> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/security-testing-orchestration/3.0/use-sto/sto-scanner-configuration/zap.md).

# Zed Attack Proxy (ZAP)

{% content-ref url="/pages/DB9wyev3EQMwqyBFx6dP" %}
[Zed Attack Proxy step configuration](/security-testing-orchestration/3.0/use-sto/sto-scanner-configuration/zap/zap-scanner-reference.md)
{% endcontent-ref %}

{% content-ref url="/pages/hUmRVqGodAGnbZWx7lOW" %}
[Tutorial: DAST app scans using Zed Attack Proxy](/security-testing-orchestration/3.0/use-sto/sto-scanner-configuration/zap/dast-scan-zap.md)
{% endcontent-ref %}
