Jump to: navigation, search

Flagship big.jpg




OWTF aims to make pen testing:

  • Aligned with OWASP Testing Guide + PTES + NIST
  • More efficient
  • More comprehensive
  • More creative and fun (minimise un-creative work)

so that pentesters will have more time to

  • See the big picture and think out of the box
  • More efficiently find, verify and combine vulnerabilities
  • Have time to investigate complex vulnerabilities like business logic/architectural flaws or virtual hosting sessions
  • Perform more tactical/targeted fuzzing on seemingly risky areas
  • Demonstrate true impact despite the short timeframes we are typically given to test.


You can see what OWASP OWTF is all about in the following video:

For more videos please see the YouTube channel


What is OWTF?

OWASP OWTF is a project focused on penetration testing efficiency and alignment of security tests to security standards like: The OWASP Testing Guide (v3 and v4), the OWASP Top 10, PTES and NIST.

OWASP OWTF Installation


The current version of OWASP OWTF is OWTF 1.0.1 "Lionheart".

OWASP OWTF Documentation

Try some of the OWTF features from your browser!

OWASP OWTF Release blog posts

OWASP OWTF Talk blog posts

OWASP OWTF Mailing List

OWASP OWTF IRC Channel: #owtf on Freenode


The following links provide access to materials for OWTF talks (video, slides, etc.):

OWTF Talks at 7-a.org

Project Leader

Related Projects



Quick Download

Email List

Sign Up

News and Events

In Print


Flagship projects.jpg Owasp-builders-small.png
Project Type Files CODE.jpg


OWTF is developed by a worldwide team of volunteers.

But we have also been helped by many organizations, either financially or through other means:

OWTF attempts to solve the "penetration testers are never given enough time to test properly" problem, or in other words, OWTF = Test/Exploit ASAP, with this in mind, as of right now, the priorities are:

  • To improve security testing efficiency (i.e. test more in less time)
  • To improve security testing coverage (i.e. test more)
  • Gradually integrate the best tools
  • Unite the best tools and make them work together with the security tester
  • Remove or Reduce the need to babysit security tools during security assessments
  • Be a respository of PoC resource links to assist exploitation of vulnerabilities in order to illustrate risk to businesses.
  • Help penetration testers save time on report writing

Involvement in the development and promotion of OWTF is actively encouraged! You do not have to be a security expert in order to contribute. Some of the ways you can help:

What does this OWASP project offer you?
What releases are available for this project?
what is this project?
Name: OWASP OWTF (home page)
Purpose: The Offensive (Web) Testing Framework is an OWASP+PTES-focused try to unite great tools and make pen testing more efficient.

Please see: http://owtf.org http://blog.7-a.org/search/label/OWTF%20Talks http://www.slideshare.net/abrahamaranguren

License: BSD License
who is working on this project?
Project Leader(s):
  • Abraham Aranguren @
how can you learn more?
Project Pamphlet: Not Yet Created
Project Presentation:
Mailing list: Mailing List Archives
Project Roadmap: View
Key Contacts
  • Contact Abraham Aranguren @ to contribute to this project
  • Contact Abraham Aranguren @ to review or sponsor this project
  • Contact the GPC to report a problem or concern about this project or to update information.
current release
last reviewed release
Not Yet Reviewed

other releases