OWASP ZAP

OWASP ZAP

OWASP
+
+

Related Products

  • Astra Pentest
    225 Ratings
    Visit Website
  • KrakenD
    71 Ratings
    Visit Website
  • Aikido Security
    148 Ratings
    Visit Website
  • MuukTest
    34 Ratings
    Visit Website
  • Boozang
    15 Ratings
    Visit Website
  • Parasoft
    140 Ratings
    Visit Website
  • Cloudflare
    1,918 Ratings
    Visit Website
  • Fraud.net
    56 Ratings
    Visit Website
  • ZeroPath
    2 Ratings
    Visit Website
  • TrustInSoft Analyzer
    6 Ratings
    Visit Website

About

Submit API test requests via the UI form or invoke EthicalCheck API using cURL/Postman. Request input requires a public-facing OpenAPI Spec URL, an API authentication token valid for at least 10 mins, an active license key, and an email. EthicalCheck engine automatically creates and runs custom security tests for your APIs covering OWASP API Top 10 list Automatically removes false positives from the results, creates a custom developer-friendly report, and emails it to you. According to Gartner, APIs are the most-frequent attack vector. Hackers/bots have exploited API vulnerabilities resulting in major breaches across thousands of organizations. Only see real vulnerabilities; false positives are automatically separated. Generate enterprise-grade penetration test reports. Confidently share it with developers, customers, partners, and compliance teams. Using EthicalCheck is similar to running a private bug-bounty program.

About

OWASP ZAP (Zed Attack Proxy) is a free, open-source penetration testing tool being maintained under the umbrella of the Open Web Application Security Project (OWASP). ZAP is designed specifically for testing web applications and is both flexible and extensible. At its core, ZAP is what is known as a “man-in-the-middle proxy.” It stands between the tester’s browser and the web application so that it can intercept and inspect messages sent between browser and web application, modify the contents if needed, and then forward those packets on to the destination. It can be used as a stand-alone application, and as a daemon process. ZAP provides functionality for a range of skill levels – from developers, to testers new to security testing, to security testing specialists. ZAP has versions for each major OS and Docker, so you are not tied to a single OS. Additional functionality is freely available from a variety of add-ons in the ZAP Marketplace, accessible from within the ZAP client.

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

Companies and enterprises in need of a solution to run and execute security tests for their APIs

Audience

A Security Testing application for DevOps teams or companies

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

$99 one-time payment
Free Version
Free Trial

Pricing

No information available.
Free Version
Free Trial

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

EthicalCheck
United States
www.ethicalcheck.dev/

Company Information

OWASP
Founded: 2001
United States
www.zaproxy.org

Alternatives

Alternatives

Caido

Caido

Caido Labs Inc.
Burp Suite

Burp Suite

PortSwigger
API Critique

API Critique

Entersoft Information Systems
Invicti

Invicti

Invicti Security

Categories

Categories

Integrations

Blink
CyCognito
Docker
Dradis
FuzzDB
Hexway Pentest Suite
IriusRisk
Jit
Kondukto
Nucleus
OAuth
OWASP Threat Dragon
Parasoft
Phoenix Security
Prancer
Seconize DeRisk Center
Seeker
Sn1per Professional
Subject7
ThreadFix

Integrations

Blink
CyCognito
Docker
Dradis
FuzzDB
Hexway Pentest Suite
IriusRisk
Jit
Kondukto
Nucleus
OAuth
OWASP Threat Dragon
Parasoft
Phoenix Security
Prancer
Seconize DeRisk Center
Seeker
Sn1per Professional
Subject7
ThreadFix
Claim EthicalCheck and update features and information
Claim EthicalCheck and update features and information
Claim OWASP ZAP and update features and information
Claim OWASP ZAP and update features and information