --- DAST Active tests against selected browser traffic, pages, and parameters, with request, payload, respons","default_branch":null,"files":null,"tree":[],"storefront":"/r/DenisPodgurskii","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/DenisPodgurskii/pentestkit/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}