ZAP (OWASP): An open-source dynamic application security testing (DAST) tool used to find vulnerabilities in web applications during development and testing; it is increasingly automated within CI/CD pipelines to catch "low-hanging fruit" before deployment.