<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Guest on ZAP</title>
    <link>/tags/guest/</link>
    <description>Recent content in Guest on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 13 Apr 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="/tags/guest/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Use ZAP with KRO in Kubernetes</title>
      <link>/blog/2026-04-13-use-zap-with-kro-in-kubernetes/</link>
      <pubDate>Mon, 13 Apr 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-04-13-use-zap-with-kro-in-kubernetes/</guid>
      <description>Learn how to integrate ZAP with KRO in a Kubernetes cluster to scan the security of each new deployment.</description>
    </item>
    <item>
      <title>Guided ZAP Scans: Faster CI/CD Feedback Using Static Analysis</title>
      <link>/blog/2026-03-27-guided-zap-scans-faster-cicd-feedback-using-sast/</link>
      <pubDate>Fri, 27 Mar 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-03-27-guided-zap-scans-faster-cicd-feedback-using-sast/</guid>
      <description>This post describes an approach that uses static analysis findings to guide ZAP&amp;rsquo;s active scans toward the most relevant endpoints. The result is a faster scanning mode suited for CI/CD pipelines, built on top of ZAP&amp;rsquo;s Automation Framework.</description>
    </item>
    <item>
      <title>Introducing DeepViolet</title>
      <link>/blog/2026-03-19-introducing-deepviolet/</link>
      <pubDate>Thu, 19 Mar 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-03-19-introducing-deepviolet/</guid>
      <description>Introducing DeepViolet: The Engine Behind ZAP&amp;rsquo;s New TLS Analysis</description>
    </item>
    <item>
      <title>OWASP PTK Integration with ZAP</title>
      <link>/blog/2026-01-19-owasp-ptk-add-on/</link>
      <pubDate>Mon, 19 Jan 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-01-19-owasp-ptk-add-on/</guid>
      <description>OWASP PTK is now pre-installed in the browsers launched by ZAP (Chrome, Edge and Firefox). This post shows how to run PTK’s DAST, IAST, SAST, and SCA inside the same authenticated session you’re testing, plus practical JWT and cookie workflows—while ZAP remains your traffic and context hub.</description>
    </item>
    <item>
      <title>Enhancing ZAP with AI for Bug Bounty Hunting</title>
      <link>/blog/2025-11-28-enhancing-zap-with-ai-for-bug-bounty-hunting/</link>
      <pubDate>Fri, 28 Nov 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-11-28-enhancing-zap-with-ai-for-bug-bounty-hunting/</guid>
      <description>Building an intelligent security testing system that leverages ZAP&amp;rsquo;s automation capabilities and machine learning to improve vulnerability detection</description>
    </item>
    <item>
      <title>Solving Caido Labs</title>
      <link>/blog/2025-10-15-solving-caido-labs/</link>
      <pubDate>Wed, 15 Oct 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-10-15-solving-caido-labs/</guid>
      <description>In this blog we show how to solve Caido labs using ZAP.</description>
    </item>
    <item>
      <title>PortSwigger Labs: Broken Brute-Force Protection, IP Block</title>
      <link>/blog/2025-04-09-portswigger-labs-broken-brute-force-protection-ip-block/</link>
      <pubDate>Wed, 09 Apr 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-04-09-portswigger-labs-broken-brute-force-protection-ip-block/</guid>
      <description>Walkthrough for the PortSwigger lab, &amp;ldquo;Broken brute-force protection, IP block&amp;rdquo;.</description>
    </item>
    <item>
      <title>Solving Portswigger Lab File Path Traversal Simple Case with ZAP</title>
      <link>/blog/2025-02-27-portswigger-lab-file-path-traversal-simple-case/</link>
      <pubDate>Thu, 27 Feb 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-02-27-portswigger-lab-file-path-traversal-simple-case/</guid>
      <description>Video and explanation of How to Solve the Portswigger labs using ZAP, in this case: &amp;lsquo;Path Traversal Simple Case&amp;rsquo;</description>
    </item>
    <item>
      <title>Use ZAP with Flagger in Kubernetes</title>
      <link>/blog/2024-12-24-use-zap-with-flagger-in-kubernetes/</link>
