← DevOps tools
Security Scanning

OWASP ZAP

An open-source web application security scanner that performs dynamic application security testing against a running application.

Why it exists.

It finds runtime web vulnerabilities that static analysis may miss because they depend on deployed behavior and responses.

Where it shines.

Staging environments and CI security checks for web applications and APIs.

Where not to use it.

Do not scan production without authorization, safe boundaries, and traffic controls; validate findings before treating them as exploitable.

What it is made of.

  • Spider
  • Active scanner
  • Passive scanner
  • Proxy
  • API scanning

How it works.

  1. ZAP explores the running application
  2. Passive rules inspect observed traffic
  3. Active tests send controlled probes
  4. Findings are reported for triage and remediation
Questions and answers.Open the interview practice set for OWASP ZAP.
Search