Overview
This document is intended to serve as a basic introduction for using OWASP’s Zed Attack Proxy (ZAP) tool to perform security testing, even if you don’t have a background in security testing. To that end, some security testing concepts and terminology is included but this document is not intended to be a comprehensive guide to either ZAP or security testing.Zed Attack Proxy (ZAP) is a free, open-source penetration testing tool
being maintained under the umbrella of the Open Web Application Security
Project (OWASP). ZAP is designed specifically for testing web
applications and is both flexible and extensible.
Download Links: https://www.zaproxy.org/download/