      <pubDate>Tue, 24 Dec 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-12-24-use-zap-with-flagger-in-kubernetes/</guid>
      <description>Learn how to integrate ZAP with Flagger in a Kubernetes cluster to scan the security of each new deployment.</description>
    </item>
    <item>
      <title>Powering Up DAST with ZAP and Noir</title>
      <link>/blog/2024-11-11-powering-up-dast-with-zap-and-noir/</link>
      <pubDate>Mon, 11 Nov 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-11-11-powering-up-dast-with-zap-and-noir/</guid>
      <description>Integrating Noir, a tool for discovering hidden endpoints in source code, with ZAP enhances dynamic application security testing (DAST).</description>
    </item>
    <item>
      <title>Automated ZAP Scans for Orchard Core Apps</title>
      <link>/blog/2023-12-08-automated-zap-scans-for-orchard-core-apps/</link>
      <pubDate>Fri, 08 Dec 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-12-08-automated-zap-scans-for-orchard-core-apps/</guid>
      <description>If you have an app running on the ASP.NET Core web framework and CMS Orchard Core, you can now easily run ZAP scans for it.</description>
    </item>
    <item>
      <title>Map Local Add-on</title>
      <link>/blog/2023-10-31-maplocal-add-on/</link>
      <pubDate>Tue, 31 Oct 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-10-31-maplocal-add-on/</guid>
      <description>Allows mapping of responses to content of chosen local file.</description>
    </item>
    <item>
      <title>Running ZAP on a raspberry pi</title>
      <link>/blog/2022-08-25-zap-on-raspberry-pi/</link>
      <pubDate>Thu, 25 Aug 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-08-25-zap-on-raspberry-pi/</guid>
      <description>Setting up ZAP on the raspberry pi.</description>
    </item>
    <item>
      <title>PortSwigger Labs: Username Enumeration with ZAP Scripts</title>
      <link>/blog/2022-04-14-portswigger-lab-username-enumeration-with-zap-scripts/</link>
      <pubDate>Thu, 14 Apr 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-04-14-portswigger-lab-username-enumeration-with-zap-scripts/</guid>
      <description>How to solve the PortSwigger Lab: Username enumeration via account lock using ZAP scripts.</description>
    </item>
    <item>
      <title>PortSwigger Labs: 2FA Broken Logic</title>
      <link>/blog/2022-04-06-portswigger-lab-2fa-broken-logic/</link>
      <pubDate>Wed, 06 Apr 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-04-06-portswigger-lab-2fa-broken-logic/</guid>
      <description>How to solve the PortSwigger Lab: 2FA Broken Logic using ZAP.</description>
    </item>
    <item>
      <title>The Eval Villain Add-on</title>
      <link>/blog/2021-12-01-the-eval-villain-add-on/</link>
      <pubDate>Wed, 01 Dec 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-12-01-the-eval-villain-add-on/</guid>
      <description>Eval Villain was recently added to the ZAP Marketplace. This add-on installs the Eval Villain web extension in Firefox and allows the inspection of arguments to arbitrary native JavaScript functions.</description>
    </item>
    <item>
      <title>Automate checking ASVS controls using ZAP scripts</title>
      <link>/blog/2021-02-10-automate-checking-asvs-controls-using-zap-scripts/</link>
      <pubDate>Wed, 10 Feb 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-02-10-automate-checking-asvs-controls-using-zap-scripts/</guid>
      <description>Write scripts in ZAP which will check a target application&amp;rsquo;s compliance against ASVS controls.</description>
    </item>
    <item>
      <title>ZAP JWT Support Add-on</title>
      <link>/blog/2020-09-03-zap-jwt-scanner/</link>
      <pubDate>Thu, 03 Sep 2020 00:00:00 +0000</pubDate>
      <guid>/blog/2020-09-03-zap-jwt-scanner/</guid>
      <description>&lt;p&gt;With the popularity of JSON Web Tokens (JWTs) there comes the need to secure their use so that they are not misused because of bad configuration, older libraries, or buggy implementations. So the JWT Support add-on is used to find such vulnerabilities and this blog explains on how to use it.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
