Proxy & Intercept
OWASP ZAP
Free intercepting proxy and automated web scanner.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Budget-friendly web testing and CI security scans.
How
Spider/AJAX spider → active scan → review alerts; use HUD for guided testing.
Why
Open-source full-featured alternative to commercial proxies.
Commands & usage
zap.sh -daemon -port 8080
docker run -t ghcr.io/zaproxy/zaproxy:stable zap-baseline.py -t https://example.com
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Comparisons
OWASP
Wordlists
Tags
Related in Proxy & Intercept
Burp Suite
Industry-standard intercepting proxy for web/app security testing.
Caido
Modern lightweight web security auditing toolkit (proxy).
mitmproxy
Interactive CLI/web intercepting proxy with Python scripting.
FoxyProxy + Browser DevTools
Browser proxy switching and built-in developer tools for web testing.