# OWASP ZAP ## Identification The OWASP Zed Attack Proxy, an open-source web-application security scanner and intercepting proxy. ## Notebook evidence - [[Scanned_20260730-1946|Scanned_20260730-1946]], PDF pages 5 and 18. ## Relationships and evidentiary boundary [[OWASP]] · [[Burp Suite]] · [[OWASP WebGoat]]. The tool or name is preserved as research context. Written proximity does not by itself prove installation, execution, authorization, compromise, ownership, or coordination; dual-use tools require lawful, scoped testing and reproducible evidence.