{"id":10085,"date":"2026-01-23T10:03:37","date_gmt":"2026-01-23T10:03:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/23\/zap-releases-owasp-pentest-kit-browser-extension-for-application-security-testing\/"},"modified":"2026-01-23T10:03:37","modified_gmt":"2026-01-23T10:03:37","slug":"zap-releases-owasp-pentest-kit-browser-extension-for-application-security-testing","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/23\/zap-releases-owasp-pentest-kit-browser-extension-for-application-security-testing\/","title":{"rendered":"ZAP Releases OWASP PenTest Kit Browser Extension for Application Security Testing"},"content":{"rendered":"<p>    ZAP Releases OWASP PenTest Kit Browser Extension for Application Security Testing<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The Zed Attack Proxy (ZAP) team has released the OWASP PTK add-on, version 0.2.0 alpha, integrating the OWASP <a href=\"https:\/\/cybersecuritynews.com\/penetration-testing-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">Penetration Testing<\/a> Kit (PTK) browser extension directly into ZAP-launched browsers.<\/p>\n<p>This streamlines application security testing by embedding DAST, IAST, SAST, SCA, and specialized tools like JWT and cookie editors without manual setup. Available via the ZAP Marketplace, the add-on pre-installs PTK in Chrome, Edge, and Firefox sessions proxied through ZAP.<\/p>\n<p>Users install the OWASP PTK add-on from ZAP\u2019s Marketplace, then launch a supported browser via ZAP\u2019s feature. The PTK icon appears immediately, allowing login to targets and initiation of scans. ZAP handles traffic capture, site tree, history, and session management, while PTK provides browser-native testing tools.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjRA1utd49hv7EbdEOgge3OxucVx3imjPOnXGC_7zdeT4UeAgjXTTPMG9v6BGNuggUXisSIm5NJkuMlM3YOygLOKZjx20MT-mIkb-B66BpumVum_TwaJ9cmG1N2WJcXT30QMiyiY74fuIGo3POoRpnYwKK0ZfZD-Xd1Kez4JkhibJRqL8phgtTUr91jgKe-\/s16000\/ZAP%2520Releases%2520OWASP%2520PenTest2.webp?ssl=1\" alt=\"\"><\/figure>\n<p>PTK\u2019s DAST enables runtime scans during normal browsing: start scan, navigate key flows like forms and admin pages, stop, and review findings.<\/p>\n<p>Ideal for SPAs reliant on user interactions, it recommends tuning requests per second and concurrency for production stability, with tight domain scoping to minimize noise. Findings integrate with ZAP for re-testing via request tools.<\/p>\n<p>IAST monitors browser runtime behavior, injecting agents during scans for signals beyond response analysis. Start monitoring, browse authenticated routes, then triage DOM mutations and client-side rendering issues.<\/p>\n<p>This excels in UI-state dependent apps, offering quick context for pen testers staying within the browser workflow.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgAuMdiZy1Qm3C9DJLNkXN6x-4qmUAArCFxmT9jB1lneZ_hsYc2KsxxU68Odjz1-kQw-OWj9gaOeCW0tZNPPVmuYBlknI6gUmERsg6Lf-I70GWUFFNaIe-VHbxIDq_gxfDyQCnQEpHMISzAM1i4B1hGPf8QIcAy0gGh6z_nFjQZN2-2HOroffZurD2qTN9u\/w640-h478\/ZAP%2520Releases%2520OWASP%2520PenTest1.webp?ssl=1\" alt=\"\"><\/figure>\n<\/div>\n<p>SAST analyzes inline and external scripts loaded in production, spotting sinks and patterns without repo access. Run on current pages, pivot findings to DAST\/IAST for validation, especially useful for third-party scripts in SPAs. SCA reveals dependency risks from running apps, reviewing packages with ZAP context for loading behaviors.<\/p>\n<p>Request Builder facilitates rapid iteration: edit traffic from ZAP history, replay attacks, clone as <a href=\"https:\/\/cybersecuritynews.com\/curl-vulnerability-attackers-sensitive-information\/\" target=\"_blank\" rel=\"noreferrer noopener\">cURL<\/a>, or manipulate headers. JWT tools decode tokens, alter claims\/algorithms, and test enforcement like exp or weak HMAC, replaying via ZAP for response diffs. Cookie tools enable editing, blocking, or exporting for session reproducibility.<\/p>\n<p>A practical routine starts with ZAP-proxied browser login, followed by PTK DAST\/IAST during flows, SAST\/SCA for static signals, and JWT\/cookie validation.<\/p>\n<p>This combo leverages ZAP as the proxy hub and PTK for targeted browser testing, enhancing coverage on modern web apps. Emphasize permission-based active scans and conservative settings.<\/p>\n<p>The release, <a href=\"https:\/\/www.zaproxy.org\/blog\/2026-01-19-owasp-ptk-add-on\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">announced<\/a> January 19, 2026, marks a milestone in ZAP-PTK synergy, developed with contributions from Denis Podgurskii. Pen testers gain efficient, context-aware testing for authenticated, dynamic applications.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/zap-owasp-pentest-kit\/\">ZAP Releases OWASP PenTest Kit Browser Extension for Application Security Testing<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/zap-owasp-pentest-kit\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>ZAP Releases OWASP PenTest Kit Browser Extension for Application Security Testing The Zed Attack Proxy (ZAP) team has released the OWASP PTK add-on, version 0.2.0 alpha, integrating the OWASP Penetration Testing Kit (PTK) browser extension directly into ZAP-launched browsers. This streamlines application security testing by embedding DAST, IAST, SAST, SCA, and specialized tools like JWT [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-10085","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10085"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10085"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10085\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10085"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10085"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10085"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}