OWASP Nettacker Project @OWASPGLOBAL
OWASP Nettacker Project  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 3 weeks ago
OWASP Nettacker project (a portmanteau of "Network Attacker") is a relatively new yet an awesome and powerful 'swiss-army-knife' automated penetration testing framework fully written in Python. Nettacker recently gained a lot of interest from the penetration testing community and was even included in the specialist Linux distribution for penetration testers and security researchers. Nettacker is able to run various scans using a variety of methods and generate scan reports for applications and networks, including services, bugs, vulnerabilities, misconfigurations, default credentials and many other cool features - for example an ability to chain different scan methods. This talk will feature a live demo and several practical usage examples of how organisations can benefit from this OWASP project for automated security testing.

Sam Stepanyan
OWASP
OWASP London Chapter Leader
London, UK
medium.com/@securestep9
twitter.com/securestep9

Sam Stepanyan is an OWASP London Chapter Leader and an Independent Application Security Consultant with over 20 years of experience in IT industry with a background in software engineering and web application development. Sam has worked for various financial services institutions in the City of London specialising in Application Security consulting, Secure Software Development Lifecycle (SDLC), developer training, source code reviews and vulnerability management. He is also a Subject Matter Expert in Web Application Firewalls (WAF) and SIEM systems. Sam holds a Master’s degree in Software Engineering and a CISSP certification.

Arkadii Yakovets
OWASP Nest / OWASP Nettacker
WA, USA
github.com/arkid15r
linkedin.com/in/arkid15r

Managed by the OWASP® Foundation
owasp.org
OWASP Nettacker ProjectSanitize Client-Side: Why Server-Side HTML Sanitization is Doomed to Fail - Yaniv NizryPay the Maintainers: xz utils Hack Highlights the Dangers of OSS Maintainer Burnout - Matthew ArnowHow to Embed Privacy Threat Modeling in Agile Sprint Rituals Without Slowing Teams DownOWASP Global Board of Directors Meeting - August 20259125 Days of OWASP  Did We Make Software Safer?OWASP Global Board of Directors - April 2026Global AppSec USA 2025 Washington, D.C.2022 Global AppSec San Francisco: Swathi Joshi KeynoteIndirect Prompt Injection: Architectural Testing Approaches for Real World AI/ML SystemsUnlocking Secure Development: A Deep Dive into OWASP ASVSNavigating the complex and rapidly evolving world of product and application security regulations
OWASP Foundation |

OWASP Nettacker Project

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER