Zed Attack Proxy Profile Banner
Zed Attack Proxy Profile
Zed Attack Proxy

@zaproxy

15,773
Followers
5
Following
61
Media
876
Statuses

Official announcements (low vol) for ZAP by @Checkmarx - the worlds most popular web app scanner. Free and open source.

Joined June 2011
Don't wanna be here? Send us removal request.
Pinned Tweet
@zaproxy
Zed Attack Proxy
4 years
Want to learn more about ZAP? The latest tutorial videos are all linked off - we're adding to them all of the time.
6
45
98
@zaproxy
Zed Attack Proxy
2 years
Happy Birthday to ME! ZAP is twelve years old today 🥳🎈
21
65
562
@zaproxy
Zed Attack Proxy
2 years
OWASP ZAP is FREE this #BlackFriday And every Friday, and every other day of the week for that matter! #owasp #OpenSource #AppSec
7
94
535
@zaproxy
Zed Attack Proxy
5 years
ZAP 2.8.0 with the Heads Up Display is now available from For full details see the release notes: Thank you to everyone who has contributed to this release.
2
86
134
@zaproxy
Zed Attack Proxy
4 years
ZAP 2.10.0 is now available to download from Release notes: This is the ten year anniversary release! Thank you to everyone who has contributed to this release or supported the @owasp ZAP project in any way.
4
66
129
@zaproxy
Zed Attack Proxy
3 years
New ZAP alpha active scan rule: Log4Shell (CVE-2021-44228) detection: Note this does depend on OAST support: Great work by @ricekot_ Blog post coming soon... #Log4Shell #log4j #owasp #dast
3
54
118
@zaproxy
Zed Attack Proxy
5 years
ZAP 2.9.0 is now available from For full details see the release notes: Thank you to everyone who has contributed to this release.
3
57
114
@zaproxy
Zed Attack Proxy
3 years
ZAP Blog post: You can now test for file upload vulnerabilities using the new FileUpload add-on (dev and weekly releases only) thanks to @sasan_karan
5
43
103
@zaproxy
Zed Attack Proxy
3 years
Blog Post: Out-of-band Application Security Testing with OWASP ZAP c/o @ricekot_ _ and @gsoc
0
31
105
@zaproxy
Zed Attack Proxy
7 years
A huge thank you to @mozilla / @MozillaSecurity / @claudijd for the $10,000 donation to @owasp ZAP - this is very much appreciated!
3
31
98
@zaproxy
Zed Attack Proxy
3 years
ZAP 2.11.1 has been released This is a security release to use a non vulnerable version of Log4J - we strongly recommend that you update asap.
0
46
98
@zaproxy
Zed Attack Proxy
6 years
Welcome to the ZAP HUD
Tweet media one
1
44
90
@zaproxy
Zed Attack Proxy
5 years
We have completely revamped - this is the new ZAP homepage. Feedback appreciated.
7
29
83
@zaproxy
Zed Attack Proxy
5 years
New websockets add-on now available with passive scanning support c/o @Kir_Manos our @gsoc student. Full blog post:
0
55
59
@zaproxy
Zed Attack Proxy
3 years
ZAP 2.11 is now available on Kali. #OWASP #kali #BugBountyTip
Tweet media one
3
28
79
@zaproxy
Zed Attack Proxy
7 years
The @owasp ZAP wiki now has a list of all of the the API calls available in 2.7.0:
0
51
73
@zaproxy
Zed Attack Proxy
7 years
. @owasp ZAP 2.7.0 is now available from For details of whats included see the release notes: Many thanks to everyone who has contributed to this release.
1
65
68
@zaproxy
Zed Attack Proxy
9 months
Tweet media one
3
9
68
@zaproxy
Zed Attack Proxy
1 year
You can now import @getpostman definitions into ZAP Implemented by Vitika Soni as part of Google Summer of Code #zaproxy #appsec #gsoc #postman
0
13
62
@zaproxy
Zed Attack Proxy
7 years
We've just exceeded 3000 stars on github! Many thanks to all of our supporters: cc @owasp
3
28
57
@zaproxy
Zed Attack Proxy
5 years
ZAP use is rocketing! These are the check-for-update requests by version since @owasp ZAP was released in 2010
Tweet media one
0
21
58
@zaproxy
Zed Attack Proxy
5 years
We have brand new @owasp ZAP API docs c/o @sshniro and Google Season of Docs ( @GoogleOSS ) :
6
23
56
@zaproxy
Zed Attack Proxy
4 years
The ZAPCon speakers have been announced: Thank you to everyone who submitted a talk - there were so many that we had to reject some very good ones
1
30
55
@zaproxy
Zed Attack Proxy
2 years
ZAP 2.12.0 is "Coming Soon" - for more details see
3
15
54
@zaproxy
Zed Attack Proxy
4 years
First Ever ZAPCon - Call For Papers:
2
39
54
@zaproxy
Zed Attack Proxy
6 years
Hacking with the ZAP HUD
0
21
52
@zaproxy
Zed Attack Proxy
8 years
You can attack a site from the ZAP cmdline using a cmd like: "./zap.sh -cmd -quickurl -quickprogress"
0
26
46
@zaproxy
Zed Attack Proxy
2 years
The ZAP Roadmap is now online: If there is something else you think we should be working on then let @psiinon know!
1
21
48
@zaproxy
Zed Attack Proxy
8 years
Announcing the official @owasp ZAP @jenkinsci plugin:
1
47
48
@zaproxy
Zed Attack Proxy
4 years
The OWASP ZAP @github Baseline Scan Action is now Verified! Thank you @GitHubSecurity
1
23
47
@zaproxy
Zed Attack Proxy
4 years
There are now 3 series of ZAP videos, all linked off - currently 32 videos in total and more will be added soon...
0
19
46
@zaproxy
Zed Attack Proxy
4 years
Better late than never - here are more details about some of the enhancements in ZAP 2.9.0: c/o @kingthorin_rm
1
25
46
@zaproxy
Zed Attack Proxy
2 years
The ZAP spiders now score 80% vs Google Crawl Maze: The latest 7% increase is thanks to @5up3r541y4n
1
7
46
@zaproxy
Zed Attack Proxy
7 years
ZAP can now launch browsers that auto proxy though ZAP and dont need to import the ZAP CA cert - update now to try it out. Java 8 required
0
37
45
@zaproxy
Zed Attack Proxy
4 years
Learn about Site Tree Modifiers: a key new feature in the next ZAP release and available right now in the latest weekly release
0
12
45
@zaproxy
Zed Attack Proxy
4 years
The @zaproxy team is pleased to announce the release of "Reflect". A third party addon by @OptionalValue , coded in Kotlin. It's designed to help you find reflected parameters (values). #owasp #zaproxy #redteam #purpleteam #bugbounty #appsec
Tweet media one
1
22
45
@zaproxy
Zed Attack Proxy
4 years
Join @psiinon and @EUSP tomorrow (17th April) for a 3 hour deep dive workshop into @owasp ZAP automation and authentication Join the @AllDayDevOps slack channel to ask questions live.
5
18
42
@zaproxy
Zed Attack Proxy
1 year
@MoistQ8 No, ZAP is staying open source.
2
1
41
@zaproxy
Zed Attack Proxy
1 year
Authentication auto-detection is now available in ZAP! Try it out and let @psiinon know how well it works for you
1
12
40
@zaproxy
Zed Attack Proxy
2 years
New blog post for the pentesters:
0
12
42
@zaproxy
Zed Attack Proxy
5 years
Want to know how ZAP can help find @owasp Top Ten risks? See
1
15
41
@zaproxy
Zed Attack Proxy
7 years
New @owasp ZAP Blog post: Scanning APIs with ZAP -
0
37
40
@zaproxy
Zed Attack Proxy
6 years
We've passed 4000 stars on @github : Thank you to all of our supporters!
1
8
38
@zaproxy
Zed Attack Proxy
2 years
One for the #pentesters - hit the ground running with the all new ZAP Pentester Pack:
0
8
40
@zaproxy
Zed Attack Proxy
3 years
Want to learn more about #ZAP and automated #security testing? Join us at @ZAProxyCon on March 8-9! #ZAPCon is a virtual user conference and it’s completely free. Save your spot 🪑
Tweet media one
1
13
38
@zaproxy
Zed Attack Proxy
7 years
The @owasp ZAP stable @Docker image has now been pulled > 100K times - remember theres also weekly and live images
0
21
37
@zaproxy
Zed Attack Proxy
4 years
New ZAP Deep Dive video: Configuration The Deep Dive series now have their own playlist:
1
18
37
@zaproxy
Zed Attack Proxy
6 years
Thanks to for this comprehensive ZAP python API example:
0
22
36
@zaproxy
Zed Attack Proxy
4 years
The team just released new versions of the ZAP GitHub Actions (full-scan and baseline). They now pass by default, with fail optional, and have reduced logging (chattiness). #GitHubActions #devops #devsecops #OpenSource #zaproxy
1
17
37
@zaproxy
Zed Attack Proxy
2 years
Want to install all of the ZAP add-ons which just contain scan rules? Now you can with the new Scan Rules Pack:
0
6
38
@zaproxy
Zed Attack Proxy
5 years
ZAP is 9 today! Thank you to all of our contributors and supporters! #owasp #zaproxy
0
14
36
@zaproxy
Zed Attack Proxy
2 years
Tweet media one
0
8
36
@zaproxy
Zed Attack Proxy
8 years
ZAP 2.6.0 is now available: Release notes: Includes security fixes so upgrade asap
0
54
36
@zaproxy
Zed Attack Proxy
6 years
The ZAP stable docker image has now been pulled over 1 million times
0
11
37
@zaproxy
Zed Attack Proxy
4 years
Just released v21.1.0 of the Wappalyzer technology detection add-on. Update includes the latest patterns/icons from upstream and support for DOM patterns courtesy of @bettercalln1ck Get it via zap marketplace. #owasp #zaproxy #cybersec #appsec #redteam #purpleteam
Tweet media one
0
12
37
@zaproxy
Zed Attack Proxy
5 years
The latest weekly release is ZAP 2.8.0 RC2 This is intended to be the last RC prior to the full release, so please report any issues asap.
1
14
35
@zaproxy
Zed Attack Proxy
2 years
There's a LOT going on in the ZAP world - read all about it here:
1
13
37
@zaproxy
Zed Attack Proxy
5 years
This weeks weekly release is the 3rd and hopefully final release candidate. We plan to release @owasp ZAP 2.9.0 next week.
2
12
35
@zaproxy
Zed Attack Proxy
2 years
We have seen a significant increase in ZAP usage recently and this has resulted in a corresponding increase in support questions, especially regarding authentication handling. We are now focussing on improving the authentication docs - see
2
6
33
@zaproxy
Zed Attack Proxy
5 years
The @owasp ZAP documentation, like that of many open source projects, could be much better. We are starting a "ZAP Documentation ++" initiative in an attempt to improve it. See this gdoc for more info on how you can get involved.
0
22
35
@zaproxy
Zed Attack Proxy
4 years
We have a new ongoing set of ZAP videos now available on YouTube - the ZAP Deep Dive Series c/o @psiinon and @StackHawk
2
13
36