Skip to content

HelpStartConceptsPscan

psiinon edited this page Jun 3, 2015 · 4 revisions

Passive Scan

ZAP passively scans all of the responses from the web application being tested. Passive scanning does not change the responses in any way and is therefore safe to use. Scanned is performed in a background thread to ensure that it does not slow down the exploration of an application.

In this release ZAP passive scanning is used for automatically adding tags and raising alerts for potential issues.

A set of rules for automatic tagging are provided by default. These can be changed, deleted or added to via the Options Passive Scan Tags screen.

The alerts raised by passive scanning can be configured using the Options Passive Scan Rules screen.

See also

     UI Overview for an overview of the user interface
     Features provided by ZAP
     Active scanning
     Scanner Rules supported by default
Clone this wiki locally