This book is ideal for students and professionals in offensive security, vulnerability analysts, and DevSecOps specialists who want to apply OWASP ZAP in technical audits and security pipelines. With a direct, functional, and tested approach, the content covers everything from basic usage to full automation strategies in CI/CD environments.
You will learn to configure proxies, intercept requests, perform fuzzing, simulate authenticated attacks, analyze HTTP responses, and generate high-impact technical reports with validated evidence.
Includes:
• Use of Spider, Active Scanner, and Passive Analysis
• Tests for XSS, SQLi, CSRF, and Privilege Escalation
• Integration with Jenkins, Docker, CLI scripts, and REST API
• Validation of headers, cookies, tokens, and authentication
• Technical checklists, advanced logging, and continuous security
Master OWASP ZAP as a tool for applied security analysis and automation, and strengthen your technical role in professional, regulated, and auditable environments.
owasp zap, devsecops, automated scanning, vulnerability analysis, offensive security, fuzzing, rest api, continuous integration, web scanning, security pipelines
Diego Rodrigues
Technical Author and Independent Researcher
ORCID: https://orcid.org/0009-0006-
StudioD21 Smart Tech Content & Intell Systems
Email:studiod21portoalegre@
LinkedIn: www.linkedin.com/in/
International technical author (tech writer)with a focus on structured production of applied knowledge. He is the founder of StudioD21 Smart Tech Content & Intell Systems, where he leads the creation of intelligent frameworks and the publication of technical textbooks supported by artificial intelligence, such as the Kali Linux Extreme and SMARTBOOKS D21 series, among others.
Holder of 42 international certifications issued by institutions such as IBM, Google, Microsoft, AWS, Cisco, META, Ec-Council, Palo Alto and Boston University, he works in the fields of Artificial Intelligence, Machine Learning, Data Science, Big Data, Blockchain, Connectivity Technologies, Ethical Hacking and Threat Intelligence.
Since 2003, he has developed more than 200 technical projects for brands in Brazil, the USA and Mexico. In 2024, he established himself as one of the greatest authors of technical books of the new generation, with more than 180 titles published in six languages. His work is based on the proprietary applied technical writing protocol TECHWRITE 2.3, focused on scalability, conceptual precision and practical applicability in professional environments.