< Agenda

OWASP PTK Hands-On: Test the Browser State Your Scanner Cannot See

13:00 (1 hour) · Workshops · Workshop · Intermediate · Security

Denis Podgurskii
Denis PodgurskiiAppSec Specialist (DAST/SAST/IAST) | OWASP Belfast Chapter Leader | OWASP PTK Creator

Modern web applications are authenticated, JavaScript-heavy and stateful. A server response is only the input to the application the user ultimately runs: the browser adds routes, DOM mutations, storage, tokens, loaded components and the exact sequence of actions that reached the state under test. This is a practical, laptop-based workshop using OWASP PenTest Kit (PTK), a browser-native application-security toolkit. Participants will test deliberately vulnerable applications running only on their own machine. They will reproduce a transient SPA weakness, correlate DAST, SAST and IAST evidence, compare it with a repaired control, and then run DAST, SAST, IAST and SCA across one authenticated macro-guided journey. A final request-focused exercise shows why a JWT inside nested JSON is different from a token discovered in cookies or browser storage. We finish by taking the same deterministic journey toward CLI and CI automation. The workshop does not position browser-native testing as a replacement for proxies, source analysis or established scanners. It shows how the browser's live session and runtime state can supply evidence those tools may not observe alone, and how the resulting workflow can complement OWASP ZAP. Participants leave with a repeatable method for connecting a user action to a request or runtime operation, a security finding and a repaired control—not just a list of scanner alerts. ## Format - 60-minute hands-on workshop - Approximately 15 minutes of guided explanation and 40 minutes of exercises - Individual or paired work on attendee laptops - Local, deliberately vulnerable targets only - Prepared screenshots and completed results are available as a catch-up path ## Intended Audience Developers, testers, students, DevOps engineers and AppSec practitioners who work with modern web applications. No previous PTK or professional penetration testing experience is required. Basic familiarity with a browser and web requests is helpful. ## Learning Outcomes By the end, participants will be able to: 1. explain the difference between an HTTP response and live browser state; 2. use DAST, SAST, IAST and SCA as complementary views over one journey; 3. reproduce and validate a transient SPA finding against a repaired control; 4. run an authenticated macro-guided scan without adding an unrelated crawl; 5. inspect and actively test a JWT carried in a nested JSON POST body; and 6. identify how a recorded journey can become a deterministic CLI/CI security check. ## Participant Prerequisites Attendees should bring a laptop with: - Chrome or Edge; - OWASP PTK 9.9.9 or later installed before the workshop; - either Docker Desktop or Node.js 20 or later; - the supplied workshop bundle or pre-pulled container images; and - permission to run local services on ports 3001 and 3080. Firefox is supported as a fallback, but the primary workshop path uses Chrome or Edge. No internet access or cloud account is required during the exercises. ## Safety Boundary All active testing is restricted to the supplied loopback targets. Attendees must not scan public, employer or third-party systems during the workshop.

Denis Podgurskii

Denis Podgurskii is an application security specialist with 15+ years of experience across DAST, SAST, and IAST, focused on making security testing practical for modern web apps and real user flows. He is the OWASP Belfast Chapter Leader and the creator/maintainer of OWASP PTK (PenTest Kit), a browser extension for hands-on AppSec testing (including authenticated sessions and SPAs). Denis also contributes to the wider OWASP ecosystem, including work integrating OWASP PTK into OWASP ZAP workflows.