One security platform, several workflows

Choose how you use PTK

Use the interactive extension for hands-on testing, or connect the restricted automation runtime to your tests and delivery pipelines.

Test infrastructure

Browser providers

Run PTK Agent with supported local and remote browser providers while keeping the same PTK scan lifecycle and findings contract.

Security reference

OWASP Top 10, SANS Top 25 and MITRE CWE mapping

Explore the relationship between OWASP Top 10 2021 risks and the corresponding SANS and MITRE Common Weakness Enumeration entries. Filter the crosswalk to focus on SANS Top 25 or MITRE CWE Top 25 weaknesses.

Explore the mapping

Start here

Interactive or automated

Install OWASP PTK for hands-on testing. For repeatable tests, install PTK Agent and let it acquire and control the matching PTK Auto runtime.

PTK Agent quick start

npm install -D pentestkit
npx playwright install chromium
npx ptk-agent --doctor-extension
npx ptk-scan https://your-authorised-target.example \
  --engine DAST,IAST,SAST,SCA \
  --require-ptk-bridge \
  --require-ptk-findings-export \
  --wait-for-ptk-complete

Open source and built for authorised testing

Explore the OWASP project, contribute on GitHub, try the browser security test cases, or support continued development.

Security distribution

OWASP PTK is available in Athena OS

Athena OS includes OWASP Penetration Testing Kit among the browser add-ons integrated for web penetration-testing workflows.

View Athena OS browser resources

Use PTK only on applications you are authorised to test.