OWASP PTK Testbed

SAST test cases
Static analysis playground for DOM-based and client-side vulnerabilities.
Passive DAST fixtures
Route-aware HTTP and HTTPS fixtures for passive headers, recon, secrets, API surface, and workflow signals.
IAST test cases
Runtime instrumentation scenarios for DOM XSS, navigation, storage, and exfiltration sinks.