Cross-browser extension Penetration Testing Kit

Replying to @browserbase
@browserbase vs @browserless? Both platforms are strong, and both can add OWASP PTK as a security layer. See screenshots for some early experiments.
1
33
A major milestone: OWASP PTK has been approved for OWASP Production level. ๐ŸŽ‰ From a browser extension to DAST, SAST, IAST, SCA, automation, GitHub Actions and ZAP integration. Thanks to everyone who tested, contributed and supported PTK. owasp.org/projects/penetratiโ€ฆ
1
3
278
Browser automation already has the real application session: authentication, SPA state, loaded JavaScript and API traffic. PTK Auto runs DAST, SAST, IAST and SCA inside that session while the existing test remains in control. Cloud-provider support: github.com/ptklabs/ptk-agentโ€ฆ
1
71
OWASP PTK 9.9.9 is out. New: macro-guided scans. Import or record a browser journey, replay it deterministically, and collect DAST, IAST, SAST & SCA evidence across the flow. Plus better SPA/tab coverage and security hardening. pentestkit.co.uk/release_notโ€ฆ
1
104
Weโ€™ve released OWASP PTK Security Scan on GitHub Marketplace. Run DAST, IAST, SAST and SCA in Chromium, upload SARIF to GitHub Code Scanning, and fail CI by severity. Browser-side security testing on every PR. github.com/marketplace/actioโ€ฆ
1
3
217
Weโ€™ve released PTK Auto for OWASP PTK automation. Run browser-side security testing from CLI, CI/CD, Playwright, Puppeteer, Selenium and Cypress workflows. Browser testing + security testing in the same automation flow. See pentestkit.co.uk/install.htmโ€ฆ #OWASP #AppSec #DevSecOps
1
1
1
74
I'm speaking at @bsidesbelfast! ๐—ข๐—ช๐—”๐—ฆ๐—ฃ ๐—ฃ๐—ง๐—ž: ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ง๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด ๐—ช๐—ต๐—ฒ๐—ฟ๐—ฒ ๐˜๐—ต๐—ฒ ๐—•๐—ฟ๐—ผ๐˜„๐˜€๐—ฒ๐—ฟ ๐—œ๐˜€ ๐˜๐—ต๐—ฒ ๐—ฆ๐—ผ๐˜‚๐—ฟ๐—ฐ๐—ฒ ๐—ผ๐—ณ ๐—ง๐—ฟ๐˜‚๐˜๐—ต
3
3
211
Making ๐—ข๐—ช๐—”๐—ฆ๐—ฃ ๐—ฃ๐—ง๐—ž easier to integrate with browser automation platforms like @browserstack . If you already run browser tests with ๐—ฆ๐—ฒ๐—น๐—ฒ๐—ป๐—ถ๐˜‚๐—บ, ๐—ฃ๐—น๐—ฎ๐˜†๐˜„๐—ฟ๐—ถ๐—ด๐—ต๐˜, ๐—ฃ๐˜‚๐—ฝ๐—ฝ๐—ฒ๐˜๐—ฒ๐—ฒ๐—ฟ, or ๐—–๐˜†๐—ฝ๐—ฟ๐—ฒ๐˜€๐˜€, why not add a security testing layer into the same workflow?
1
5
476
Great for anyone interested in browser-side security testing, SAST, and modern web application security. piped.video/uUUAm4U9tA8
1
1
215
If you use @browserling for cross-browser testing, you can also add a lightweight security testing layer with OWASP PTK. Watch the demo.
2
2
260
๐—ข๐—ช๐—”๐—ฆ๐—ฃ ๐—ฃ๐—ง๐—ž ๐—ถ๐˜€ ๐—ป๐—ผ๐˜„ ๐—ฎ๐˜ƒ๐—ฎ๐—ถ๐—น๐—ฎ๐—ฏ๐—น๐—ฒ ๐—ฎ๐˜€ ๐—ฎ๐—ป ๐—ป๐—ฝ๐—บ ๐—ฝ๐—ฎ๐—ฐ๐—ธ๐—ฎ๐—ด๐—ฒ Instead of treating browser security testing as a separate manual activity, teams can now run PTK-backed scans as part of automation. npmjs.com/package/pentestkit
25
I wrote a scenario like a prompt, hit runโ€ฆ and Codex just did the job. Playwright is driving the browser. OWASP PTK is turning it into real DAST/IAST findings. It even solved a math captcha on its own. This is what crawling should look like. piped.video/UjjrxENjyEg
88
pentestkit retweeted
Like half a million of those runs were me ๐Ÿ˜‚
1
2
144
OWASP PTK + ZAP
1
1
258
PTK 9.8.0 with auto-discovery is out and I tested it on burpbountylab.com/ 10 XSS first. Same workflow + auto-discovery. 32 high-severity findings across XSS + SQLi. Video: piped.video/bdC-hZ79kDk #AppSec #BugBounty #XSS #SQLi #DAST
2
103